Fortra disclosed a phishing campaign dubbed Chameleon SEO Poisoning that manipulates Google and Bing results to steer users searching for financial services to fraudulent banking login pages. The operation uses recently registered typosquat and lookalike domains, including private second-level domain patterns such as .ph.com and .gr.com, to impersonate major financial institutions and capture customer credentials. Fortra’s FIRE team said it tracked the activity for three months and observed a 40% increase in cases during Q2 2026.
The campaign relies on cloaking and server-side presentation control to evade detection: users arriving from poisoned search results are shown convincing bank portals, while direct visitors, automated scanners, registrars, and hosting providers may see inactive or benign pages instead. Researchers said the tactic shifts phishing away from email and SMS toward search-driven victim acquisition at the moment users intend to log in, and urged defenders to test suspicious URLs with referrer spoofing and browser emulation, monitor branded search rankings and newly registered lookalike domains, and accelerate takedowns tied to suspicious second-level domain abuse.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Fortra disclosed Chameleon SEO Poisoning as a phishing method that poisons search results and uses cloaked fake banking websites to evade scanners and steal credentials. The company said the infrastructure commonly used recently registered typosquat domains on second-level domains such as .ph.com and .gr.com.
Fortra reported a 40% increase in Chameleon SEO Poisoning cases during the second quarter of 2026. The campaign targeted major financial institutions and users searching for banking login pages through Google and Bing.
Fortra's FIRE team tracked a phishing technique it calls Chameleon SEO Poisoning over a three-month period. The activity used SEO-manipulated search results, lookalike domains, and cloaked fake banking pages to steal credentials.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.