Fake Bank Sites Bypass Security Scanners to Avoid Detection
According to a report, fake bank websites use a tactic of appearing inactive to bypass security checks, leveraging a phishing technique called Chameleon SEO Poisoning.
Understanding Chameleon SEO Poisoning
Fortra’s threat intelligence division, FIRE, identified Chameleon SEO Poisoning as a method where attackers manipulate search results and hide malicious banking sites to steal login details while evading detection. The technique involves optimizing fake pages to rank for high-intent search terms like “Bank Name Customer Portal” or “Credit Card Login” on search engines such as Google and Bing.
The Core Risk: Presentation Control
The primary risk lies in “presentation control,” a mechanism where servers dynamically alter content based on access methods. This allows malicious actors to show non-functional, offline-style pages to automated security scans while displaying operational phishing interfaces to users clicking on compromised search results.
Researchers demonstrated this by accessing a typosquat domain under two scenarios: when entered directly without a search engine referral, the site showed a dead page, but when accessed via a poisoned search result, it transitioned to a realistic fake bank login interface.
Mitigation Strategies
Fortra outlines specific actions for different stakeholders to counter Chameleon SEO Poisoning:
For Security Teams
Security teams are advised to incorporate referrer spoofing and browser emulation into routine URL testing, as direct visits no longer reliably indicate legitimacy.
For Hosting Providers and Domain Registrars
Hosting providers and domain registrars should expedite verification processes for second-level domains like .ph.com and .gr.com, and accept referrer-based evidence as valid grounds for removing malicious content.
For CISOs
Chief Information Security Officers (CISOs) should monitor search engine rankings as part of their threat landscape, flagging brand-related keywords that direct to unowned domains.
For Individuals
Individuals accessing online banking services are encouraged to avoid using search bars to navigate to login pages, instead relying on bookmarks or official mobile applications.
The Evolving Cyber Threat Landscape
The technique highlights the dynamic nature of cyber threats, where adversaries exploit technical vulnerabilities and user behavior to maintain persistence in search results. The findings emphasize the need for adaptive security measures that account for dynamic content delivery and the growing sophistication of phishing operations.
Conclusion
Chameleon SEO Poisoning underscores the urgency for proactive security strategies that address both technical and behavioral aspects of modern phishing attacks. Staying informed and adopting recommended mitigation practices is critical for all stakeholders.
