hacker-news · Crawled Jul 25, 2026

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

1 IoCs
Read original article ↗

AI Summary

Recent phishing campaigns targeting insurance providers have evolved from traditional credential harvesting to real-time account hijacking. Attackers use phishing pages as live intermediaries, synchronizing with victims during login sessions to bypass multi-factor authentication by relaying one-time passwords (OTPs) in real time. These operations leverage disposable infrastructure and sophisticated phishing kits like the InsureOTP Kit, enabling immediate account compromise and reducing detection windows.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
GitHub Repo InsureOTP Kit Details →