# Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit

> A credential-harvesting phishing page hosted at addresses.performs.vu uses a server-side polymorphic generator that produces a syntactically distinct page on virtually every request — 50 downloads of the same URL yielded 50 distinct SHA-256 hashes — defeating hash- and static-signature-based detection. The obfuscator itself is buggy: 2 of 56 collected samples fail to render because two JavaScript functions share an undeclared global loop variable, causing an infinite loop and ~100% single-core CPU usage for ~30 seconds.

- **Published:** 2026-08-30T00:00:00Z
- **Last reviewed:** 2026-08-30T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2246
- **ID:** TL-2026-2246
- **Severity:** MEDIUM
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 6 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-08-27, SANS Internet Storm Center handler Jan Kopriva published the diary "A polymorphic phishing page (that occasionally breaks itself)," documenting a phishing campaign caught in his spam traps. The lure links to hxxps://addresses.performs.vu/communications.html?good=[recipient_address], a page that impersonates no specific brand but presents a generic credential-entry form. Kopriva retrieved the same URL 50 times with an automated script and found that every download returned a functionally identical but syntactically unique page: 50 distinct SHA-256 hashes and 21 distinct page titles from 50 requests. The server-side polymorphic generator varies function and variable names, reorders functions, expresses numeric constants through different arithmetic operations, randomizes form/input names, CSS class names and HTML element identifiers, randomizes image-loading parameters, and inserts zero-width characters at varying positions inside visible strings. Kopriva explicitly considered whether an LLM was generating the variants in real time (as demonstrated separately by Palo Alto Networks Unit 42's proof-of-concept for LLM-assembled runtime phishing JavaScript, which pulls generated snippets from live LLM APIs such as DeepSeek and Google Gemini via prompt-injection-style jailbreak prompts embedded in the page) but concluded a conventional polymorphic/metamorphic obfuscator is the more plausible explanation, because the transformations between samples are systematic and relatively simple rather than freeform.

Of 56 total collected samples, 2 failed to deobfuscate/render. Root cause: two of the generated functions (named _il and _YF in the specific sample examined, with a third helper, _ie, invoked during decoding — all three names are themselves randomized in other polymorphic variants) both used an undeclared variable k as a loop counter, making it an implicit global rather than a local variable. Inside the outer 64-iteration decode loop (bounded by k<=63), the shared counter caused progress to stall in a repeating 48→49 sequence, pegging a single CPU core near 100%, and hanging the browser tab for roughly 30 seconds — an unintentional, self-inflicted defect in the polymorphic engine rather than a deliberate anti-analysis measure, though it incidentally also disrupts naive automated sample collection. Despite the pervasive per-request randomization, two elements were observed to stay constant or fall within a bounded, confirmed set across all 56 samples: the URL path segment /communications.html never changed, and the decoded page's <title> element rotated among at least 21 distinct values across the 50 scripted downloads, with "Solution," "Viewer," "Credentials," "Private," and "Authenticate" confirmed among them — both are more durable detection signals than the per-request SHA-256 hash. The credential-entry form itself only becomes visible and interactive after the client-side JavaScript decoder finishes executing; the page is non-functional with JavaScript disabled, and the observed ?good=[recipient_address] query parameter indicates the sender already held the target's email address before delivering the link.

Infrastructure-wise, the phishing page is hosted on Vanuatu's .vu ccTLD, which KnowBe4 ThreatLabs (2026-08-28) and IronScales (2025-10-18, on an unrelated but structurally identical .vu phishing incident targeting a different victim with a fabricated public-insurance-adjuster lure) both document as increasingly abused ground for disposable phishing domains: open registration without strict ID verification, default WHOIS privacy, low cost/bulk pricing, and automated free TLS issuance (Let's Encrypt) that lets a .vu page present a legitimate-looking HTTPS padlock. KnowBe4 recorded a 159.6% rise in phishing sites and 1,660 unique malicious .vu domains between April and July 2026 — concentrated through the registrars Dynadot (884 domains) and Sav.com (770 domains), with domains typically operational for under 20 days before rotation, and 99.9% of observed .vu indicators appearing as embedded URLs inside email bodies rather than as sender domains (mirroring this campaign's structure: a clean/neutral delivery channel pointing to a disposable .vu landing page) — the same ccTLD family, though not the same specific domain, as this campaign's infrastructure. Barracuda's separate January 2026 threat-spotlight report on 2025 phishing-kit evolution corroborates the broader trend this campaign belongs to: rising use of polymorphic/JavaScript-obfuscated kits (dense obfuscation, Base64/XOR layering) specifically engineered to defeat static and hash-based detection, though that report describes other named kits (Whisper 2FA, Cephas, GhostFrame) rather than this campaign directly. Because hash- and signature-based detection is explicitly undermined by the polymorphism, defenders are advised to prioritize behavioral and structural indicators: the ultimate form-submission destination, browser-side JavaScript deobfuscation/eval activity, anomalous single-core CPU spikes during page load, DOM mutation patterns typical of dynamically assembled credential forms, and the campaign's stable path/title elements.

Neither source names a threat actor, campaign alias, or confirms the ultimate credential-exfiltration endpoint; no CVE or CVSS applies since this is a phishing operation rather than a software vulnerability.

## MITRE ATT&CK

- T1589.002 Email Addresses
- T1583.001 Domains
- T1608.005 Link Target
- T1608.003 Install Digital Certificate
- T1566.002 Spearphishing Link
- T1204.001 Malicious Link
- T1059.007 JavaScript
- T1027 Obfuscated Files or Information
- T1027.003 Steganography
- T1027.014 Polymorphic Code
- T1140 Deobfuscate/Decode Files or Information
- T1056.003 Web Portal Capture

## Sources

- [A polymorphic phishing page (that occasionally breaks itself)](https://isc.sans.edu/diary/A+polymorphic+phishing+page+that+occasionally+breaks+itself/33290/)
- [Polymorphic Phishing Attack Generates Unique Credential-Stealing Page on Every Visit](https://gbhackers.com/polymorphic-phishing-attack/)
- [The .vu Surge: How Threat Actors Are Exploiting Vanuatu's Domain Extension](https://blog.knowbe4.com/vu-domain-phishing-surge-exploiting-vanuatu-tld)
- [Cloudflare Blocked the Page, But the Email Still Landed: A .vu TLD Phishing Domain That Slipped Through](https://ironscales.com/threat-intelligence/gmail-barracuda-relay-vu-tld-cloudflare-phishing-block-insurance-impersonation)
- [Threat Spotlight: How phishing kits evolved in 2025](https://blog.barracuda.com/2026/01/07/threat-spotlight-phishing-kits-evolved-2025)
- [The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time](https://unit42.paloaltonetworks.com/real-time-malicious-javascript-through-llms/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2246
