CTM360 Research has uncovered a sophisticated evolution in insurance phishing campaigns, where attackers now hijack accounts in real time rather than harvesting credentials for later use. The operation, dubbed InsureOTP Kit, leverages Google Ads to lure victims searching for insurance quotations, renewals, or price comparisons. Sponsored advertisements redirect users to phishing sites that closely mimic legitimate insurance portals, often hosted on legitimate platforms like GitHub Pages, Netlify, Hostinger, Wix, and Lovable.
Unlike traditional phishing, these modern campaigns synchronize with victims during the authentication process. As victims submit credentials, attackers simultaneously use the data to log into the genuine insurance portal. When a one-time password (OTP) is sent by the provider, the phishing page prompts the victim to enter it under the guise of identity verification, then relays it to the real site before it expires. This enables attackers to bypass multi-factor authentication and establish authenticated sessions within the same browsing session.
The InsureOTP Kit, a previously undocumented phishing framework, supports real-time victim monitoring, backend administrative dashboards, manual approval workflows, session tracking, Telegram Bot integrations, and live OTP handling. Some variants use Telegram Bot APIs for instant data exfiltration, while others communicate directly with attacker-controlled servers. Backend interfaces can request additional OTP submissions if authentication fails, allowing continued attempts before codes expire.
CTM360 identified publicly accessible backend resources, including administrative components, source code, SQLite databases, and operational records, providing deep insight into the campaign’s infrastructure. The primary target appears to be Saudi Arabia, with additional activity across Europe, the United States, and India. This shift from credential theft to session-time compromise demands a new defensive approach, moving beyond identifying phishing domains to understanding the entire attacker ecosystem.
Malware: InsureOTP Kit
Companies: CTM360, Gartner, GitHub, Netlify, Hostinger, Wix, Lovable
Original source: thehackernews.com