"Instead of functioning as static data collection pages, these phishing portals actively engage with victims throughout the authentication process," CTM360 found.
Google Ads as the initial vector
CTM360's investigation found a consistent and striking delivery mechanism: sponsored Google advertisements. Rather than relying primarily on phishing emails or SMS, operators purchased ads that appeared when users searched for quotations, renewals, or price comparisons. The advertisements promoted offers such as "Compare car insurance offers" or "Cheapest third-party insurance," and directed users into lifelike phishing flows that mimicked quotation services and customer portals.
Real-time session hijacking replaces delayed credential theft
Historically, phishing collected credentials for later use. CTM360 documents a clear evolution: attackers now synchronize with victims in real time, turning the phishing page into an active intermediary between the user and the legitimate insurance portal. As victims enter credentials and face multi-factor challenges such as one-time passwords (OTPs), the phishing site immediately prompts for the same codes and relays them to the real service before they expire. This continuous, session-time compromise allows attackers to validate credentials, satisfy MFA challenges, and establish authenticated sessions inside a single browsing interaction.
InsureOTP Kit and modern phishing kits as operational platforms
CTM360 identified a purpose-built phishing kit—named InsureOTP Kit—that exemplifies how modern kits have become operational platforms rather than simple credential collectors. The framework provided live session management and backend administration, allowing operators to manage victim sessions and persist in attempts to access accounts until authentication succeeded.
- Observed capabilities included real-time victim monitoring, backend administrative dashboards, manual approval workflows, and session tracking.
- Variants used Telegram Bot integrations or direct backend APIs to transmit structured victim submissions instantly.
- Researchers observed live OTP handling and backend interfaces that could request additional OTP submissions when authentication failed, enabling repeated attempts within the limited code lifetime.
Disposable hosting, randomized domains, and exposed backend content
Operators leaned on disposable infrastructure and legitimate cloud services to evade traditional takedowns and brand-monitoring. CTM360 observed phishing sites hosted on platforms such as GitHub Pages, Netlify, Hostinger, Wix, and Lovable, and noted the use of randomized domains with little resemblance to the insurance brands being impersonated. This approach allowed rapid campaign rotation and reduced the effectiveness of conventional domain-blocking and brand-watch efforts.
In several instances, CTM360 located publicly accessible backend resources tied to the phishing infrastructure. Exposed archives contained administrative components, backend source code, SQLite databases, and operational records that revealed how the framework functioned. Those findings underscore that analysis of infrastructure and tooling can reveal the broader campaign ecosystem rather than a single disposable landing page.
What this means for technologists, insurers, and customers
Technologists and security teams: Detection models that assume a gap between credential capture and account abuse are no longer sufficient. CTM360 recommends monitoring for paid advertisements abusing brands, newly registered lookalike domains, disposable cloud-hosted phishing infrastructure, and authentication patterns consistent with real-time OTP interception.
Insurers and procurement leaders: The report shows attackers reuse the same operational infrastructure across multiple insurance brands and markets—Saudi Arabia was identified as a primary target, with additional activity observed across Europe, the United States, and India. Organizations need intelligence that connects infrastructure, tooling, and attacker workflows, not only lists of malicious domains.
End users and customers: Because these attacks can complete within a single browsing session, the time to detect and interrupt compromise is dramatically reduced. The phishing flows are designed to mimic legitimate interfaces and prompt for OTPs as part of routine verification, enabling attackers to capture second-factor codes in real time.
CTM360 frames the broader change succinctly: the campaign's defining characteristic is "session-time compromise." The firm has also evolved its own offering in response, expanding from Digital Risk Protection into a broader Cyber Threat Intelligence platform; earlier this year CTM360 was included in Gartner's inaugural Magic Quadrant for Cyber Threat Intelligence Technologies.
The immediate takeaway is stark and specific: attackers have shortened the window between deception and access to a single session, and their tooling now manages live sessions and OTP exchanges. Defenders must therefore extend monitoring beyond isolated phishing pages to the advertiser feeds, disposable hosting services, backend signatures, and authentication telemetry that together reveal how these campaigns operate.




