InsureOTP Kit: Real-Time OTP Interception Phishing Campaign Targeting Insurance Providers (CTM360)
InsureOTP Kit (TL-2026-1679), also tracked as The InsureTrap, is a high-severity phishing campaign, first published 2026-07-25. It has no confirmed attribution, affects Multiple Insurance Providers Customer-facing insurance web portals, maps to 17 MITRE ATT&CK techniques (T1036, T1056, T1071), and is covered by 9 detection rules and 15 indicators of compromise.
Key facts for TL-2026-1679
- Threat ID
- TL-2026-1679
- Also known as
- The InsureTrap, InsureOTP Kit
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-07-25
- Last reviewed
- 2026-07-25
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- insurance, financial-services
- Target regions
- saudi arabia, Middle East, Europe, united states of america, india
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in InsureOTP Kit
Malware and tooling: InsureOTP, InsureOTP Kit, Telegram Bot API
CTM360 disclosed 'The InsureTrap' — a coordinated real-time phishing campaign using a previously undocumented phishing framework, the 'InsureOTP Kit', to impersonate motor, health, life, home and travel insurance providers. Victims lured via sponsored Google Ads land on fake insurer portals that harvest credentials and relay live one-time passwords to the legitimate service before they expire, enabling authenticated account hijacking rather than static credential theft.
How InsureOTP Kit works
CTM360's report 'The InsureTrap: Real-Time Phishing & Account Hijacking Through Fake Insurance Portals' (published 2026-07-22, covered by The Hacker News 2026-07-25) documents a coordinated phishing operation targeting customers of multiple insurance providers, primarily in Saudi Arabia with secondary activity observed in Europe, the United States, and India.
The campaign is driven by sponsored Google Ads for common insurance search terms (e.g. 'Compare car insurance offers', 'Cheapest third-party insurance') that redirect victims to convincing, brand-mimicking phishing portals covering motor, health, life, home, and travel insurance lines. Rather than passively harvesting static credentials, the InsureOTP Kit operates as a real-time, human-in-the-loop attack framework: as a victim submits their login details on the fake portal, an operator (or automated relay) simultaneously uses the same data to authenticate against the legitimate insurer portal. When the real portal responds with a one-time password (OTP) or additional verification challenge, the phishing page dynamically prompts the victim for that exact code, captures it, and relays it back to the legitimate session before the OTP expires — achieving live account takeover and bypassing OTP/MFA controls entirely rather than merely stealing reusable secrets.
Backend architecture supporting the kit includes Telegram Bot API integrations that push structured victim submissions to operators for real-time review/approval, local (SQLite-based) storage of operational and victim records, and built-in administrative dashboards giving operators visibility into live sessions and manual approval workflows for OTP relay. Front-end phishing pages are not hosted on dedicated bulletproof infrastructure but instead on legitimate free/low-cost web-hosting and site-builder platforms — GitHub Pages, Netlify, Hostinger, Wix, and Lovable — using randomized, disposable subdomains that are rotated frequently to evade takedown and reputation-based blocking, and abusing the inherent trust and TLS validity of these mainstream platforms.
CTM360 categorizes this as part of a broader pattern of 'TrapPhishing'-style real-time interactive campaigns the vendor has tracked across sectors (e.g. corporate banking 'Cyberheist Phish', government portals 'GovTrap'), where attacker tooling is purpose-built to defeat OTP/MFA rather than rely on static phishing. No CVE or software vulnerability underlies this threat — it is a social-engineering and phishing-kit-driven campaign against the insurance vertical.
MITRE ATT&CK techniques used in TL-2026-1679
Defense Evasion
Credential Access
T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1557 Adversary-in-the-Middle
Collection
T1056 Input Capture; T1119 Automated Collection
Command and Control
T1071 Application Layer Protocol; T1102 Web Service
Initial Access
Execution
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities
Reconnaissance
T1593 Search Open Websites/Domains
Impact
stealth
Affected products and versions in InsureOTP Kit
- Multiple Insurance Providers — Customer-facing insurance web portals (motor, health, life, home, travel lines)
Vulnerable versions: Any OTP/SMS-based customer authentication flow
Fixed in: Phishing-resistant MFA (FIDO2/WebAuthn) deployments not relayable via real-time interception - Google — Google Ads (sponsored search)
Vulnerable versions: Ad platform lacking brand-impersonation detection for insurance-comparison keywords
Fixed in: N/A - policy/detection improvement, not a version
Remediation for InsureOTP Kit
Immediate actions
- Alert insurance customers to verify insurer URLs directly (not via sponsored search ads) before entering credentials or OTPs
- Report and request takedown of phishing pages hosted on GitHub Pages, Netlify, Hostinger, Wix, and Lovable subdomains impersonating the insurer brand
- Monitor Google Ads brand-abuse channels and file trademark/malicious-ad complaints against sponsored listings impersonating the insurer
- Force session invalidation and password/OTP reset for any customer account with suspicious concurrent-session or rapid re-authentication activity
- Add fraud-detection rules for logins immediately followed by high-value policy or payment-method changes
Workarounds
- Disable SMS/email OTP as the sole MFA factor for high-value account actions (policy changes, payouts, payment method updates) pending phishing-resistant MFA rollout
- Add out-of-band verification (e.g. app push confirmation with transaction detail, not a bare numeric code) for sensitive account changes
Longer-term hardening
- Migrate OTP-based verification to phishing-resistant MFA (FIDO2/WebAuthn hardware keys or platform passkeys) that cannot be relayed by an attacker-in-the-middle
- Implement device fingerprinting and behavioral biometrics on the customer portal login flow to detect anomalous relay-style authentication patterns
- Deploy continuous brand-abuse / phishing-domain monitoring across free-hosting platforms (GitHub Pages, Netlify, Wix, Hostinger, Lovable) for the insurer's brand terms
- Establish a rapid takedown SLA and legal process with hosting providers and Google Ads abuse teams for insurance-brand impersonation
Weaknesses (CWE) in InsureOTP Kit
CWE-1021, CWE-451, CWE-290
Timeline of InsureOTP Kit
- CTM360 publishes the full report 'The InsureTrap: Real-Time Phishing & Account Hijacking Through Fake Insurance Portals'.
- CTM360 confirms primary targeting of Saudi Arabia with secondary activity observed in Europe, the United States, and India.
- CTM360 documents the kit's Telegram Bot API integration, SQLite-based local storage, and admin dashboard supporting live manual OTP-relay approval by operators.
- CTM360 documents attacker abuse of GitHub Pages, Netlify, Hostinger, Wix, and Lovable for hosting rotating, disposable phishing subdomains.
- CTM360 maps 'The InsureTrap' campaign infrastructure, finding phishing pages impersonating motor, health, life, home, and travel insurance providers.
- CTM360 identifies and names the previously undocumented 'InsureOTP Kit', a purpose-built real-time OTP interception framework targeting insurance customers.
- TL-Intel Harness ingests and tracks the disclosure as an active, ongoing phishing threat (TL-2026-1679).
- The Hacker News covers CTM360's findings, bringing the InsureOTP Kit campaign to broader public and defender attention.
Sources cited for InsureOTP Kit
- CTM360 Research Reveals How Insurance Customers Are Targeted by Real-Time OTP Phishing
- The InsureTrap: Real-Time Phishing & Account Hijacking Through Fake Insurance Portals
- Cybersecurity Reports & Threat Intelligence Insights | CTM360
- CTM360 maps out real-time phishing infrastructure targeting corporate banking worldwide
- CTM360 Exposes Global GovTrap Campaign With 11,000+ Fake Government Portals Targeting Citizens Worldwide
- CTM360 Identifies Surge in Phishing Attacks Targeting Meta Business Users
More in phishing
- Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt Injection)
- OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvesters
- Malicious Google Ads Campaign Targets Ledger Hardware Wallet Users to Steal BIP-39 Recovery Phrases via Google Cloud Storage / Vercel / Google Sites Redirect Chain
- Google Account Security Team Impersonation Vishing Campaign — Telegram Recruitment Ad Leaks Call Script
- Tax-Themed Phishing and Malware Campaign Targeting Indian Taxpayers: WhatsApp Fake ITD Notices (ITD.zip Android APK + Certum-Signed ITD_Tax_Notice.exe Loader), Cloned e-Filing Portals and Refund Scams
Detection coverage for TL-2026-1679
As of 2026-07-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1679 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.