CryptoChameleon: New Phishing Tactics Exhibited in FCC-Targeted Attack | Threat Intel

Lookout identified a phishing kit, dubbed CryptoChameleon, that builds near-perfect replicas of SSO pages (notably Okta) and uses email, SMS and voice lures to harvest usernames, passwords, MFA tokens, password‑reset URLs and photo IDs from hundreds of mostly U.S. victims. The kit includes an operator console for real‑time credential replay and customizable post-login pages, with infrastructure hosted on multiple domains and shifting IPs. #Cryptochameleon #FCC #Okta #Coinbase #ScatteredSpider

Keypoints

  • Phishing kit impersonates Okta SSO and major crypto platforms (Coinbase, Binance, Gemini, Kraken, etc.) to harvest credentials and identity documents.
  • Site uses hCaptcha to block automated crawlers and lend legitimacy before presenting the fake login page.
  • Operators monitor an admin console that records each victim and lets the attacker choose real‑time follow‑up pages (MFA prompt, SMS token request, account review message, etc.).
  • Attackers perform real‑time credential replay to the legitimate service to capture and use MFA tokens (authenticator or SMS) with options to display last digits of phone numbers and choose token length for realism.
  • Delivery combines phishing links via SMS/email with voice calls (vishing) to coach victims through the flow, primarily targeting mobile users in the U.S.
  • Phishing kit files of interest include /js/consts.js (C2 URL), /js/init.js (collection and redirect logic) and CSS assets for visual impersonation; many spoof domains and C2 servers were enumerated.
  • Infrastructure shifted across hosts and IPs (Hostwinds/Hostinger → RetnNet 213.178.155[.]194 → QWARTA 185.12.127[.]233 → OOO Westcall 81.94.159[.]46), suggesting active operational movement.

MITRE Techniques

  • [T1566] Phishing – Use of email, SMS, and voice lures to deliver links and social‑engineer victims into the phishing flow (‘…use a combination of email, SMS, and voice phishing to trick the target…’).
  • [T1566.002] Phishing: Spearphishing Link – Lures include text messages and links and are used while victims are on calls to prompt immediate interaction (‘…they were sent a text message that linked them to the phishing page.’).
  • [T1204] User Execution – Operators guide victims by phone and SMS to perform actions (click links, enter credentials, submit IDs), inducing the user to execute the attacker’s requested steps (‘While the victim was on the phone with the threat actor, they were sent a text message that linked them to the phishing page.’).
  • [T1036] Masquerading – Impersonation of legitimate Okta and company pages plus homoglyph domain tricks to make spoofed domains appear authentic (‘…impersonation of Okta, registration of domains using companyname‑okta.com, and homoglyph swapping.’).
  • [T1583.001] Acquire Infrastructure: Domains – Registration and use of numerous spoof domains and subdomains as part of the kit’s infrastructure (e.g., fcc-okta[.]com and many coinbase‑lookalike domains) (‘The domain in question was fcc-okta[.]com…’).
  • [T1056] Input Capture – Collection of credentials, password reset URLs and photo IDs via the fake SSO pages and form submissions (‘…trick the target into sharing usernames, passwords, password reset URLs and even photo IDs…’).
  • [T1071] Application Layer Protocol – Use of command‑and‑control domains and web hosting (official-server[.]com, original-backend[.]com and glitch/hosting providers) to receive and manage harvested data and backend operations (‘Most of the websites use a subdomain of official-server[.]com as their C2…’).

Indicators of Compromise

  • [C2 Domains] Command and control infrastructure – official-server[.]com, original-backend[.]com, and others (see report list).
  • [Phishing Domains] Spoofed login sites – fcc-okta[.]com, binance-okta[.]com, and dozens/hundreds of coinbase‑lookalike domains (e.g., captcha-coinbase[.]com, accountrecovery-coinbase[.]com) among many others.
  • [IP Addresses] Hosting and migration points – 213.178.155[.]194 (RetnNet), 185.12.127[.]233 (QWARTA LLC), and 81.94.159[.]46 (OOO Westcall Ltd) used as hosting locations.
  • [File Paths] Kit components and collectors – /js/consts.js (C2 URL), /js/init.js (client‑side collection and redirect logic), and CSS assets in /css/ for visual spoofing.

Lookout discovered the kit by spotting a suspicious domain registration pattern and then analyzing the deployed pages and assets. The kit gates visitors with hCaptcha to block automated crawlers, serves near‑identical replicas of targeted SSO (Okta) and crypto login pages, and records submissions to an operator‑facing backend. Client JavaScript (notably /js/init.js) handles data collection and redirects; /js/consts.js contains the C2 domain. The operator console enumerates each victim row and allows real‑time selection of the next page (authenticator prompt, SMS token entry, account‑review messages), and can inject contextual details such as the last digits of a phone number or choice of a 6/7‑digit code to increase believability.

The operational flow relies on immediate credential replay: when credentials are submitted, operators attempt live logins to obtain MFA challenges and then prompt victims (via customized pages) to provide OTPs, SMS codes or other verification material. Delivery is driven by coordinated social engineering—spoofed support calls combined with SMS links—and the kit stores high‑quality captures (valid email/password pairs, OTPs, password reset URLs, and ID photos). Backend infrastructure includes numerous spoof domains and C2 hosts (official-server[.]com, original-backend[.]com, glitch[.]me entries) and shows frequent host/IP migration to prolong uptime and evade takedown.

For detection and response, monitor for access to or DNS resolution of the enumerated C2 and spoof domains, unusual redirections to Okta/SSO pages from SMS/email, and submissions to unexpected endpoints. Inspect web server logs for requests to phishing‑style paths and client JS files (init.js/consts.js), and correlate mobile‑originated suspicious flows that include SMS links plus concurrent support‑style phone calls. Quarantine traffic to the listed IPs and domains and treat submissions captured by these flows as compromised credentials requiring immediate rotation and re‑authentication with confirmed channels.

Read more: https://www.lookout.com/threat-intelligence/article/cryptochameleon-fcc-phishing-kit