CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
A new investigation by CTM360 reveals a significant evolution in insurance phishing attacks, moving beyond simple credential harvesting to real-time account hijacking. Attackers now synchronize their activity with victims during legitimate insurance portal logins, intercepting OTPs and completing authentication in real-time. This sophisticated approach, supported by operational phishing kits and disposable infrastructure, significantly reduces the window of opportunity for defenders to detect and prevent account compromise. The campaign utilizes paid Google ads to lure victims and employs a previously undocumented phishing kit, InsureOTP Kit, to manage victim sessions and exfiltrate data.
For years, phishing campaigns targeting financial institutions followed a predictable pattern: attackers would steal usernames and passwords, and then exploit them later when an opportunity arose. However, a new investigation by CTM360 reveals a significant evolution in insurance phishing attacks, moving beyond simple credential harvesting to real-time account hijacking. Attackers now synchronize their activity with victims during legitimate insurance portal logins, intercepting OTPs and completing authentication in real-time.
This sophisticated approach, supported by operational phishing kits and disposable infrastructure, significantly reduces the window of opportunity for defenders to detect and prevent account compromise. The campaign utilizes paid Google ads to lure victims, directing them to convincingly replicated insurance provider portals. These portals closely mimic the branding, user interfaces, and quotation workflows of genuine insurance companies, designed to minimize suspicion throughout the interaction.
Insurance has become an increasingly attractive target, with customers now able to purchase policies, renew coverage, submit claims, manage accounts, update personal information, and complete payments entirely through digital portals. This expansion of online services creates a rich environment for threat actors.
Unlike traditional banking attacks that primarily target financial transactions, compromised insurance accounts often contain extensive personal information, identity documents, policy records, payment methods, and other sensitive customer data that can support fraud far beyond the initial compromise. The investigation identified a previously undocumented phishing kit named InsureOTP Kit, purpose-built for insurance-themed phishing operations. This kit provides live session management, real-time data collection, backend administration, and multiple data exfiltration methods.
Unlike older phishing kits that simply emailed captured credentials, InsureOTP Kit allows operators to actively manage each victim session. Observed capabilities included: real-time victim monitoring, backend administrative dashboards, manual approval workflows, session tracking, Telegram Bot integrations, direct backend API communication, and live OTP handling. Some variants relied on Telegram Bot APIs to receive structured victim submissions instantly, while others transmitted information directly to attacker-controlled backend servers. Researchers also observed backend interfaces capable of requesting additional OTP submissions whenever authentication failed, allowing operators to continue attempting account access before authentication codes expired.
One of the more valuable aspects of cyber threat intelligence is the ability to move beyond individual phishing pages and understand the broader campaign ecosystem. During the investigation, CTM360 identified publicly accessible backend resources associated with the phishing infrastructure. Analysis of exposed archives revealed administrative components, backend source code, SQLite databases, operational records, and supporting infrastructure that provided insight into how the phishing framework functioned. The investigation demonstrates why modern threat intelligence extends beyond identifying malicious domains or phishing websites. By analyzing the underlying infrastructure, tooling, backend components, and attacker workflows, defenders can gain a much deeper understanding of how campaigns are developed, managed, and executed.
For defenders, this means detection cannot rely solely on identifying phishing domains after they appear online. Organizations should monitor for paid advertisements abusing their brands, newly registered lookalike domains, disposable cloud-hosted phishing infrastructure, and authentication patterns that indicate real-time OTP interception. Equally important is understanding the attacker ecosystem behind these campaigns rather than treating each phishing site as an isolated incident. This reflects a broader shift taking place across the cybersecurity industry as well. Digital Risk Protection (DRP) has traditionally focused on identifying external threats such as phishing websites, brand impersonation, and malicious domains. Today, organizations increasingly require Cyber Threat Intelligence (CTI) that explains how campaigns operate, how attacker infrastructure is connected, how phishing kits evolve, and how adversaries execute and adapt their operations. CTM360 has undergone this same evolution, expanding from a Digital Risk Protection platform into a broader Cyber Threat Intelligence platform. Earlier this year, CTM360 was recognized as one of the vendors included in Gartner's inaugural Magic Quadrant™ for Cyber Threat Intelligence Technologies.
