Fortra reported a 40% increase in cloaked “Chameleon” SEO-poisoning campaigns during the second quarter of 2026. The activity targets major financial institutions and their customers by using high-intent banking search terms to push phishing pages into prominent Google and Bing results, while showing benign content to automated scanners and other inspection systems.
The campaigns use newly registered, typosquatted second-level domains rather than compromised legitimate websites, making fraudulent pages appear relevant to users seeking banking services. Organizations should warn customers and employees to reach financial portals through official mobile applications or manually saved bookmarks, rather than search-engine results, and monitor for typosquatted domains impersonating their brands.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Fortra reported a 40% increase in cloaked “Chameleon” SEO-poisoning activity during the second quarter of 2026. The campaigns used newly registered typosquatted domains and banking-related search terms to direct users to phishing pages while evading automated scanning.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.