PHISLES is a financially motivated phishing operation active since January 2024 that targets online banking customers in the Philippines. The campaign impersonates major Philippine banks and focuses on stealing usernames, passwords, and one-time passwords from retail banking users in order to conduct rapid account takeover and fund theft. Activity remained ongoing as of January 2026. The operation relies on phishing emails themed around unauthorized transactions or suspicious logins from unknown devices. PHISLES has used compromised email accounts to improve sender legitimacy and evade spam and email security controls. The campaign has also leveraged credential collections obtained from previously stolen account data to source sender-account access. A notable tradecraft shift occurred around mid-2025, when the operators moved away from placing phishing links directly in emails and instead routed victims through chains of legitimate internet services before delivering them to counterfeit banking pages. This infrastructure abuse included trusted web platforms, URL-shortening services, cloud-hosted redirectors, and content-delivery or edge-hosting services to make visible links appear benign and to bypass secure email gateways. The actors also hijacked a legitimate Philippine educational institution’s domain by creating hidden subdomains with valid TLS certificates that redirected victims to attacker-controlled infrastructure while leaving the institution’s normal operations unaffected. PHISLES demonstrates strong social-engineering capability, credential theft, session-time-sensitive fraud execution, and defense evasion through abuse of trusted services and legitimate infrastructure. The operation is best characterized as a cybercriminal phishing actor focused on real-time financial fraud against Philippine banking customers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.