A phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners has been discovered by Fortra.
The company’s threat intelligence unit, Fortra Intelligence and Research Experts (FIRE), spent three months tracking the technique and reports a 40% jump in cases during the second quarter of 2026.
Attackers rank these pages for high-intent keywords such as “Bank Name Customer Portal” or “Credit Card Login” on Google and Bing, using standard SEO poisoning to climb above the legitimate site.
“It is important to clear up a common misconception here: these are not compromised domains by nature. Instead, these domains are typo-squats that have been recently registered on second-level domains (SLDs) like .ph.com, .gr.com, and similar variants,” researchers said.
The danger comes from what researchers call presentation control, the server’s ability to decide what a visitor sees based on how they arrived. By serving different content depending on where the click came from, the technique keeps standard security sweeps from spotting the threat, letting poisoned search results stay active for days or weeks, Fortra noted.
Researchers demonstrated the effect directly, pulling up one typosquat domain under two different conditions. Typed in by hand, with no search engine referrer attached, the domain served a dead, offline-looking page.
Clicked through from the poisoned search result, the same domain immediately switched to a convincing fake bank login page.
Actionable recommendations
Fortra’s recommendations split by role:
Security teams should treat referrer spoofing and browser emulation as standard steps when testing a reported URL, since a direct visit alone no longer tells them anything reliable.
Hosting providers and registrars are advised to speed up vetting on SLDs like .ph.com and .gr.com, and accept referrer-triggered evidence as grounds for a takedown.
CISOs should watch search rankings as an attack surface, flagging brand keywords that suddenly point to a domain they don’t own.
Anyone banking online is better off skipping the search bar for the bank’s login page and bookmarking it instead, or using the bank’s official app.
