As cited
Citation snapshot as of .
threat intel
Fake bank websites play dead to evade security scanners
Fortra Intelligence and Research Experts identified a phishing technique called Chameleon SEO Poisoning that uses search result manipulation and cloaked fake banking websites to harvest credentials while evading detection. The method ranks malicious pages for banking-related keywords and adapts content based on visitor type, making it invisible to security scanners. Cases increased 40% during the second quarter of 2026.
Why it matters: Banking customers and security teams need to understand this evasion technique targets high-intent search queries; practitioners should monitor for cloaking behavior and educate users on verifying URLs before entering credentials.
- Source published
- First seen by Cybersecurity Tracker