logo

Fake bank websites play dead to evade security scanners

ID: a9c97357-7e18-5693-8634-ad15771613fe

STIX ID: report--a9c97357-7e18-5693-8634-ad15771613fe

Feed Name: Help Net Security

Threat Score
60/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Sinisa Markovic

...
...

Fortra’s FIRE unit uncovered "Chameleon SEO Poisoning," a phishing campaign using typo‑squat domains and SEO poisoning to surface fake bank login pages in search results; attackers cloak content based on the search referrer so scanners see benign pages while search-click victims receive convincing credential-stealing forms. FIRE tracked the technique for three months, reported a 40% rise in Q2 2026, and issued role-specific recommendations for detection and takedown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.