A sophisticated phishing technique known as Chameleon SEO Poisoning leverages manipulated search engine results and cloaked fake banking websites to harvest user credentials while bypassing automated security scanners.
Researchers from Fortra’s threat intelligence unit, Fortra Intelligence and Research Experts (FIRE), tracked the attack vector over a three-month period and documented a 40% surge in active cases during the second quarter of 2026. Threat actors manipulate search rankings on platforms like Google and Bing for high-intent keywords including “Bank Name Customer Portal” or “Credit Card Login,” positioning malicious links above legitimate institutions through standard SEO poisoning methods.
Unlike traditional phishing infrastructure, the domains involved in these campaigns are not compromised legitimate properties. Instead, investigators found they are newly registered typo-squats utilizing second-level domains (SLDs) such as .ph.com and .gr.com. According to Fortra researchers, “It is important to clear up a common misconception here: these are not compromised domains by nature. Instead, these domains are typo-squats that have been recently registered on second-level domains (SLDs) like .ph.com, .gr.com, and similar variants.”
The core mechanism relies on presentation control, enabling the malicious server to dynamically alter rendered content based on the visitor’s arrival vector. When security scanners or analysts evaluate a domain via direct navigation without a search engine referrer, the server renders an inactive, offline-looking page. However, when a victim clicks through from a poisoned search engine result, the identical domain immediately serves a fully functional, convincing fake bank login interface.
To combat this evolving threat landscape, Fortra advises security teams to integrate referrer spoofing and browser emulation into their standard URL evaluation protocols, as direct visits no longer reliably surface malicious content. Additionally, enterprise registrars and hosting providers are urged to accelerate vetting processes on high-risk SLDs and accept referrer-triggered evidence to expedite site takedowns.