GBHackers

Google and Bing Search Results Used to Deliver Hidden Banking Phishing Pages


Threat actors are increasingly using Google and Bing as phishing delivery channels, employing a cloaking technique that presents harmless pages to security scanners while serving credential-harvesting banking portals to genuine search users.

The campaigns target users of major financial institutions and combine search-engine optimization abuse, recently registered lookalike domains, and referral-aware payload delivery to extend phishing-page lifespans.

Unlike conventional phishing operations that push malicious links through email or SMS, Chameleon campaigns use a pull-based model.

Attackers manipulate search-engine results pages to position fraudulent sites for high-intent queries such as “Bank Name Customer Portal,” “Credit Card Login,” or similar account-access terms.

Victims searching for a financial service may therefore encounter a malicious result that appears above, or close to, the legitimate banking page.

The attacker-controlled domains are often typo-squats hosted on recently registered second-level-domain structures, including variants under domains such as .ph.com and .gr.com, rather than necessarily being compromised legitimate websites.

This approach turns search visibility into an initial-access vector. A user’s trust in a familiar search engine and the urgency of accessing an account does much of the social-engineering work for the operator.

Fortra Intelligence and Research Experts (FIRE) reported that “Chameleon SEO Poisoning” activity rose by more than 40% in Q2 2026.

Google and Bing Search Results

The defining feature of Chameleon SEO Poisoning is presentation control. The same URL returns different content depending on how the visitor arrives.

When a researcher, hosting provider, reputation service, or automated sandbox accesses the suspicious domain directly, the server may return an offline page, generic error, or fake 404 response.

This makes the domain appear inert and can cause analysts to dismiss an alert as a false positive incorrectly.

However, when the request contains a referrer indicating that the visitor clicked through from Google or Bing, the site serves its active payload: typically a high-fidelity clone of a banking login portal designed to capture credentials, session cookies, or other authentication material.

FIRE warned that these campaigns can facilitate credential theft and session hijacking while remaining active longer than traditional phishing infrastructure.

The technique effectively conditions the phishing page on the victim’s journey. The poisoned search result is the hook, while the direct visit becomes the mask.

Most domain-reputation systems and automated URL scanners evaluate a site through a direct request. That model is poorly suited to a campaign that evaluates the requester first.

A scanner using a default scripting user agent, a data-center IP address, or no search referrer may receive the clean version of the page.

The malicious domain can consequently preserve a neutral reputation score even while banking customers arriving through search results are exposed to a live credential-harvesting portal.

Fortra recommends that SOC teams move beyond static scans and emulate victim conditions.

Investigations should test relevant search-engine referrers, modern consumer-browser user agents, and where legally and operationally appropriate geographic profiles aligned with the targeted institution’s customer base.

For CISOs, this shifts brand-protection strategy from reactive takedowns toward continuous monitoring of search results for brand, login, and support keywords.

Anomalous top-ranking results, especially those using newly registered lookalike domains, should be treated as a high-priority fraud signal.

FIRE previously documented how SEO-poisoning services can use backlink manipulation and compromised sites to elevate fraudulent financial pages, underlining the scale and commercial maturity of this ecosystem.

SOC playbooks should also prohibit closing a suspicious-URL case solely because a direct visit returns an offline page.

Analysts need context-aware evidence collection that records the referrer, user agent, redirect chain, rendered content, and geographic response behavior.

For consumers, the safest approach remains avoiding search engines to reach banking portals. Use an official banking application or a manually saved bookmark, inspect the full domain before entering credentials, and contact the institution through a verified channel if a login page appears unusual.

★ Which Security Tools Should You Cut? Score Them on One Page – Download the Inherited Security Stack Guide



Source link