CyberSecurity SEE

Google and Bing Search Results Revealed Covert Banking Phishing Pages

Google and Bing Search Results Revealed Covert Banking Phishing Pages

Threat actors are increasingly exploiting Google and Bing as conduits for phishing attacks, leveraging a sophisticated cloaking technique. This method allows them to present benign pages to security scanners, while unsuspecting users searching the web encounter malicious banking portals designed to harvest credentials. These deceptive campaigns primarily target customers of major financial institutions, incorporating tactics such as search engine optimization (SEO) abuse, the use of recently registered lookalike domains, and a mechanism of referral-aware payload delivery. This multifaceted approach extends the lifespan of phishing pages, making them an ongoing threat.

The Chameleon campaigns differ significantly from traditional phishing operations, which typically rely on disseminating harmful links through email or SMS. Instead, these malicious actors utilize a pull-based model. By manipulating the search engine results pages (SERPs), they can position fraudulent websites to appear at the top of search results for high-intent queries. These queries often revolve around terms such as “Bank Name Customer Portal,” “Credit Card Login,” or similar phrases associated with account access. Victims searching for these financial services could unknowingly click on a fraudulent result that is prominently displayed, often above or in close proximity to the legitimate banking webpage.

Most of these attacker-controlled domains are usually typo-squats or are hosted on newly established second-level domains, which may incorporate variants under domain extensions like .ph.com and .gr.com. Rather than being compromised legitimate websites, these domains are crafted to deceive users. The effectiveness of this strategy lies in transforming search visibility into an initial access vector. Users typically place a great deal of trust in familiar search engines, and this, combined with their urgency to access their accounts, performs much of the social-engineering work for the attackers.

Recent reports from Fortra Intelligence and Research Experts (FIRE) indicate that incidents of “Chameleon SEO Poisoning” have surged by more than 40% in the second quarter of 2026, underscoring the growing prevalence of these phishing attempts. The distinctive feature of Chameleon SEO Poisoning is its ability to control presentation—essentially allowing the same URL to deliver different content based on how the visitor arrived at the site.

When researchers, hosting providers, or automated sandboxing services access a suspicious domain directly, the server may return an offline page, generic error, or even a fabricated 404 response. This tactic can render the domain seemingly inert, leading analysts to incorrectly dismiss alerts as false positives. However, when a request is generated via a referrer from Google or Bing, the site delivers its active payload. This payload is typically a highly convincing clone of a legitimate banking login portal, intended to capture user credentials, session cookies, or other authentication information.

FIRE has warned that these campaigns can facilitate credential theft and session hijacking, with the added advantage of sustaining operations longer than traditional phishing infrastructures. The technique intricately conditions the user’s experience; the poisoned search result acts as bait while the direct visit becomes the entity that conceals the malicious intent.

Most domain reputation systems and automated URL scanners evaluate sites through direct requests, a model ill-suited to a campaign like this one that assesses the requester first. A scanner operating with a default scripting user agent, devoid of a search referrer, may retrieve the clean version of the page. As a result, the malicious domain can maintain an innocuous reputation score while banking customers directed through search results are exposed to active credential-harvesting efforts.

Fortra now urges Security Operations Center (SOC) teams to evolve beyond mere static scans and to replicate the conditions encountered by victims. This involves testing relevant search-engine referrers, employing modern consumer-browser user agents, and, where feasible and legal, considering geographic profiles aligned with the customer base of targeted institutions.

For Chief Information Security Officers (CISOs), this evolving landscape necessitates a shift in brand protection strategy from reactive measures, such as takedowns, to proactive, continuous monitoring of search results for keywords associated with brand names, logins, and customer support. It is recommended that any anomalous top-ranking results, particularly those from newly registered lookalike domains, be treated as high-priority fraud indicators.

FIRE has previously documented how SEO-poisoning services manipulate backlink strategies and compromised websites to elevate fraudulent financial pages, emphasizing the alarming scale and commercial sophistication of this ecosystem. In light of this, SOC playbooks should prohibit dismissing a suspicious URL case solely based on a direct visit returning an inactive page. Instead, analysts must adopt a context-aware approach to evidence collection that includes tracking the referrer, user agent, redirect chain, rendered content, and geographic response behaviors.

For consumers, the safest course of action remains to bypass search engines altogether when accessing banking portals. Utilizing an official banking application, manually saved bookmarks, and carefully inspecting the full URL before entering any credentials can keep users safe. If an unusual login page emerges, contacting the institution through verified channels is advisable to mitigate risks further.

Source link

Exit mobile version