InsureOTP Kit: Real-Time OTP Interception Phishing Campaign Targeting Insurance Providers (CTM360)

InsureOTP Kit (TL-2026-1679), also tracked as The InsureTrap, is a high-severity phishing campaign, first published 2026-07-25. It has no confirmed attribution, affects Multiple Insurance Providers Customer-facing insurance web portals, maps to 17 MITRE ATT&CK techniques (T1036, T1056, T1071), and is covered by 9 detection rules and 15 indicators of compromise.

Key facts for TL-2026-1679

Threat ID
TL-2026-1679
Also known as
The InsureTrap, InsureOTP Kit
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-07-25
Last reviewed
2026-07-25
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
insurance, financial-services
Target regions
saudi arabia, Middle East, Europe, united states of america, india
Detection rules
9
Indicators of compromise
15

Malware and tooling in InsureOTP Kit

Malware and tooling: InsureOTP, InsureOTP Kit, Telegram Bot API

CTM360 disclosed 'The InsureTrap' — a coordinated real-time phishing campaign using a previously undocumented phishing framework, the 'InsureOTP Kit', to impersonate motor, health, life, home and travel insurance providers. Victims lured via sponsored Google Ads land on fake insurer portals that harvest credentials and relay live one-time passwords to the legitimate service before they expire, enabling authenticated account hijacking rather than static credential theft.

How InsureOTP Kit works

CTM360's report 'The InsureTrap: Real-Time Phishing & Account Hijacking Through Fake Insurance Portals' (published 2026-07-22, covered by The Hacker News 2026-07-25) documents a coordinated phishing operation targeting customers of multiple insurance providers, primarily in Saudi Arabia with secondary activity observed in Europe, the United States, and India.

The campaign is driven by sponsored Google Ads for common insurance search terms (e.g. 'Compare car insurance offers', 'Cheapest third-party insurance') that redirect victims to convincing, brand-mimicking phishing portals covering motor, health, life, home, and travel insurance lines. Rather than passively harvesting static credentials, the InsureOTP Kit operates as a real-time, human-in-the-loop attack framework: as a victim submits their login details on the fake portal, an operator (or automated relay) simultaneously uses the same data to authenticate against the legitimate insurer portal. When the real portal responds with a one-time password (OTP) or additional verification challenge, the phishing page dynamically prompts the victim for that exact code, captures it, and relays it back to the legitimate session before the OTP expires — achieving live account takeover and bypassing OTP/MFA controls entirely rather than merely stealing reusable secrets.

Backend architecture supporting the kit includes Telegram Bot API integrations that push structured victim submissions to operators for real-time review/approval, local (SQLite-based) storage of operational and victim records, and built-in administrative dashboards giving operators visibility into live sessions and manual approval workflows for OTP relay. Front-end phishing pages are not hosted on dedicated bulletproof infrastructure but instead on legitimate free/low-cost web-hosting and site-builder platforms — GitHub Pages, Netlify, Hostinger, Wix, and Lovable — using randomized, disposable subdomains that are rotated frequently to evade takedown and reputation-based blocking, and abusing the inherent trust and TLS validity of these mainstream platforms.

CTM360 categorizes this as part of a broader pattern of 'TrapPhishing'-style real-time interactive campaigns the vendor has tracked across sectors (e.g. corporate banking 'Cyberheist Phish', government portals 'GovTrap'), where attacker tooling is purpose-built to defeat OTP/MFA rather than rely on static phishing. No CVE or software vulnerability underlies this threat — it is a social-engineering and phishing-kit-driven campaign against the insurance vertical.

MITRE ATT&CK techniques used in TL-2026-1679

Defense Evasion

T1036 Masquerading

Credential Access

T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1557 Adversary-in-the-Middle

Collection

T1056 Input Capture; T1119 Automated Collection

Command and Control

T1071 Application Layer Protocol; T1102 Web Service

Initial Access

T1189 Drive-by Compromise

Execution

T1204 User Execution

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities

Reconnaissance

T1593 Search Open Websites/Domains

Impact

T1657 Financial Theft

stealth

T1684.001 Impersonation

Affected products and versions in InsureOTP Kit

  • Multiple Insurance Providers — Customer-facing insurance web portals (motor, health, life, home, travel lines)
    Vulnerable versions: Any OTP/SMS-based customer authentication flow
    Fixed in: Phishing-resistant MFA (FIDO2/WebAuthn) deployments not relayable via real-time interception
  • Google — Google Ads (sponsored search)
    Vulnerable versions: Ad platform lacking brand-impersonation detection for insurance-comparison keywords
    Fixed in: N/A - policy/detection improvement, not a version

Remediation for InsureOTP Kit

Immediate actions

  • Alert insurance customers to verify insurer URLs directly (not via sponsored search ads) before entering credentials or OTPs
  • Report and request takedown of phishing pages hosted on GitHub Pages, Netlify, Hostinger, Wix, and Lovable subdomains impersonating the insurer brand
  • Monitor Google Ads brand-abuse channels and file trademark/malicious-ad complaints against sponsored listings impersonating the insurer
  • Force session invalidation and password/OTP reset for any customer account with suspicious concurrent-session or rapid re-authentication activity
  • Add fraud-detection rules for logins immediately followed by high-value policy or payment-method changes

Workarounds

  • Disable SMS/email OTP as the sole MFA factor for high-value account actions (policy changes, payouts, payment method updates) pending phishing-resistant MFA rollout
  • Add out-of-band verification (e.g. app push confirmation with transaction detail, not a bare numeric code) for sensitive account changes

Longer-term hardening

  • Migrate OTP-based verification to phishing-resistant MFA (FIDO2/WebAuthn hardware keys or platform passkeys) that cannot be relayed by an attacker-in-the-middle
  • Implement device fingerprinting and behavioral biometrics on the customer portal login flow to detect anomalous relay-style authentication patterns
  • Deploy continuous brand-abuse / phishing-domain monitoring across free-hosting platforms (GitHub Pages, Netlify, Wix, Hostinger, Lovable) for the insurer's brand terms
  • Establish a rapid takedown SLA and legal process with hosting providers and Google Ads abuse teams for insurance-brand impersonation

Weaknesses (CWE) in InsureOTP Kit

CWE-1021, CWE-451, CWE-290

Timeline of InsureOTP Kit

  • CTM360 publishes the full report 'The InsureTrap: Real-Time Phishing & Account Hijacking Through Fake Insurance Portals'.
  • CTM360 confirms primary targeting of Saudi Arabia with secondary activity observed in Europe, the United States, and India.
  • CTM360 documents the kit's Telegram Bot API integration, SQLite-based local storage, and admin dashboard supporting live manual OTP-relay approval by operators.
  • CTM360 documents attacker abuse of GitHub Pages, Netlify, Hostinger, Wix, and Lovable for hosting rotating, disposable phishing subdomains.
  • CTM360 maps 'The InsureTrap' campaign infrastructure, finding phishing pages impersonating motor, health, life, home, and travel insurance providers.
  • CTM360 identifies and names the previously undocumented 'InsureOTP Kit', a purpose-built real-time OTP interception framework targeting insurance customers.
  • TL-Intel Harness ingests and tracks the disclosure as an active, ongoing phishing threat (TL-2026-1679).
  • The Hacker News covers CTM360's findings, bringing the InsureOTP Kit campaign to broader public and defender attention.

Sources cited for InsureOTP Kit

More in phishing

Detection coverage for TL-2026-1679

As of 2026-07-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1679 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats