All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Cybercriminals can now drain your bank account without you clicking on unsolicited links in phishing emails or SMS messages. Fake banking websites have now made their way to the top of search engine results.
Researchers have found attackers using a new phishing technique called Chameleon SEO poisoning, through which they can rank typosquatted websites that closely resemble legitimate banking portals higher in search engine results.[1]
Once you land on one of these fake banking sites, attackers may not only steal your credentials but also hijack your active session, potentially giving them access to your account.
Here’s how Chameleon SEO poisoning works and how you can stay safe with just a little caution.
Why is Chameleon SEO poisoning so difficult to detect
What happens if you fall for Chameleon SEO poisoning
What can you do to protect yourself
Bottom line
What is Chameleon SEO poisoning
Fortra Intelligence and Research Experts (FIRE) have published a report highlighting a 40% increase in a new phishing tactic called Chameleon SEO poisoning.
Under this technique, malicious actors use search engine optimization (SEO) to trick search engines into ranking their malicious pages higher than legitimate websites.
So, when you search for your banking portal on a search engine and inadvertently click on the first link available, you could land on an attacker’s typosquatted domain instead of the real one.
It’s worth noting that the legitimate domains themselves are not hijacked. Instead, these are fake ones, carefully crafted typosquatted pages with only a minor tweak to their domain names, which could be very easy for the average user to overlook.
As per FIRE’s report, these websites have recently been registered on second-level domains such as .ph.com or .gr.com.
Attackers aim to reproduce a convincing copy of the legitimate website by using the exact logos, color scheme, and layout so that the potential victim does not suspect that they’re on a malicious website.
Why is Chameleon SEO poisoning so difficult to detect
Unlike traditional phishing attempts, which rely heavily on “push” techniques such as sending mass emails and SMS messages to potential victims, Chameleon SEO poisoning adopts a “pull” technique by allowing search engines to do most of the work.
But the bigger problem is that these sites use a technique called cloaking to avoid detection. This means that if a security analyst or threat-intelligence bot visits the malicious domain directly, the server will return an error, a fake 404 page, or fail to load altogether. When someone visits the website directly, the HTTP referrer doesn’t indicate that the user clicked the link from a search engine, so the site refuses to load.
However, when users click on the link through a search engine, the HTTP referrer header is available, allowing the website to open.
From a user standpoint, the fact that the website shows up at the top of search engine results is the biggest deception. Naturally, users are more likely to trust a site that appears prominently in their search results.
What happens if you fall for Chameleon SEO poisoning
Once inside, attackers can transfer funds or initiate unauthorized transactions. They could also hijack your active session, potentially allowing them to access your account even when additional authentication, such as 2FA codes, is involved.
FIRE specifically identifies credential theft and session hijacking as the phishing payloads used in these attacks.
If you’re someone who uses the same credentials across accounts, you can fall prey to credential stuffing, which is when attackers test your stolen credentials against other accounts, such as email, social media, or online brokerage accounts, significantly increasing your attack surface.
The websites may also include a fake “Download Our App” or similar button, which could silently install malware or information stealers on your device.
This could lead to the exfiltration of saved passwords and browser cookies from your device, potentially resulting in identity theft and account takeovers.
Even worse, attackers could sell your harvested credentials on the dark web, where banking credentials could be misused by other threat actors and expose you to repeated attacks.
What can you do to protect yourself
The consequences of handing over your banking and other sensitive information to attackers are grave, but luckily, there are several safe online banking practices you can implement to protect yourself.
- Pay attention to the address bar: Since attackers can visually clone a banking website pixel by pixel, it could be very difficult to distinguish a fake website from a genuine one. The only reliable tell is the actual domain name shown in the website’s address bar. If you’re on a sensitive website such as a banking portal, it always pays to verify the actual domain name before proceeding with your transaction.
- Use bookmarks: Do not access banking portals through search engines. Instead, use mobile applications or bookmarked URLs to access financial-service portals. Make sure you bookmark the correct URL from an official source, such as your card statement or banking app. This will eliminate any guesswork the next time you access your banking portal.
- Use a password manager with autofill: This can be an effective way to avoid falling for typosquatted domains. Password managers not only remember your passwords but also autofill them when you visit the same website. So, if you land on a different website, say yourbank.ph.com instead of yourbank.com, the password manager simply won’t autofill your credentials. That, in itself, is a big red flag.
- Use a third-party antivirus program: Many antiviruses come with real-time protection, which could flag suspicious websites before you visit them. These antiviruses show you a warning before you interact with such websites, helping prevent further interaction. They’ll also protect you in case a malicious site tries to install malware on your device.
- Use an identity theft protection service: If you’ve already become a victim of such an attack, there’s a chance that your credentials are already out there in the wild. In such a scenario, consider getting an identity theft protection service. These tools scan the dark web and other databases for your leaked credentials and notify you when they find any. Many providers also offer professional identity restoration services, which could help you recover from the attack and minimize potential financial losses.
Bottom line
The new Chameleon SEO poisoning technique takes phishing to the next level by avoiding detection through cloaking. Plus, the fact that phishing sites now rank in search engine results makes it even more difficult for unsuspecting users to spot them.
Once you land on a fake banking portal, attackers can quickly drain your funds and cause significant financial losses. That said, a little awareness on your side could help you avoid becoming a victim of this type of attack.
Always double-check the website URL, bookmark legitimate URLs and only use those, and use third-party protection tools like a password manager with autofill, an antivirus program, and an identity theft protection service.
[1] The "Chameleon" Threat: Unmasking and Mitigating Cloaked SEO Poisoning in Financial Services