CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
ID: af8f08c9-838c-596f-ae03-ca82c3b4a6ca
STIX ID: report--af8f08c9-838c-596f-ae03-ca82c3b4a6ca
Feed Name: The Hacker News
**Executive summary:** This CTI report describes coordinated insurance-themed phishing campaigns that leverage paid Google Ads and disposable cloud-hosted landing pages to perform real-time session hijacking—relaying OTPs and authenticating to genuine insurance portals during a victim's active session—supported by a purpose-built phishing framework called "InsureOTP" that provides live session management, backend dashboards, Telegram integrations, and other operational tooling; defenders are advised to monitor paid-ad abuse, lookalike domains, disposable hosting, and anomalous authentication patterns to detect and disrupt these attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
