Josh Bonus, Senior Manager, Security Operations at Fortra, and Jitesh Khanna, Security Operations Technical Lead, Credential Theft at Fortra, explain in Help Net Security how Chameleon SEO Poisoning enables threat actors to use manipulated search results and cloaked fake banking websites to steal credentials while avoiding detection. Their research found a more than 40% increase in activity during Q2 2026 and demonstrates how attackers can present different content depending on how a visitor arrives at a website. The findings highlight the need for organizations to adopt context-aware investigation methods and monitor search rankings as part of their phishing defense strategy.
"It is important to clear up a common misconception here: these are not compromised domains by nature. Instead, these domains are typo-squats that have been recently registered on second-level domains (SLDs) like .ph.com, .gr.com, and similar variants."
- FIRE Researchers Josh Bonus and Jitesh Khanna, Help Net Security