Sunday, September 6, 2026

Trusted Platforms Exploited to Steal Philippine Banking Credentials

Hackers are increasingly exploiting trusted online platforms to launch sophisticated phishing campaigns targeting bank users in the Philippines.

Despite ongoing improvements in email security, phishing remains one of the most effective attack methods due to its scalability and ease of deployment.

The campaign, active since early 2024 and still evolving in 2026, primarily targets customers of major Philippine banks rather than the institutions themselves.

Researchers identified more than 900 malicious links distributed through phishing emails, with over 400 victims impacted during the operation.

Unlike traditional phishing attacks that rely on suspicious domains, this campaign stands out for its strategic abuse of legitimate services.

Group-IB CERT team discovered a phishing email campaign specifically targeting users of major banks in the Philippines.

Threat actors leveraged platforms such as Google Business, AMP CDN, Cloudflare Workers, and URL shortening services to disguise malicious links.

Philippine Banking Credentials

By embedding phishing redirects within trusted domains, attackers significantly improved email deliverability and bypassed secure email gateways.

Group-IB Threat Intelligence Portal: PHISLES (Source : GroupIB).
Group-IB Threat Intelligence Portal: PHISLES (Source : GroupIB).

The emails themselves were sent from compromised accounts, many of which were likely sourced from combolists databases of stolen credentials circulating on underground forums.

This tactic enhanced credibility, as messages appeared to originate from legitimate organizational domains rather than disposable email services.

Sender emails sourced from Combolists (Source : GroupIB).
Sender emails sourced from Combolists (Source : GroupIB).

Social engineering played a central role in the campaign’s success. Early phishing waves in 2024 focused on fake transaction alerts, urging users to click “Cancel Payment” links.

By late 2025, attackers shifted to new narratives, including warnings about suspicious device logins and requests to update account details. These evolving themes helped maintain effectiveness and evade user suspicion.

Once victims clicked the links, they were routed through multiple redirection layers before landing on highly convincing fake banking pages.

These pages used a technique known as “hotlinking,” pulling real assets directly from legitimate bank servers to replicate authentic interfaces. This not only improved visual accuracy but also reduced detection by security tools.

Trusted services become tools

The attack workflow was designed for real-time financial fraud. Victims were prompted to enter login credentials, followed by personal details and One-Time Passwords (OTPs).

When attackers embed phishing redirects within Google Business posts or use this domain as an intermediary, SEGs often allow the email through, assuming it is safe.

Various legitimate and trusted services are abused to mask malicious links and evade secure email gateways  (Source : GroupIB).
Various legitimate and trusted services are abused to mask malicious links and evade secure email gateways (Source : GroupIB).

The phishing kit used automated scripts to transmit this data instantly via Telegram bots, allowing attackers to bypass multi-factor authentication and execute unauthorized transactions within minutes.

In a more advanced twist, researchers also discovered that attackers compromised a legitimate educational institution’s domain within the Philippine ccTLD.

By creating malicious subdomains with valid SSL certificates, they hosted phishing infrastructure under a trusted domain, further increasing the campaign’s legitimacy and resilience.

The threat actor successfully compromised the infrastructure of a legitimate educational institution in the Philippines to host their phishing payload. 

Phishing content hosted on a hijacked subdomain of an educational institution (Source : GroupIB).
Phishing content hosted on a hijacked subdomain of an educational institution (Source : GroupIB).

The infrastructure showed signs of careful planning, including short-lived SSL certificates and rapidly rotating subdomains to avoid detection.

Additionally, researchers noted that organizations could detect such attacks by monitoring HTTP referrer headers, which may reveal unauthorized domains loading assets from official servers.

This campaign highlights how modern phishing operations are becoming more adaptive and technically sophisticated.

By combining trusted platforms, compromised accounts, and real-time data exfiltration, attackers can scale operations while maintaining high success rates.

Security experts emphasize the need for stronger monitoring, improved email filtering, and continuous user awareness.

As cybercriminals increasingly exploit trust in well-known platforms and brands, both financial institutions and their customers face growing risks from evolving phishing threats.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security

Chainguard has surpassed 1 billion container build manifests, doubling...

Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe

Russian state-sponsored threat actor BlueDelta, also tracked as APT28,...

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption

Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS)...

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged...

Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours

A threat actor used frontier artificial-intelligence models and attack-specific...

CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each

Used-car platform CARS24 has alleged that confidential information belonging...

Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors

The financially motivated threat actor Toy Ghouls has expanded...

Related Articles

Recent News