Phishing campaigns targeting financial institutions are evolving from credential harvesting for later use to real-time account hijacking, based on information published by The Hacker News.Recent investigations reveal a shift in phishing operations, particularly targeting the insurance sector, which has become an attractive target due to expanded online services for customers. Attackers are now synchronizing their activities with victims in real time, authenticating against legitimate insurance portals as victims unknowingly complete the login process within a single browsing session. This sophisticated approach often begins with sponsored Google advertisements, directing users to phishing websites that closely mimic genuine insurance providers. These sites replicate branding and user interfaces to reduce suspicion. The underlying infrastructure is disposable, frequently utilizing legitimate website builders and free hosting platforms. A key development is the "InsureOTP Kit," a phishing kit designed for live session management and real-time data collection, including the interception of one-time passwords (OTPs) to bypass multi-factor authentication. This evolution transforms phishing from a data collection exercise into an active account hijacking operation, requiring defenders to adopt a more comprehensive approach beyond identifying malicious domains to understanding attacker infrastructure, tooling, and operational methodologies.Source: The Hacker News
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds




