Fake Bank Sites ‘Play Dead’ to Steal Logins

About DFIR · Medium sophistication
Last updated August 24, 2026

Researchers documented a real phishing method where attackers push fake bank sites up in search results, then show different content depending on how a person arrived. If someone clicks from a poisoned search result, the site shows a realistic bank login page to steal credentials; if security teams visit directly, it shows a harmless “offline” page to evade scanning. Defenders are advised to validate suspicious URLs using referrer spoofing and browser emulation because a direct visit may hide the scam.

Key findings

  • Attackers manipulate search rankings and use typosquatted banking domains to capture login credentials.
  • The phishing site uses “presentation control” (cloaking) to show a fake bank login only to visitors coming from poisoned search results.
  • Security teams may see a benign “dead/offline” page if they test by typing the domain directly, allowing the scam to evade automated scanning.
  • Researchers reported a 40% increase in observed cases in Q2 2026.
  • Defensive guidance: use referrer spoofing and browser emulation when validating reported URLs.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Security operations / Incident response, Helpdesk / IT support.
  • Affected industries: Banking / Financial services.
  • Attack channels: website.
  • Impersonated: A victim’s bank (look-alike/typosquatted domain).

Awareness takeaways

  • Avoid logging into banks (and other sensitive services) via search results; use saved bookmarks or official apps.
  • Treat ‘offline’ or blank pages as suspicious when investigating a reported URL; attackers may be hiding the real phishing page from direct visits.
  • For security validation and triage, test suspicious URLs using controlled browser emulation/referrer techniques, direct visits alone may not reveal the threat.

Red flags to watch for

  • Login page reached via search result rather than a trusted bookmark/app
  • Domain is a look-alike or slightly misspelled bank address (typosquatted)
  • Site behavior changes depending on how you arrive (cloaking/presentation control)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You Google your bank, click the top result, and the site looks a little slow… no big deal, right? Behind that click is a trick called Chameleon SEO Poisoning. From search, you get a perfect fake bank login. But if IT types the same address in directly, it plays dead and shows a harmless offline page. Researchers are seeing more of this: typosquatted bank sites boosted in search, using presentation control to steal logins while dodging our scanners and even manual checks that just type the URL in. Here’s the move: never log in to your bank from a search result. Use your saved bookmark or the official banking app every time.

Similar attacks

Fake Bank Login Pages Hide From Scanners

Fake Bank Login Pages Hide From Scanners

Researchers observed phishing sites that appear “dead” to security scanners but turn into convincing fake bank login pages when a victim arrives from poisoned Google/Bing search results. The goal is to steal banking credentials while keeping the malicious pages online for days or weeks by showing…

August 24, 2026
Manic Android Spyware Uses Fake Utility Apps

Manic Android Spyware Uses Fake Utility Apps

A new Android malware family called “Manic” is being used in real campaigns targeting banking, government identity, and messaging apps, especially in Ukraine and parts of Europe. It spreads through phishing sites and “dropper” apps disguised as legitimate utilities (including a booking-app lure),…

August 20, 2026
Vishing “Help Desk” Scams and Lookalike Phish Surge

Vishing “Help Desk” Scams and Lookalike Phish Surge

This weekly roundup highlights multiple real-world social engineering threats, including fake IT help-desk phone calls that push employees to phishing sites to steal passwords and one-time authentication codes. It also describes credential-phishing sites impersonating WhatsApp and Instagram that…

August 14, 2026
Wall Street Hit by Helpdesk Impersonation Calls

Wall Street Hit by Helpdesk Impersonation Calls

A phone-first extortion campaign targeted dozens of major U.S. financial firms by calling employees and posing as corporate help-desk staff. Victims were pushed to “update” passkeys/MFA and sent to fake login pages; attackers captured passwords and MFA codes in real time to take over accounts and…

August 7, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026