logo

Trusted Platforms Exploited to Steal Philippine Banking Credentials

ID: e4284c2a-fe41-51d5-b24d-33f752b2b7a6

STIX ID: report--e4284c2a-fe41-51d5-b24d-33f752b2b7a6

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-04-03

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

This report describes an ongoing, sophisticated phishing campaign against Philippine bank customers that leverages trusted services and compromised domains to host convincing fake banking pages; researchers observed over 900 malicious links and more than 400 victims, with stolen credentials and OTPs exfiltrated via automated Telegram bots to enable rapid fraud. The operation uses hotlinking of real bank assets, short-lived SSL certificates, rotating subdomains, and compromised sender accounts to evade detection and improve email deliverability, and defenders are advised to improve monitoring, email filtering, and user awareness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.