logo

Brazilian Bank Targeted by Phishing Site and DNS Poisoning

ID: c787cc1d-d84b-5be0-8291-d429263f8ad9

STIX ID: report--c787cc1d-d84b-5be0-8291-d429263f8ad9

Feed Name: Zscaler Security Research Blog

Threat Score
65/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

A phishing campaign targeted Santander Brazil by poisoning DNS to resolve santander.com.br to a cloned site at 200.252.58.134 that captured login credentials. The phishing site closely mimicked the real site (legitimate IPs 200.220.178.3 and 200.220.186.3), lacked HTTPS and contained copied HTML comments; the compromised DNS servers were later cleaned but the phishing site remained accessible and unlisted by some URL blocklists.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.