hacker-news · Crawled Jul 25, 2026
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
1 IoCs
Read original article ↗
AI Summary
Recent phishing campaigns targeting insurance providers have evolved from traditional credential harvesting to real-time account hijacking. Attackers use phishing pages as live intermediaries, synchronizing with victims during login sessions to bypass multi-factor authentication by relaying one-time passwords (OTPs) in real time. These operations leverage disposable infrastructure and sophisticated phishing kits like the InsureOTP Kit, enabling immediate account compromise and reducing detection windows.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| GitHub Repo | InsureOTP Kit | Details → |