Analysis of e-banking phishing via cloned web interfaces: Attack vectors and detection approaches
Abstract
With the widespread adoption of digital banking platforms, phishing-based fraudulent redirection attacks have become one of the most critical cyber threats targeting the financial sector. Data published by the National Cyber Incident Response Center (USOM) show that malicious URLs in Türkiye have reached hundreds of thousands, indicating the persistence of locally operated phishing campaigns and the increasing diversity of attackers’ techniques. This study presents a forensic case analysis of a phishing incident targeting e-banking users, focusing on domain manipulation, cloned web interfaces, and reverse-proxy-based session hijacking. The analysis examines domain registration records, hosting infrastructure, certificate attributes, redirection flow, and HTML structure within a structured multi-layered framework. The findings show that attackers rely on short-lived and rapidly changing domain infrastructures to support credential theft and session hijacking attempts. In addition, several indicators of compromise (IoCs) were derived with the support of USOM data to facilitate the early detection of similar attacks. The results indicate that phishing campaigns cannot be mitigated solely through user awareness; instead, DNS, content, certificate, and infrastructure indicators should be evaluated together.