Trusted Online Platforms Exploited In Credential Theft Attacks Targeting Filipinos

Despite robust security defenses, email phishing remains a dominant and highly effective threat. Cybercriminals frequently impersonate reputable financial institutions, exploiting the trust these brands have built to target organizations and customers.

Group-IB, the widespread availability of free hosting platforms allows attackers to build and distribute phishing campaigns with minimal effort, making operations highly scalable.

Evolving Tactics and Abused Infrastructure

The threat actors distributed phishing emails with varying social engineering narratives to lure victims. Throughout 2024, emails typically claimed that an unauthorized transaction had been detected, prompting users to click a “Cancel Payment” button.

This tactic created urgency and drove victims toward a malicious webpage. By late 2025, the theme shifted to warnings about suspicious device logins and requests to verify contact information for improved account security.

Furthermore, threat actors stopped embedding phishing links directly in the email body. Instead, they leveraged trusted platforms to host or redirect malicious content.

Abused services included Google Business Profiles, the AMP Content Delivery Network (CDN), URL shorteners, and Google Cloud Workstations.

By nesting attacks within legitimate infrastructure, attackers inherited high domain reputations and effectively evaded Secure Email Gateways.

Trusted Platforms Steal Credentials (Source: group-ib)
Trusted Platforms Steal Credentials (Source: group-ib)

Bypassing Security For Real-Time Fraud

Once victims clicked the deceptive links, they were redirected to a phishing site that closely resembled a legitimate banking portal.

To ensure visual fidelity, attackers employed a “hotlinking” technique. The phishing kit dynamically fetched resources, such as images and scripts, directly from the official servers of the impersonated bank.

While this made the fake portal look authentic, it created a digital fingerprint via a malicious Referer header, which network defenders can use to identify and block the attack.

Various legitimate and trusted services are abused to mask malicious links and evade secure email gateways (Source: group-ib)
Various legitimate and trusted services are abused to mask malicious links and evade secure email gateways (Source: group-ib)

The primary objective of this operation is immediate financial theft. The workflow is specifically designed to facilitate unauthorized fund transfers in real time. Victims first enter their banking username and password.

The malicious script intentionally triggers an error message after the first submission, forcing victims to re-enter credentials and reducing the risk of typos.

According to Group-IB research, victims are asked for supplementary personal information, including their mobile number and the last four digits of their account or card number. In the final step, victims must enter the OTP sent to their mobile device.

By capturing this code, attackers bypass multi-factor authentication (MFA) and complete fraudulent transactions before the OTP expires. The stolen data is systematically exfiltrated in real time via Telegram bots.

This ongoing investigation exposes an operation far more adaptive than typical credential-harvesting schemes.

By shifting narratives, abusing trusted cloud services, and hijacking legitimate domains, the PHISLES threat actors demonstrate a clear intent to maximize reach and bypass modern security defenses.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories