Threat reportPhishingTL-2026-2246
Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit
Polymorphic Phishing Attack Generates Unique (TL-2026-2246) is a medium-severity phishing campaign, first published 2026-08-30. It has no confirmed attribution, maps to 12 MITRE ATT&CK techniques (T1027, T1027.003, T1027.014), and is covered by 9 detection rules and 6 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 12MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 6Indicators of compromise
Key facts for TL-2026-2246
- Threat ID
- TL-2026-2246
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Detection rules
- 9
- Indicators of compromise
- 6
How Polymorphic Phishing Attack Generates Unique works
A credential-harvesting phishing page hosted at addresses.performs.vu uses a server-side polymorphic generator that produces a syntactically distinct page on virtually every request — 50 downloads of the same URL yielded 50 distinct SHA-256 hashes — defeating hash- and static-signature-based detection. The obfuscator itself is buggy: 2 of 56 collected samples fail to render because two JavaScript functions share an undeclared global loop variable, causing an infinite loop and ~100% single-core CPU usage for ~30 seconds.
On 2026-08-27, SANS Internet Storm Center handler Jan Kopriva published the diary "A polymorphic phishing page (that occasionally breaks itself)," documenting a phishing campaign caught in his spam traps. The lure links to hxxps://addresses.performs.vu/communications.html?good=[recipient_address], a page that impersonates no specific brand but presents a generic credential-entry form. Kopriva retrieved the same URL 50 times with an automated script and found that every download returned a functionally identical but syntactically unique page: 50 distinct SHA-256 hashes and 21 distinct page titles from 50 requests. The server-side polymorphic generator varies function and variable names, reorders functions, expresses numeric constants through different arithmetic operations, randomizes form/input names, CSS class names and HTML element identifiers, randomizes image-loading parameters, and inserts zero-width characters at varying positions inside visible strings. Kopriva explicitly considered whether an LLM was generating the variants in real time (as demonstrated separately by Palo Alto Networks Unit 42's proof-of-concept for LLM-assembled runtime phishing JavaScript, which pulls generated snippets from live LLM APIs such as DeepSeek and Google Gemini via prompt-injection-style jailbreak prompts embedded in the page) but concluded a conventional polymorphic/metamorphic obfuscator is the more plausible explanation, because the transformations between samples are systematic and relatively simple rather than freeform.
Of 56 total collected samples, 2 failed to deobfuscate/render. Root cause: two of the generated functions (named _il and _YF in the specific sample examined, with a third helper, _ie, invoked during decoding — all three names are themselves randomized in other polymorphic variants) both used an undeclared variable k as a loop counter, making it an implicit global rather than a local variable. Inside the outer 64-iteration decode loop (bounded by k<=63), the shared counter caused progress to stall in a repeating 48→49 sequence, pegging a single CPU core near 100%, and hanging the browser tab for roughly 30 seconds — an unintentional, self-inflicted defect in the polymorphic engine rather than a deliberate anti-analysis measure, though it incidentally also disrupts naive automated sample collection. Despite the pervasive per-request randomization, two elements were observed to stay constant or fall within a bounded, confirmed set across all 56 samples: the URL path segment /communications.html never changed, and the decoded page's <title> element rotated among at least 21 distinct values across the 50 scripted downloads, with "Solution," "Viewer," "Credentials," "Private," and "Authenticate" confirmed among them — both are more durable detection signals than the per-request SHA-256 hash. The credential-entry form itself only becomes visible and interactive after the client-side JavaScript decoder finishes executing; the page is non-functional with JavaScript disabled, and the observed ?good=[recipient_address] query parameter indicates the sender already held the target's email address before delivering the link.
Infrastructure-wise, the phishing page is hosted on Vanuatu's .vu ccTLD, which KnowBe4 ThreatLabs (2026-08-28) and IronScales (2025-10-18, on an unrelated but structurally identical .vu phishing incident targeting a different victim with a fabricated public-insurance-adjuster lure) both document as increasingly abused ground for disposable phishing domains: open registration without strict ID verification, default WHOIS privacy, low cost/bulk pricing, and automated free TLS issuance (Let's Encrypt) that lets a .vu page present a legitimate-looking HTTPS padlock. KnowBe4 recorded a 159.6% rise in phishing sites and 1,660 unique malicious .vu domains between April and July 2026 — concentrated through the registrars Dynadot (884 domains) and Sav.com (770 domains), with domains typically operational for under 20 days before rotation, and 99.9% of observed .vu indicators appearing as embedded URLs inside email bodies rather than as sender domains (mirroring this campaign's structure: a clean/neutral delivery channel pointing to a disposable .vu landing page) — the same ccTLD family, though not the same specific domain, as this campaign's infrastructure. Barracuda's separate January 2026 threat-spotlight report on 2025 phishing-kit evolution corroborates the broader trend this campaign belongs to: rising use of polymorphic/JavaScript-obfuscated kits (dense obfuscation, Base64/XOR layering) specifically engineered to defeat static and hash-based detection, though that report describes other named kits (Whisper 2FA, Cephas, GhostFrame) rather than this campaign directly. Because hash- and signature-based detection is explicitly undermined by the polymorphism, defenders are advised to prioritize behavioral and structural indicators: the ultimate form-submission destination, browser-side JavaScript deobfuscation/eval activity, anomalous single-core CPU spikes during page load, DOM mutation patterns typical of dynamically assembled credential forms, and the campaign's stable path/title elements.
Neither source names a threat actor, campaign alias, or confirms the ultimate credential-exfiltration endpoint; no CVE or CVSS applies since this is a phishing operation rather than a software vulnerability.
MITRE ATT&CK techniques used in TL-2026-2246
Defense Evasion
T1027 Obfuscated Files or Information; T1027.003 Steganography; T1027.014 Polymorphic Code; T1140 Deobfuscate/Decode Files or Information
Collection
Execution
T1059.007 JavaScript; T1204.001 Malicious Link
Initial Access
Resource Development
T1583.001 Domains; T1608.003 Install Digital Certificate; T1608.005 Link Target
Reconnaissance
Remediation for Polymorphic Phishing Attack Generates Unique
Immediate actions
- Block or closely inspect the .vu ccTLD at email gateways and web proxies for organizations with no legitimate business relationship to Vanuatu, given its documented abuse for cheap, low-scrutiny disposable phishing infrastructure
- Add DNS/web-proxy alerting for the observed domain addresses.performs.vu and its parent performs.vu, and for the constant path segment /communications.html on any newly registered .vu domain
- Decouple email-layer and web-layer blocking so that a web-layer block/interstitial on a phishing domain triggers retroactive purge of already-delivered emails referencing that domain, closing the gap where the email lands before the link is flagged
Workarounds
- Treat links on newly registered ccTLD domains (observed .vu campaign domains average under 20 days old) with added scrutiny, particularly generic paths like communications.html paired with a recipient-identifying query parameter such as ?good=
Longer-term hardening
- Shift phishing-page detection away from static file-hash/signature matching toward behavioral indicators: anomalous single-core CPU spikes during page load, browser-side JavaScript deobfuscation/eval activity, and DOM mutation patterns typical of dynamically assembled credential-harvesting forms
- Monitor Certificate Transparency logs for newly issued Let's Encrypt certificates on rare ccTLDs (e.g. .vu) combined with brand-relevant or generic lure keywords in the hostname/path
- When triaging a reported phishing URL, retrieve it multiple times and diff the resulting page content/hash before publishing a single-hash indicator, since a single download will not reveal server-side polymorphism
Timeline of Polymorphic Phishing Attack Generates Unique
- GBHackers publishes coverage of the SANS ISC findings under the title "Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit," which is the source feed that triggered this hunt.
- Jan Kopriva publishes the SANS Internet Storm Center diary "A polymorphic phishing page (that occasionally breaks itself)," documenting the server-side polymorphism technique and the obfuscator bug, and assesses that a conventional polymorphic obfuscator (not a real-time LLM generator) most plausibly produced the samples.
- Deobfuscation of 56 collected samples shows 2 fail to render: two JavaScript functions (_il and _YF, with helper _ie) share an undeclared global loop variable k, causing the 64-iteration decode loop to stall in a repeating 48→49 sequence, ~100% single-core CPU usage, and a ~30-second browser hang.
- An automated script retrieves the phishing URL (addresses.performs.vu/communications.html) 50 times; each of the 50 downloaded pages produces a distinct SHA-256 hash despite functioning identically, with 21 distinct page titles observed.
- SANS ISC handler Jan Kopriva's spam trap intercepts an email containing the phishing link later analyzed as this polymorphic credential-harvesting campaign.
- KnowBe4 ThreatLabs publishes a companion trend report documenting a 159.6% rise in phishing sites and 1,660 unique malicious .vu-ccTLD domains observed April-July 2026, concentrated through the registrars Dynadot and Sav.com — the same Vanuatu domain family hosting this campaign's addresses.performs.vu page.
Sources cited for Polymorphic Phishing Attack Generates Unique
- A polymorphic phishing page (that occasionally breaks itself)
- Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit
- The .vu Surge: How Threat Actors Are Exploiting Vanuatu's Domain Extension
- Cloudflare Blocked the Page, But the Email Still Landed: A .vu TLD Phishing Domain That Slipped Through
- Threat Spotlight: How phishing kits evolved in 2025
- The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time
Detection coverage for TL-2026-2246
As of 2026-08-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2246 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.