A new phishing kit called CryptoChameleon is targeting Federal Communications Commission (FCC) employees using specially crafted single sign-on (SSO) pages for Okta. The pages are similar to the real ones, confusing the employees.
The phishing kit is also being used to target employees and users platforms cryptosuch as Binance, Coinbase, Kraken, and Gemini. In these attacks, phishing pages impersonating Okta, Gmail, iCloud, Outlook, Twitter, Yahoo, and AOL are used.

Attackers are conducting sophisticated phishing and social engineering, which include emails, SMS, and voice phishing. The goal is to extract sensitive information from victims, such as usernames, passwords, and even photo IDs.
The attacks were discovered by Lookout researchers, and according to their observations, they resemble the 2022 Oktapus campaign carried out by hackers Scattered Spider.
See also: Phishing emails: Warning signs and protection tips
Socialengineering attacks
Attackers use domains that closely resemble the domains of the legitimate entities they impersonate. In the case of the FCC attacks , they created “ fcc-okta[.]com ,” which has only one character different from the FCC’s legitimate Okta single-sign-on page. So, someone might not immediately notice the difference.
The attackers then call the victims on the phone, send emails or SMS and impersonate customer support, directing the victims to the phishing website for the supposed recovery of their accounts.
Victims who are convinced and go to the phishing website are asked to solve a CAPTCHA challenge, which is intended to lend legitimacy to the process.
Those who go through this step end up on a well-designed phishing page, which looks like the genuine Okta login site.
The CryptoChameleon phishing kit developed by cybercriminals allows them to interact with victims in real-time to request additional authentication in case multi-factor authentication (MFA) codes are required. This allows attackers to gain control of victims’ accounts.
The central panel that controls the phishing process allows attackers to customize the phishing page to include the digits of the victim's phone number, making the SMS tokens appear legitimate.
See also: TimbreStealer malware spreads via phishing scams

After the phishing process is complete, the victim may be redirected to the login page of the real platform or to a fake portal that states that their account is being verified.
In both cases, attackers gain time to exploit the stolen information.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
CryptoChameleon phishing kit and attacks
Lookout researchers analyzed the phishing kit and found various clues about the lures used by hackers and their targets.
Researchers also gained short-term access to the attacker's backend logs and found that the phishing sites tricked more than 100 people. Additionally, many of the phishing sites are active and still stealing credentials from unsuspecting users and employees.
Researchers saw that threat actors primarily used Hostwinds and Hostinger to host the phishing pages in late 2023. They later switched to Russia-based RetnNet
Lookout was unable to determine whether the CryptoChameleon phishing kit is used by specific hackers or is rented to multiple groups.
See also: Bitwarden: New auto-fill option reduces the risk of credential phishing
In any case, the number of attacks and the multifaceted approach to victims (email, SMS, calls, etc.) indicate that this is a significant threat and that users should be careful.
The first and most important step in protecting against phishing attacks is education. It is essential to recognize a phishing attempt, which may include suspicious emails, links, or login pages, as in the case of CryptoChameleon.

Second, always use software security. This can include antivirus programs and anti-phishing software. These tools can help you identify and avoid phishing attempts.
Third, be careful with your personal data. Never share personal information, such as credentials, bank details, or card numbers, via email or on websites that you are directed to by strange links. Type the name of the service into your browser and always log in from the official page.
Finally, using different passwords for different accounts and changing them regularly can help protect your accounts.
Source: www.bleepingcomputer.com
