Search results are sending people to fake Bitrefill checkouts
Scam sites impersonating Bitrefill's crypto checkout appear in search results, tricking victims into sending up to $1,990 in crypto directly to scammers.
Malwarebytes documents a cluster of lookalike domains copying Bitrefill's gift card checkout, surfaced via search engine results rather than email. Victims choose an amount up to $1,990 and pay in Bitcoin, Ethereum, USDC, USDT, Solana, or Litecoin to scammer-controlled addresses, with no recourse since crypto payments are irreversible. Domains use typosquatting and Punycode/IDN homoglyph tricks, and the fake sites run commercial analytics software to measure and optimize victim conversion. Bitrefill's security team is working with takedown specialists to remove the sites.
Hacked Thai College Website Abused to Redirect Google Searchers to Illegal Online Casinonew
ADEX uncovered a hacked Thai college domain serving casino pages through real Google search redirects, part of a global campaign compromising government and education sites.
Anti-fraud platform ADEX found a casino-themed page planted on the compromised km.chpc.ac.th domain in Thailand's educational .ac.th zone, which Google indexed and ranked first to redirect users to illegal online gambling. The scheme achieved full ad cloaking without deploying any cloaking code by chaining a genuine Google results page and a third-party redirect. The same domain-borrowing tactic is tracked globally: Thailand reports roughly 30 million gambling URLs across about 1,000 public-sector sites, Indonesia blocked 683 government and education sites, and Netcraft found an underground market selling access to more than 15,000 compromised .gov, .edu and ccTLD domains. ADEX argues Google's site reputation abuse policy does not cover institutions that are hijacked without their knowledge.
ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign
Unit 42 uncovers ApateWeb, a campaign using over 130,000 domains and multilayered redirects to deliver scareware, adware and PUPs to millions of users.
Unit 42 discovered ApateWeb, a large-scale campaign using a network of more than 130,000 domains to deliver scareware, potentially unwanted programs, adware including a rogue browser and browser extensions, and scam pages. The campaign uses a three-layer structure with deceptive emails as the entry point, centralized victim tracking via UUIDs, intermediate adware or anti-bot redirections, and evasion tactics such as cloaking, bot detection error pages, and wildcard DNS abuse. Activity spiked since August 2022, with several hundred attacker-controlled sites remaining in Tranco's top 1 million rankings and millions of monthly hits; Unit 42 blocked an estimated 3.5 million sessions across 74,711 devices in November 2023.
How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
Huntress details campaigns abusing Claude Artifacts, claude.ai/share links, and ChatGPT/Grok conversations to deliver SectopRAT, MacSync, and AMOS stealers.
Huntress SOC documented nine months of campaigns in which attackers weaponized trusted AI platform features—Claude Artifacts, public claude.ai/share links, and indexable ChatGPT/Grok conversations—to deliver malware. The July FakeAgent campaign hit more than 29 organizations via a malicious Claude Artifact posing as a Claude Desktop download page that redirected to SectopRAT. A claude.ai/share link disguised as an Apple Support guide tricked a victim into running a curl command that deployed the MacSync stealer, harvesting cookies, credentials, keychain secrets, Telegram sessions, and SSH/cloud keys, while SEO-poisoned ChatGPT and Grok conversations delivered the AMOS stealer via ClickFix-style instructions.
Fake bank websites play dead to evade security scanners
Fortra uncovered Chameleon SEO Poisoning: cloaked typosquat bank sites rank on Google and Bing to steal credentials while evading scanners, with cases up 40% in Q2 2026.
Fortra's threat intelligence unit FIRE spent three months tracking Chameleon SEO Poisoning, a phishing method that ranks recently registered typosquat domains on second-level domains like .ph.com and .gr.com above legitimate bank sites on Google and Bing. The technique uses presentation control (cloaking by referrer): direct visits get a dead, offline-looking page, while search-referred clicks receive a convincing fake bank login page, letting poisoned results persist for days or weeks. Fortra recorded a 40% jump in cases during the second quarter of 2026 and recommends referrer-spoofed URL testing, faster SLD takedowns, and bookmarking bank logins.