Researchers have uncovered a sophisticated phishing scheme using cloaked banking portals and manipulated search rankings to bypass security audits.
Cybersecurity researchers at Fortra have identified a persistent threat campaign dubbed Chameleon SEO Poisoning, which deploys cloaked fake banking portals designed to harvest enterprise and consumer credentials while actively evading automated security analysis. According to data from the Fortra Intelligence and Research Experts (FIRE) threat intelligence unit, which spent three months monitoring the tactic, occurrences of the technique surged by 40 percent in the second quarter of 2026.
Threat actors execute the campaign by optimizing malicious pages to rank prominently on major search engines like Google and Bing for high-intent search queries, including phrases such as “Bank Name Customer Portal” or “Credit Card Login.” By leveraging SEO poisoning methodologies, these unauthorized links outrank legitimate financial institution resources, tricking unsuspecting users seeking official banking services.
Investigators clarified that the underlying infrastructure does not rely on compromised enterprise domains, but instead utilizes newly registered typosquatting domains across various second-level domains (SLDs) like .ph.com and .gr.com. “It is important to clear up a common misconception here: these are not compromised domains by nature. Instead, these domains are typo-squats that have been recently registered on second-level domains (SLDs) like .ph.com, .gr.com, and similar variants,” researchers noted.
The technical mechanism relies heavily on presentation control, allowing the hosting server to dynamically alter rendered content based on the visitor’s HTTP referrer headers. When automated security scanners or direct visitors navigate to the typosquatted URL without a search engine referrer, the server displays an inactive, offline-appearing placeholder page. Conversely, when visitors click through a poisoned search engine result, the server instantly swaps the interface for a highly convincing fraudulent login portal.
Fortra recommends that enterprise security teams integrate referrer spoofing and dynamic browser emulation into their URL analysis procedures to prevent false negatives caused by direct-access evasion. Furthermore, domain registrars and hosting providers are urged to accelerate scrutiny of high-risk SLD variants and utilize referrer-evidenced indicators to expedite malicious domain takedowns.