Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Anthropic Reveals Claude Escaped Testing, Breaching Three Companies

July 31, 2026

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

July 31, 2026

Cryptominer Abuses Linux PAM to Hide From SOC Analysts

July 31, 2026
Facebook X (Twitter) Instagram
Friday, July 31
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
News

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

Team-CWDBy Team-CWDJuly 31, 2026No Comments8 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose.

That model is changing.

Recent investigations into insurance-focused phishing operations reveal a more immediate approach. Instead of harvesting credentials for later use, attackers now synchronize their activity with victims in real time, authenticating against legitimate insurance portals as victims unknowingly complete the login process. The entire attack can unfold within a single browsing session.

This shift highlights a broader trend across the cybersecurity landscape. As phishing campaigns become more sophisticated, simply identifying malicious websites and impersonation domains is no longer enough. Organizations increasingly need to understand the infrastructure, techniques, and operational workflows behind these attacks.

Insurance Has Become an Increasingly Attractive Target

Insurance providers have rapidly expanded their online services. Customers can now purchase policies, renew coverage, submit claims, manage accounts, update personal information, and complete payments entirely through digital portals.

While this improves customer experience, it also creates an attractive environment for threat actors.

Unlike traditional banking attacks that primarily target financial transactions, compromised insurance accounts often contain extensive personal information, identity documents, policy records, payment methods, and other sensitive customer data that can support fraud far beyond the initial compromise.

During the investigation, a coordinated phishing operation targeting multiple insurance providers across several regions was identified. Rather than impersonating a single organization, the campaign reused the same operational infrastructure across numerous insurance brands, adapting language, branding, and content to match local markets. Saudi Arabia appeared to be the primary target, while additional activity was observed across Europe, the United States, and India.

Google Ads Are Becoming the Initial Attack Vector

One of the more notable observations was the consistent use of sponsored Google advertisements as the primary delivery mechanism.

Instead of relying on phishing emails or SMS campaigns, attackers purchase advertisements that appear when users search for insurance quotations, renewals, or price comparisons. The advertisements promoted offers such as “Compare car insurance offers” or “Cheapest third-party insurance,” encouraging users to click what appeared to be legitimate quotation services.

After clicking the advertisement, victims are redirected to phishing websites designed to closely resemble genuine insurance providers. These sites replicated branding, user interfaces, quotation workflows, and customer portals with a level of realism intended to reduce suspicion throughout the interaction.

The infrastructure supporting these campaigns was equally disposable. Rather than relying on dedicated malicious hosting, operators frequently leveraged legitimate website builders and free hosting platforms such as GitHub Pages, Netlify, Hostinger, Wix, Lovable, and other cloud services. Randomized domains with little or no resemblance to insurance brands allowed campaigns to rotate rapidly while reducing the effectiveness of conventional brand-monitoring efforts.

Phishing Has Evolved into Real-Time Account Hijacking

Phishing campaigns have long been used to steal sensitive information, including personal information, financial details, payment card data, insurance records, and account credentials. In many cases, the objective was to collect as much information as possible and exploit it later through account takeover, identity fraud, or financial abuse.

Modern insurance phishing campaigns represent a significant evolution of this model. Rather than functioning as static data collection pages, these phishing portals actively engage with victims throughout the authentication process. As victims submit their information, attackers simultaneously use the collected data to interact with the legitimate insurance portal in real time, turning the phishing page into a live intermediary between the victim and the genuine service.

This approach allows attackers to overcome authentication mechanisms that would traditionally limit the usefulness of stolen credentials. When the legitimate insurance provider sends a one-time password (OTP) or other verification challenge, the phishing page immediately prompts the victim to enter the same code under the guise of routine identity verification. The submitted OTP is then relayed to the legitimate portal before it expires, enabling attackers to complete the authentication process while the victim remains unaware.

Instead of simply harvesting information for future use, these campaigns synchronize every stage of the login process, allowing attackers to validate credentials, satisfy multi-factor authentication requirements, and establish authenticated sessions in real time. The result is a far more effective form of phishing that transforms what was once a data collection exercise into an active account hijacking operation, significantly reducing the opportunity for victims or defenders to detect and interrupt the attack before access is gained.

Modern Phishing Kits Function Like Operational Platforms

Analysis of the phishing infrastructure revealed that these campaigns are supported by considerably more than static phishing pages.

During the investigation, CTM360 identified a previously undocumented phishing kit and named it InsureOTP Kit. The kit is purpose-built for insurance-themed phishing operations, providing live session management, real-time data collection, backend administration, and multiple data exfiltration methods.

Unlike older phishing kits that simply emailed captured credentials, this framework allows operators to actively manage each victim session.

Observed capabilities included:

  • Real-time victim monitoring
  • Backend administrative dashboards
  • Manual approval workflows
  • Session tracking
  • Telegram Bot integrations
  • Direct backend API communication
  • Live OTP handling

Some variants relied on Telegram Bot APIs to receive structured victim submissions instantly, while others transmitted information directly to attacker-controlled backend servers. Researchers also observed backend interfaces capable of requesting additional OTP submissions whenever authentication failed, allowing operators to continue attempting account access before authentication codes expired.

These capabilities demonstrate how phishing kits continue to evolve from simple credential collectors into interactive attack platforms designed for live account compromise.

Infrastructure Can Reveal the Entire Operation

One of the more valuable aspects of cyber threat intelligence is the ability to move beyond individual phishing pages and understand the broader campaign ecosystem.

During the investigation, CTM360identified publicly accessible backend resources associated with the phishing infrastructure. Analysis of exposed archives revealed administrative components, backend source code, SQLite databases, operational records, and supporting infrastructure that provided insight into how the phishing framework functioned.

The investigation demonstrates why modern threat intelligence extends beyond identifying malicious domains or phishing websites. By analyzing the underlying infrastructure, tooling, backend components, and attacker workflows, defenders can gain a much deeper understanding of how campaigns are developed, managed, and executed.

Rather than asking “Where is the phishing page?” investigators are asking “How does the campaign operate?”

This shift reflects one of the most significant changes in modern cyber threat intelligence, moving beyond the detection of individual threats toward understanding the adversary’s infrastructure, tooling, and operational methodology.

Why Defenders Need a Different Approach

The defining characteristic of this campaign is not simply credential theft; it is session-time compromise.

Traditional incident response assumes there is a delay between credential theft and account abuse. That assumption no longer always holds.

In these operations, credential harvesting, OTP interception, and account takeover occur as part of a single continuous workflow. By the time a victim realizes something is wrong, the attacker may already have authenticated successfully and gained access to the legitimate account.

For defenders, this means detection cannot rely solely on identifying phishing domains after they appear online.

Organizations should monitor for paid advertisements abusing their brands, newly registered lookalike domains, disposable cloud-hosted phishing infrastructure, and authentication patterns that indicate real-time OTP interception.

Equally important is understanding the attacker ecosystem behind these campaigns rather than treating each phishing site as an isolated incident.

Looking Beyond the Phishing Page

Insurance phishing campaigns provide a clear example of how external threats continue to evolve.

Attackers are optimizing for speed, automation, and immediate access rather than delayed exploitation. Infrastructure is increasingly disposable, phishing kits are becoming operational platforms, and account compromise now occurs during the victim’s active session rather than afterward.

For defenders, this reinforces an important reality. Identifying malicious websites alone is no longer enough. Security teams increasingly need contextual intelligence that connects infrastructure, attacker workflows, tooling, and campaign behavior to understand how threats evolve and where they can be disrupted before they reach customers.

This reflects a broader shift taking place across the cybersecurity industry as well. Digital Risk Protection (DRP) has traditionally focused on identifying external threats such as phishing websites, brand impersonation, and malicious domains. Today, organizations increasingly require Cyber Threat Intelligence (CTI) that explains how campaigns operate, how attacker infrastructure is connected, how phishing kits evolve, and how adversaries execute and adapt their operations.

CTM360 has undergone this same evolution, expanding from a Digital Risk Protection platform into a broader Cyber Threat Intelligence platform. Earlier this year, CTM360 was recognized as one of the vendors included in Gartner’s inaugural Magic Quadrant™ for Cyber Threat Intelligence Technologies.

While this investigation focuses on an insurance phishing campaign, it also demonstrates why modern security programs require intelligence that goes beyond identifying individual indicators to understanding complete adversary operations.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.





Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCryptominer Abuses Linux PAM to Hide From SOC Analysts
Next Article Anthropic Reveals Claude Escaped Testing, Breaching Three Companies
Team-CWD
  • Website

Related Posts

News

Anthropic Reveals Claude Escaped Testing, Breaching Three Companies

July 31, 2026
News

Cryptominer Abuses Linux PAM to Hide From SOC Analysts

July 31, 2026
News

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

July 31, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What’s at stake if your employees post too much online

December 1, 2025

What it is and how to protect yourself

January 8, 2026

A stealthy RAT burrowing deep into Android devices

May 26, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.