
Fake Install Guides and Helpdesk Calls Drive Attacks
This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…
Researchers observed insurance-themed phishing that doesn’t just steal passwords, it hijacks accounts in real time while the victim is actively logging in. The attack often starts with sponsored Google ads that lead to convincing fake insurance portals, which immediately prompt victims for one-time passcodes (OTPs) and relay them to the real site before they expire. CTM360 says a purpose-built kit (“InsureOTP Kit”) supports live session monitoring, OTP handling, and even Telegram-based data exfiltration.
This campaign begins not with an email or text message but with a sponsored search ad. Victims searching for insurance quotes or comparisons see ads promising offers like cheap car insurance, and clicking them leads to a polished lookalike insurance portal. The site asks for login credentials and then, framed as routine identity verification, prompts for a one-time passcode (OTP). Rather than storing that OTP for later use, the phishing page relays it to the real insurance provider's site in real time, completing the login before the code expires. Researchers at CTM360 identified a purpose-built framework behind this activity, named the InsureOTP Kit, which includes live session monitoring, admin dashboards, and the ability to request additional OTPs if an authentication attempt fails.
The attack collapses several stages that defenders typically expect to be separated by time. Credential harvesting, OTP interception, and account takeover all happen within a single browsing session, leaving little or no window between theft and abuse. The use of sponsored ads as the delivery mechanism also bypasses common phishing awareness training that focuses on suspicious emails or SMS messages. Because the attacker infrastructure is hosted on legitimate platforms like GitHub Pages, Netlify, Hostinger, and Wix, and rotates frequently, brand monitoring and static blocklists struggle to keep pace.
Organizations in insurance and financial services should treat OTPs as sensitive as passwords and train customers, call center staff, and fraud teams to never enter one on a page reached via an ad or unfamiliar link. Encouraging navigation to insurance and finance logins through official bookmarks or manually typed URLs reduces exposure to malicious ads. Because the entire attack chain can complete in a single session, incident response plans should assume account takeover can happen immediately rather than relying on a delay. Marketing and brand protection teams should also monitor for paid ads abusing the organization's brand and for lookalike portals hosted on common cloud and site-builder platforms, since these are the primary channels this kit relies on.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
It typically starts with a sponsored Google ad promising cheap insurance quotes or comparisons, which redirects victims to a convincing lookalike insurance portal.
The phishing page acts as a live intermediary, capturing the OTP the victim enters and immediately relaying it to the real insurance site before it expires, completing account takeover during the same session.
CTM360 identified and named a previously undocumented phishing framework called InsureOTP Kit that supports live session monitoring, OTP handling, admin dashboards, and Telegram-based data exfiltration.
Attackers used disposable infrastructure built on legitimate hosting and site-builder tools such as GitHub Pages, Netlify, Hostinger, and Wix to rotate sites quickly and evade brand monitoring.
You Google “compare car insurance offers,” click the top ad, and log in. In 30 seconds, your policy is hijacked while you’re still on the page. That ad can lead to a lookalike portal built with the InsureOTP Kit. It relays your username, password, and one-time passcode straight into the real insurance site in real time. Here’s the twist: when your real insurer texts you an OTP, the fake page pops up, “Enter verification code.” You type it, they replay it instantly, and if it fails, they just ask you for another. If you land on any insurance or finance login from a sponsored ad, stop. Close it, type the official address yourself, and only enter OTPs there.

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Amazon says North Korea-linked actors compromised widely used npm packages (including debug and chalk) by tricking a trusted maintainer into signing in through…

Researchers observed LogoKit phishing campaigns that create a unique fake login page for each recipient in real time. The kit pulls a live screenshot of the…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled…