The InsureTrap


Overview
CTM360 identified a coordinated phishing campaign targeting customers of multiple insurance
providers through fraudulent websites impersonating legitimate insurance brands and online
service portals. The campaign abuses trusted insurance brands spanning various sectors,
including motor, health, life, home, and travel insurance, among others, to lure victims into
submitting personal information, policy details, account credentials, and authentication codes
under the guise of account verification, policy updates, claim processing, or customer service
requests.
Analysis of the campaign infrastructure indicates a real-time credential theft and account
takeover workflow. During the investigation, CTM360 identified and named the phishing kit
InsureOTP Kit, a previously undocumented phishing framework specifically designed to target
insurance customers. The kit collects victim-submitted information through phishing portals and
transmits it to attacker-controlled infrastructure, including Telegram bot integrations, local
storage mechanisms, and built-in backend servers. The captured data enables threat actors to
intercept one-time passwords (OTPs), gain unauthorized access to victim accounts, and facilitate account compromise.
Read the full report and explore CTM360’s latest insights and threat intelligence.



