logo

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

ID: af8f08c9-838c-596f-ae03-ca82c3b4a6ca

STIX ID: report--af8f08c9-838c-596f-ae03-ca82c3b4a6ca

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-07-25

Date Updated: 2026-07-25

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** This CTI report describes coordinated insurance-themed phishing campaigns that leverage paid Google Ads and disposable cloud-hosted landing pages to perform real-time session hijacking—relaying OTPs and authenticating to genuine insurance portals during a victim's active session—supported by a purpose-built phishing framework called "InsureOTP" that provides live session management, backend dashboards, Telegram integrations, and other operational tooling; defenders are advised to monitor paid-ad abuse, lookalike domains, disposable hosting, and anomalous authentication patterns to detect and disrupt these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.