ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Fake bank websites play dead to evade security scanners

mediumPhishing & fraud exploited in the wildimportance 58
AI summary · glm-5.3-flash

Fortra uncovered Chameleon SEO Poisoning: cloaked typosquat bank sites rank on Google and Bing to steal credentials while evading scanners, with cases up 40% in Q2 2026.

Fortra's threat intelligence unit FIRE spent three months tracking Chameleon SEO Poisoning, a phishing method that ranks recently registered typosquat domains on second-level domains like .ph.com and .gr.com above legitimate bank sites on Google and Bing. The technique uses presentation control (cloaking by referrer): direct visits get a dead, offline-looking page, while search-referred clicks receive a convincing fake bank login page, letting poisoned results persist for days or weeks. Fortra recorded a 40% jump in cases during the second quarter of 2026 and recommends referrer-spoofed URL testing, faster SLD takedowns, and bookmarking bank logins.

  • Typosquat domains on SLDs like .ph.com and .gr.com outrank legitimate bank sites via SEO poisoning.
  • Cloaking serves a dead page to direct visitors but a fake login to search-referred clicks.
  • Fortra recorded a 40% increase in cases during Q2 2026 after three months of tracking.
  • Recommendations include referrer-spoofed testing, faster SLD takedowns, and bookmarking bank logins.
Full article342 words · extracted from helpnetsecurity.com · click to collapse

A phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners has been discovered by Fortra.

The company’s threat intelligence unit, Fortra Intelligence and Research Experts (FIRE), spent three months tracking the technique and reports a 40% jump in cases during the second quarter of 2026.

Attackers rank these pages for high-intent keywords such as “Bank Name Customer Portal” or “Credit Card Login” on Google and Bing, using standard SEO poisoning to climb above the legitimate site.

“It is important to clear up a common misconception here: these are not compromised domains by nature. Instead, these domains are typo-squats that have been recently registered on second-level domains (SLDs) like .ph.com, .gr.com, and similar variants,” researchers said.

The danger comes from what researchers call presentation control, the server’s ability to decide what a visitor sees based on how they arrived. By serving different content depending on where the click came from, the technique keeps standard security sweeps from spotting the threat, letting poisoned search results stay active for days or weeks, Fortra noted.

Researchers demonstrated the effect directly, pulling up one typosquat domain under two different conditions. Typed in by hand, with no search engine referrer attached, the domain served a dead, offline-looking page.

fake banking websites phishing

Clicked through from the poisoned search result, the same domain immediately switched to a convincing fake bank login page.

fake banking websites phishing

Actionable recommendations

Fortra’s recommendations split by role:

Security teams should treat referrer spoofing and browser emulation as standard steps when testing a reported URL, since a direct visit alone no longer tells them anything reliable.

Hosting providers and registrars are advised to speed up vetting on SLDs like .ph.com and .gr.com, and accept referrer-triggered evidence as grounds for a takedown.

CISOs should watch search rankings as an attack surface, flagging brand keywords that suddenly point to a domain they don’t own.

Anyone banking online is better off skipping the search bar for the bank’s login page and bookmarking it instead, or using the bank’s official app.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/08/24/chameleon-seo-poisoning-fake-banking-websites-phishing/