Insurance phishing campaigns are evolving from delayed credential theft to real-time account hijacking, where attackers relay victims’ login data and OTPs to legitimate portals during the same session. The investigation also shows how the InsureOTP Kit, sponsored Google ads, and disposable cloud-hosted infrastructure are being used across multiple insurance brands and regions. #InsureOTPKit #CTM360 #GoogleAds #TelegramBotAPI #SaudiArabia
Keypoints
- Attackers now hijack insurance accounts in real time during the victim’s login session.
- Sponsored Google ads are used to lure users searching for insurance quotes and renewals.
- The campaign targets multiple insurance brands across Saudi Arabia, Europe, the United States, and India.
- The InsureOTP Kit includes live session tracking, OTP handling, dashboards, and Telegram Bot integrations.
- Defenders need to monitor infrastructure, lookalike domains, and abuse of brand-related ads.
Read More: https://thehackernews.com/2026/07/ctm360-research-reveals-how-insurance.html