Hackers are increasingly exploiting trusted online platforms to launch sophisticated phishing campaigns targeting bank users in the Philippines.
Despite ongoing improvements in email security, phishing remains one of the most effective attack methods due to its scalability and ease of deployment.
The campaign, active since early 2024 and still evolving in 2026, primarily targets customers of major Philippine banks rather than the institutions themselves.
Researchers identified more than 900 malicious links distributed through phishing emails, with over 400 victims impacted during the operation.
Unlike traditional phishing attacks that rely on suspicious domains, this campaign stands out for its strategic abuse of legitimate services.
Group-IB CERT team discovered a phishing email campaign specifically targeting users of major banks in the Philippines.
Threat actors leveraged platforms such as Google Business, AMP CDN, Cloudflare Workers, and URL shortening services to disguise malicious links.
Philippine Banking Credentials
By embedding phishing redirects within trusted domains, attackers significantly improved email deliverability and bypassed secure email gateways.

The emails themselves were sent from compromised accounts, many of which were likely sourced from combolists databases of stolen credentials circulating on underground forums.
This tactic enhanced credibility, as messages appeared to originate from legitimate organizational domains rather than disposable email services.

Social engineering played a central role in the campaign’s success. Early phishing waves in 2024 focused on fake transaction alerts, urging users to click “Cancel Payment” links.
By late 2025, attackers shifted to new narratives, including warnings about suspicious device logins and requests to update account details. These evolving themes helped maintain effectiveness and evade user suspicion.
Once victims clicked the links, they were routed through multiple redirection layers before landing on highly convincing fake banking pages.
These pages used a technique known as “hotlinking,” pulling real assets directly from legitimate bank servers to replicate authentic interfaces. This not only improved visual accuracy but also reduced detection by security tools.
Trusted services become tools
The attack workflow was designed for real-time financial fraud. Victims were prompted to enter login credentials, followed by personal details and One-Time Passwords (OTPs).
When attackers embed phishing redirects within Google Business posts or use this domain as an intermediary, SEGs often allow the email through, assuming it is safe.

The phishing kit used automated scripts to transmit this data instantly via Telegram bots, allowing attackers to bypass multi-factor authentication and execute unauthorized transactions within minutes.
In a more advanced twist, researchers also discovered that attackers compromised a legitimate educational institution’s domain within the Philippine ccTLD.
By creating malicious subdomains with valid SSL certificates, they hosted phishing infrastructure under a trusted domain, further increasing the campaign’s legitimacy and resilience.
The threat actor successfully compromised the infrastructure of a legitimate educational institution in the Philippines to host their phishing payload.

The infrastructure showed signs of careful planning, including short-lived SSL certificates and rapidly rotating subdomains to avoid detection.
Additionally, researchers noted that organizations could detect such attacks by monitoring HTTP referrer headers, which may reveal unauthorized domains loading assets from official servers.
This campaign highlights how modern phishing operations are becoming more adaptive and technically sophisticated.
By combining trusted platforms, compromised accounts, and real-time data exfiltration, attackers can scale operations while maintaining high success rates.
Security experts emphasize the need for stronger monitoring, improved email filtering, and continuous user awareness.
As cybercriminals increasingly exploit trust in well-known platforms and brands, both financial institutions and their customers face growing risks from evolving phishing threats.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





