CyberSecurityNews

Hackers Poison Google and Bing Results to Deliver Cloaked Banking Phishing Pages


Bank customers searching for a login page can now be led into a trap before they receive a suspicious email or text message.

Criminals are manipulating Google and Bing results so that fraudulent banking pages appear where people expect to find legitimate services.

The campaign, called Chameleon SEO Poisoning, turns ordinary searches for terms such as a bank customer portal or credit card login into a phishing opportunity.

Victims who click a highly ranked result can be shown a convincing copy of a banking site built to collect passwords and hijack active sessions.

Analysts at Fortra Intelligence and Research Experts, known as FIRE, identified a sharp rise in this activity during the second quarter of 2026. The campaigns targeted several major financial institutions and their customers.

Poisoned SERP (Source – Fortra)

Fortra said in a report shared with Cyber Security News (CSN) that the sites are designed to look harmless when inspected in the usual way, delaying reports and takedowns. This gives attackers more time to capture credentials for consumers and financial institutions alike.

Hackers Poison Google and Bing Results

The operation relies on search engine optimization poisoning, a tactic that pushes attacker-controlled pages higher for high-intent searches. Instead of compromising a real website, the operators register lookalike names, then build pages around the words users type into Google or Bing.

This approach moves phishing away from the usual push model of bulk emails and messages. It pulls victims in at the moment they are looking for their bank.

Similar abuse has placed fake software download links near the top of Bing, showing how search rankings can become an effective delivery channel for fraud and malware.

Direct Access (The Mask) (Source - Fortra)
Direct Access (The Mask) (Source – Fortra)

The crucial trick is cloaking. A direct visit by a security researcher, automated scanner, registrar or hosting provider may receive an inactive page or a false 404 error.

The same address can deliver a pixel-perfect banking portal only when its server sees that the visitor arrived through a Google or Bing search result.

Attackers use this presentation control to remain online for days or weeks. The method also helps explain why a reported link can appear clean during a routine check while real customers continue to encounter an active credential theft page.

Why Routine Checks Fall Short

Most reputation services and passive scanners examine a site in isolation. When they browse a suspicious address directly, the Chameleon page can identify the missing search referral and return harmless content.

A security operations team may then mark the alert as a false positive, even though the malicious version is reserved for search users.

Researchers recommend testing suspicious results in the same context as the victim. That means using a current consumer-browser profile, passing the relevant search referrer and, where appropriate, checking from the geography of the bank’s customers.

The goal is to reproduce what an ordinary user sees rather than what a default script receives. Defenders should also watch recently registered lookalike domains and unusual top-ranking results for branded banking terms.

The broader pattern resembles search poisoning attacks on Windows, where small changes in a domain name and a credible-looking page can direct a searcher to a harmful destination.

Search Referral (The Hook) (Source - Fortra)
Search Referral (The Hook) (Source – Fortra)

For consumers, the safest route is to open a bank through its official mobile app or a previously saved bookmark, not a search result.

That simple habit reduces exposure to pages that imitate trusted brands, much as banking phishing through trusted platforms exploits familiar services to make a theft attempt look legitimate.

Organizations should treat search visibility as part of their attack surface, not merely a marketing concern.

Context-aware monitoring, faster review of cloaked evidence and stronger checks on rapid registrations can help expose these pages. SEO poisoned enterprise downloads show that the technique can target customers and employees.

The immediate lesson is straightforward: a prominent result is not proof of authenticity. Banks, security teams and users need to verify the route to a financial service, because attackers are increasingly hiding their phishing pages behind the trust people place in search engines.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Private second-level domain.ph.comPrivate second-level domain pattern cited by researchers as a vehicle used for recently registered lookalike sites in the campaign.
Private second-level domain.gr.comPrivate second-level domain pattern cited by researchers as a vehicle used for recently registered lookalike sites in the campaign.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC



Source link