Fortra’s threat‑intelligence team has uncovered a sophisticated phishing technique dubbed Chameleon SEO Poisoning, which leverages manipulated search‑engine results and cloaked counterfeit banking sites to harvest user credentials while slipping past conventional security scanners. The method relies on classic search‑engine optimization (SEO) poisoning to push malicious pages ahead of legitimate banking portals for high‑intent queries such as “Bank Name Customer Portal” or “Credit Card Login.” By securing top positions on Google and Bing, attackers increase the likelihood that unsuspecting users will click the fraudulent link instead of the authentic site.
Unlike many phishing campaigns that hijack existing domains, the Chameleon approach exploits freshly registered typo‑squat domains on second‑level domains (SLDs) such as .ph.com, .gr.com, and other similar variants. These SLDs are not compromised by default; rather, they are deliberately chosen because they closely resemble the brand’s official web address, making the deception more convincing at a glance. The newly registered nature of the domains also means that traditional domain‑reputation tools may have insufficient data to flag them as malicious.
Central to the attack is the concept of “presentation control.” The compromised server is programmed to examine the HTTP referrer header—the information indicating the page from which a visitor arrived. When a request originates from a search engine result, the server delivers a fully functional replica of a bank’s login interface, complete with branding elements that match the target institution. Conversely, a direct navigation to the same URL, lacking a search‑engine referrer, returns a barren page that appears offline or under construction. This conditional rendering effectively hides the malicious payload from automated crawlers and routine security sweeps that typically access URLs without a referrer.
Fortra’s researchers demonstrated the dual behavior by accessing a single typo‑squat domain under two distinct circumstances. A manual entry of the URL, with no referrer attached, produced a dead‑end page that would likely be dismissed by a cautious user. In contrast, clicking the link from a poisoned search result caused the same domain to instantly transform into a polished, counterfeit bank login page, complete with input fields for usernames and passwords. The rapid switch shows how the technique can remain active for days or weeks before any anomaly is detected.
Related: AI blurs the line between fraud and identity
The emergence of Chameleon SEO Poisoning prompted a three‑month investigative effort by Fortra Intelligence and Research Experts (FIRE), during which they observed a 40 % increase in reported incidents in the second quarter of 2026. This surge highlights the growing adoption of the method among threat actors seeking to bypass static detection mechanisms.
Mitigation strategies differ by stakeholder, reflecting the varied points of influence across the ecosystem. Security teams are advised to incorporate referrer spoofing and browser‑emulation steps into their URL testing workflows. By simulating traffic that appears to come from a search engine, analysts can reveal the hidden malicious content that would otherwise remain invisible during a straightforward direct visit.
- Hosting providers and domain registrars should accelerate their vetting processes for SLDs such as .ph.com and .gr.com. Accepting evidence of referrer‑triggered content as sufficient cause for takedown can reduce the window of exposure for victims.
- CISOs need to treat search‑engine rankings as an attack surface. Continuous monitoring of brand‑related keywords can surface unauthorized domains that begin to rank for legitimate brand terms, allowing rapid response before user interaction occurs.
- End users who conduct online banking are encouraged to bypass search engines altogether when accessing their financial institution. Bookmarking the official login page or using the bank’s dedicated mobile application eliminates the risk of encountering a poisoned search result.
Beyond the immediate technical safeguards, the phenomenon illustrates a broader shift in phishing tactics toward dynamic content delivery based on contextual cues. Attackers are increasingly exploiting the trust users place in search‑engine rankings, assuming that a top‑position result must be safe. By manipulating the presentation layer, they can tailor the user experience in real time, rendering static detection tools ineffective. Organizations that adopt a proactive stance—regularly auditing search rankings, tightening domain‑registration policies, and enhancing testing procedures—will be better positioned to disrupt the lifecycle of such campaigns before credentials are compromised.
