Threat reportPhishingTL-2026-2246

Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit

mediumACTIVE

Polymorphic Phishing Attack Generates Unique (TL-2026-2246) is a medium-severity phishing campaign, first published 2026-08-30. It has no confirmed attribution, maps to 12 MITRE ATT&CK techniques (T1027, T1027.003, T1027.014), and is covered by 9 detection rules and 6 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
12MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
6Indicators of compromise

Key facts for TL-2026-2246

Threat ID
TL-2026-2246
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Detection rules
9
Indicators of compromise
6

How Polymorphic Phishing Attack Generates Unique works

A credential-harvesting phishing page hosted at addresses.performs.vu uses a server-side polymorphic generator that produces a syntactically distinct page on virtually every request — 50 downloads of the same URL yielded 50 distinct SHA-256 hashes — defeating hash- and static-signature-based detection. The obfuscator itself is buggy: 2 of 56 collected samples fail to render because two JavaScript functions share an undeclared global loop variable, causing an infinite loop and ~100% single-core CPU usage for ~30 seconds.

On 2026-08-27, SANS Internet Storm Center handler Jan Kopriva published the diary "A polymorphic phishing page (that occasionally breaks itself)," documenting a phishing campaign caught in his spam traps. The lure links to hxxps://addresses.performs.vu/communications.html?good=[recipient_address], a page that impersonates no specific brand but presents a generic credential-entry form. Kopriva retrieved the same URL 50 times with an automated script and found that every download returned a functionally identical but syntactically unique page: 50 distinct SHA-256 hashes and 21 distinct page titles from 50 requests. The server-side polymorphic generator varies function and variable names, reorders functions, expresses numeric constants through different arithmetic operations, randomizes form/input names, CSS class names and HTML element identifiers, randomizes image-loading parameters, and inserts zero-width characters at varying positions inside visible strings. Kopriva explicitly considered whether an LLM was generating the variants in real time (as demonstrated separately by Palo Alto Networks Unit 42's proof-of-concept for LLM-assembled runtime phishing JavaScript, which pulls generated snippets from live LLM APIs such as DeepSeek and Google Gemini via prompt-injection-style jailbreak prompts embedded in the page) but concluded a conventional polymorphic/metamorphic obfuscator is the more plausible explanation, because the transformations between samples are systematic and relatively simple rather than freeform.

Of 56 total collected samples, 2 failed to deobfuscate/render. Root cause: two of the generated functions (named _il and _YF in the specific sample examined, with a third helper, _ie, invoked during decoding — all three names are themselves randomized in other polymorphic variants) both used an undeclared variable k as a loop counter, making it an implicit global rather than a local variable. Inside the outer 64-iteration decode loop (bounded by k<=63), the shared counter caused progress to stall in a repeating 48→49 sequence, pegging a single CPU core near 100%, and hanging the browser tab for roughly 30 seconds — an unintentional, self-inflicted defect in the polymorphic engine rather than a deliberate anti-analysis measure, though it incidentally also disrupts naive automated sample collection. Despite the pervasive per-request randomization, two elements were observed to stay constant or fall within a bounded, confirmed set across all 56 samples: the URL path segment /communications.html never changed, and the decoded page's <title> element rotated among at least 21 distinct values across the 50 scripted downloads, with "Solution," "Viewer," "Credentials," "Private," and "Authenticate" confirmed among them — both are more durable detection signals than the per-request SHA-256 hash. The credential-entry form itself only becomes visible and interactive after the client-side JavaScript decoder finishes executing; the page is non-functional with JavaScript disabled, and the observed ?good=[recipient_address] query parameter indicates the sender already held the target's email address before delivering the link.

Infrastructure-wise, the phishing page is hosted on Vanuatu's .vu ccTLD, which KnowBe4 ThreatLabs (2026-08-28) and IronScales (2025-10-18, on an unrelated but structurally identical .vu phishing incident targeting a different victim with a fabricated public-insurance-adjuster lure) both document as increasingly abused ground for disposable phishing domains: open registration without strict ID verification, default WHOIS privacy, low cost/bulk pricing, and automated free TLS issuance (Let's Encrypt) that lets a .vu page present a legitimate-looking HTTPS padlock. KnowBe4 recorded a 159.6% rise in phishing sites and 1,660 unique malicious .vu domains between April and July 2026 — concentrated through the registrars Dynadot (884 domains) and Sav.com (770 domains), with domains typically operational for under 20 days before rotation, and 99.9% of observed .vu indicators appearing as embedded URLs inside email bodies rather than as sender domains (mirroring this campaign's structure: a clean/neutral delivery channel pointing to a disposable .vu landing page) — the same ccTLD family, though not the same specific domain, as this campaign's infrastructure. Barracuda's separate January 2026 threat-spotlight report on 2025 phishing-kit evolution corroborates the broader trend this campaign belongs to: rising use of polymorphic/JavaScript-obfuscated kits (dense obfuscation, Base64/XOR layering) specifically engineered to defeat static and hash-based detection, though that report describes other named kits (Whisper 2FA, Cephas, GhostFrame) rather than this campaign directly. Because hash- and signature-based detection is explicitly undermined by the polymorphism, defenders are advised to prioritize behavioral and structural indicators: the ultimate form-submission destination, browser-side JavaScript deobfuscation/eval activity, anomalous single-core CPU spikes during page load, DOM mutation patterns typical of dynamically assembled credential forms, and the campaign's stable path/title elements.

Neither source names a threat actor, campaign alias, or confirms the ultimate credential-exfiltration endpoint; no CVE or CVSS applies since this is a phishing operation rather than a software vulnerability.

MITRE ATT&CK techniques used in TL-2026-2246

Defense Evasion

T1027 Obfuscated Files or Information; T1027.003 Steganography; T1027.014 Polymorphic Code; T1140 Deobfuscate/Decode Files or Information

Collection

T1056.003 Web Portal Capture

Execution

T1059.007 JavaScript; T1204.001 Malicious Link

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains; T1608.003 Install Digital Certificate; T1608.005 Link Target

Reconnaissance

T1589.002 Email Addresses

Remediation for Polymorphic Phishing Attack Generates Unique

Immediate actions

  • Block or closely inspect the .vu ccTLD at email gateways and web proxies for organizations with no legitimate business relationship to Vanuatu, given its documented abuse for cheap, low-scrutiny disposable phishing infrastructure
  • Add DNS/web-proxy alerting for the observed domain addresses.performs.vu and its parent performs.vu, and for the constant path segment /communications.html on any newly registered .vu domain
  • Decouple email-layer and web-layer blocking so that a web-layer block/interstitial on a phishing domain triggers retroactive purge of already-delivered emails referencing that domain, closing the gap where the email lands before the link is flagged

Workarounds

  • Treat links on newly registered ccTLD domains (observed .vu campaign domains average under 20 days old) with added scrutiny, particularly generic paths like communications.html paired with a recipient-identifying query parameter such as ?good=

Longer-term hardening

  • Shift phishing-page detection away from static file-hash/signature matching toward behavioral indicators: anomalous single-core CPU spikes during page load, browser-side JavaScript deobfuscation/eval activity, and DOM mutation patterns typical of dynamically assembled credential-harvesting forms
  • Monitor Certificate Transparency logs for newly issued Let's Encrypt certificates on rare ccTLDs (e.g. .vu) combined with brand-relevant or generic lure keywords in the hostname/path
  • When triaging a reported phishing URL, retrieve it multiple times and diff the resulting page content/hash before publishing a single-hash indicator, since a single download will not reveal server-side polymorphism

Timeline of Polymorphic Phishing Attack Generates Unique

  • GBHackers publishes coverage of the SANS ISC findings under the title "Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit," which is the source feed that triggered this hunt.
  • Jan Kopriva publishes the SANS Internet Storm Center diary "A polymorphic phishing page (that occasionally breaks itself)," documenting the server-side polymorphism technique and the obfuscator bug, and assesses that a conventional polymorphic obfuscator (not a real-time LLM generator) most plausibly produced the samples.
  • Deobfuscation of 56 collected samples shows 2 fail to render: two JavaScript functions (_il and _YF, with helper _ie) share an undeclared global loop variable k, causing the 64-iteration decode loop to stall in a repeating 48→49 sequence, ~100% single-core CPU usage, and a ~30-second browser hang.
  • An automated script retrieves the phishing URL (addresses.performs.vu/communications.html) 50 times; each of the 50 downloaded pages produces a distinct SHA-256 hash despite functioning identically, with 21 distinct page titles observed.
  • SANS ISC handler Jan Kopriva's spam trap intercepts an email containing the phishing link later analyzed as this polymorphic credential-harvesting campaign.
  • KnowBe4 ThreatLabs publishes a companion trend report documenting a 159.6% rise in phishing sites and 1,660 unique malicious .vu-ccTLD domains observed April-July 2026, concentrated through the registrars Dynadot and Sav.com — the same Vanuatu domain family hosting this campaign's addresses.performs.vu page.

Sources cited for Polymorphic Phishing Attack Generates Unique

Detection coverage for TL-2026-2246

As of 2026-08-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2246 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
6 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats