Google, Bing Search Results Poisoned to Deliver Banking Phishing
Key Takeaways Cybercriminals are leveraging “Chameleon SEO Poisoning” to manipulate Google and Bing search results, leading users to sophisticated banking phishing sites. The attack...
Key Takeaways
- Cybercriminals are leveraging “Chameleon SEO Poisoning” to manipulate Google and Bing search results, leading users to sophisticated banking phishing sites.
- The attack specifically targets individuals searching for bank login portals or credit card access, redirecting them to highly convincing fraudulent pages.
- A key feature of this campaign is “cloaking,” where malicious pages only display phishing content when accessed via a search engine referral, making detection by direct visits or automated scanners difficult.
- The campaign significantly increased in Q2 2026, targeting numerous major financial institutions and their customers.
- Users are advised to access banking services through official apps or bookmarks, while organizations need context-aware monitoring and scrutiny of new lookalike domains.
Hackers Exploit Search Engines to Deliver Banking Phishing
In a concerning development, financial sector customers are now at heightened risk of falling victim to phishing schemes even before receiving any suspicious emails or text messages. Malicious actors are actively manipulating search engine results on platforms like Google and Bing to prominently display fraudulent banking pages, masquerading as legitimate services.
Table Of Content
This sophisticated operation, dubbed “Chameleon SEO Poisoning,” transforms routine searches for terms such as “bank customer portal” or “credit card login” into prime opportunities for credential theft. When unsuspecting users click on what appears to be a highly-ranked, authentic search result, they are instead directed to a meticulously crafted replica of a banking website. These imposter sites are designed to capture sensitive information like passwords and hijack active user sessions, as detailed in a comprehensive report.
Escalation of Chameleon SEO Poisoning
Analysts at Fortra Intelligence and Research Experts (FIRE) observed a significant surge in these activities during the second quarter of 2026. The campaigns have specifically targeted the clientele of several prominent financial institutions, indicating a strategic focus on high-value targets. Fortra said in a report shared with Cyber Security News (CSN) that the deceptive nature of these sites allows them to appear innocuous during standard inspections, thus delaying detection and takedown efforts. This extended operational window grants attackers more time to compromise credentials belonging to both individual consumers and the financial institutions themselves.
Advanced Cloaking Techniques Evade Detection
The success of the Chameleon SEO Poisoning campaign hinges on search engine optimization (SEO) poisoning, a tactic that elevates attacker-controlled web pages in search rankings for specific, high-intent queries. Rather than compromising existing legitimate websites, the perpetrators register new domain names that closely resemble official bank URLs. They then construct web pages optimized with keywords that users are likely to enter into Google or Bing when searching for banking services.
This method marks a significant shift from traditional phishing, moving beyond the “push” model of mass emails and messages. Instead, it employs a “pull” strategy, ensnaring victims precisely when they are actively seeking their bank’s services. Similar SEO poisoning tactics have previously been observed, for instance, placing fake software download links at the top of Bing search results, demonstrating the effectiveness of search rankings as a vector for distributing fraud and malware.
A critical element enabling this evasion is “cloaking.” If a security researcher, an automated scanning tool, a domain registrar, or a hosting provider attempts to access one of these suspicious URLs directly, the server will often present a benign, inactive page or even a false 404 error. Conversely, the very same URL will deliver a pixel-perfect, fully functional banking phishing portal only when the server detects that the visitor originated from a Google or Bing search result. This selective content delivery allows attackers to maintain their malicious pages online for extended periods, sometimes weeks, without being flagged or taken down. It also explains why a reported malicious link might appear clean during a routine security check, even as actual customers continue to encounter the active credential-harvesting page.
Why Routine Checks Fall Short
The inherent design of most reputation services and passive security scanners makes them vulnerable to this cloaking technique. When these tools access a suspicious web address directly, they typically receive the harmless version of the page because the crucial search referrer information is absent. Consequently, security operations teams may mistakenly classify these alerts as false positives, unaware that the malicious content is specifically reserved for users arriving via search engines.
To effectively combat this threat, researchers advocate for testing suspicious search results within the same context as an actual victim. This involves utilizing a standard consumer browser profile, accurately passing the relevant search referrer, and, where applicable, conducting checks from the geographical location of the bank’s customer base. The primary objective is to replicate the experience of an ordinary user, rather than relying on what a default automated script would encounter. Furthermore, defenders should closely monitor recently registered domains that closely resemble legitimate financial institutions (e.g., those using private second-level domains like .ph.com or .gr.com) and scrutinize any unusual top-ranking search results for branded banking terms. The broader implications of this pattern echo previous search poisoning attacks, such as those targeting Windows users, where minor alterations to domain names combined with credible-looking pages successfully redirect users to harmful destinations.
For consumers, the most secure approach to accessing banking services is to use the bank’s official mobile application or a previously saved bookmark, rather than clicking on a search engine result. This simple practice significantly reduces exposure to pages designed to imitate trusted brands, much like how banking phishing campaigns exploit trusted platforms to lend legitimacy to theft attempts.
Organizations must recognize search visibility as a component of their overall attack surface, moving beyond its traditional classification as solely a marketing concern. Implementing context-aware monitoring, expediting the review of cloaked evidence, and strengthening checks on rapid domain registrations can help identify and expose these deceptive pages. The history of SEO-poisoned enterprise software downloads demonstrates that this technique can target both customers and employees alike.
The immediate takeaway is clear: a prominent search result does not inherently guarantee authenticity. Banks, cybersecurity teams, and individual users must all diligently verify the legitimacy of the path they take to access financial services, as attackers are increasingly leveraging the public’s trust in search engines to conceal their phishing operations.
What You Should Do
- For Consumers: Always access your bank’s website or online services directly via its official mobile application or a trusted, previously saved bookmark. Avoid clicking on banking-related links from search engine results, even if they appear to be highly ranked.
- For Organizations (Financial Institutions & Security Teams):
- Implement advanced, context-aware monitoring solutions that can detect cloaked content by simulating user behavior, including referrer headers and geographic locations.
- Prioritize and rapidly investigate alerts related to suspicious domain registrations, particularly those using lookalike private second-level domains (e.g.,
.ph.com,.gr.com). - Educate employees and customers about the risks of SEO poisoning and the importance of verifying URLs before entering credentials.
- Actively monitor search engine results for your brand’s keywords to identify and report fraudulent pages promptly.
- Treat search engine visibility as a critical part of your organization’s attack surface, not merely a marketing metric.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Private second-level domain | .ph.com |
Private second-level domain pattern cited by researchers as a vehicle used for recently registered lookalike sites in the campaign. |
| Private second-level domain | .gr.com |
Private second-level domain pattern cited by researchers as a vehicle used for recently registered lookalike sites in the campaign. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.