Fake Bank Websites Play Dead to Evade Security Scanners via Chameleon SEO Poisoning

A newly tracked phishing technique dubbed Chameleon SEO Poisoning uses advanced cloaking and manipulated search engine results to harvest enterprise credentials while actively evading automated security analysis.

Researchers at Fortra Intelligence and Research Experts (FIRE) tracked the deceptive campaign over a three-month observation period, recording a 40% surge in active cases throughout the second quarter of 2026. The methodology relies on optimizing fraudulent domains for high-intent corporate and consumer search keywords, including terms such as customer portals and credit card login pages, allowing attackers to outrank legitimate financial institutions on search engines like Google and Bing.

According to Fortra investigators, the threat infrastructure does not typically rely on compromised legitimate domains. Instead, threat actors register fresh typosquatted second-level domains using registry variants such as .ph.com and .gr.com to establish their staging presence.

The critical security bypass mechanism involves server-side presentation control, which dynamically alters displayed content based on the visitor’s origin and traffic source. When security scanners or analysts perform direct visits without a valid search engine referrer, the targeted server renders a benign or entirely offline-looking page. However, when users click through poisoned search engine results, the identical URL immediately switches to a fully functional fake banking login interface.

“It is important to clear up a common misconception here: these are not compromised domains by nature. Instead, these domains are typo-squats that have been recently registered on second-level domains (SLDs) like .ph.com, .gr.com, and similar variants,” researchers explained regarding the infrastructure mechanics.

To mitigate these risks, Fortra advises enterprise security teams to integrate browser emulation and referrer spoofing as standard operating procedures during URL analysis. Furthermore, organizations are urged to monitor search engine rankings for brand keyword anomalies, while end users should bypass search engines entirely when accessing sensitive financial portals by utilizing official mobile applications or pre-saved bookmarks.

Leave a Reply

Your email address will not be published. Required fields are marked *