Affected Systems
Insurance providers globally, with primary focus on Saudi Arabia; additional activity in Europe, US, and India. Affects customers of multiple insurance brands using online portals for policy management, claims, and payments. Attack leverages Google Ads, free hosting platforms (GitHub Pages, Netlify, Hostinger, Wix, Lovable), and the InsureOTP phishing kit.
Exploitation Status
Active exploitation confirmed. CTM360 research documents live campaigns using real-time OTP relay techniques. Attackers purchase Google Ads to deliver phishing sites that act as live proxies, intercepting and relaying credentials and multi-factor authentication codes to legitimate insurance portals during victim login sessions.
Business Impact
Traditional phishing defenses (brand monitoring, static credential harvesting detection) are insufficient. Attackers bypass MFA by relaying OTP codes in real time, completing account takeover within a single session before detection. Compromised insurance accounts expose extensive PII, identity documents, payment methods, and policy records—enabling fraud beyond financial theft. Free hosting platforms and randomized domains reduce effectiveness of domain blocklists and brand protection tools.
Urgency
🟠 Within 24 hours
Recommended Actions
- Monitor for unauthorized Google Ads campaigns impersonating your insurance brand; establish direct communication with Google Ads abuse team for rapid takedown.
- Implement behavioral analytics and session anomaly detection to identify simultaneous logins from disparate geolocations or rapid credential reuse patterns indicative of real-time relay attacks.
- Deploy phishing-resistant MFA (FIDO2/WebAuthn) that binds authentication to the legitimate domain, preventing OTP relay; phase out SMS and TOTP-based MFA for high-risk accounts.
- Educate customers to verify URLs before login and avoid clicking sponsored search results; publish official domain lists and promote direct navigation or bookmarked links.
- Coordinate with threat intelligence providers to identify InsureOTP Kit indicators (domains, hosting patterns, phishing page fingerprints) and integrate into SIEM, proxy, and email gateway blocklists.
