ASEC identifies new phishing emails impersonating OTT services
ASEC has recently identified a wave of highly sophisticated phishing emails impersonating well-known OTT services in an attempt to steal users’ personal and payment information. The attackers prompt victims to click the ‘Update Now’ hyperlink by claiming that a subscription payment issue has occurred, leading to a fake login page. Unlike typical phishing tactics—where the victim’s email address is automatically pre-filled—this campaign requires users to manually enter their account details, making the login process appear normal and reducing the likelihood of suspicion. Let’s take a closer look at how this phishing attack unfolds.


Figure 1. Phishing email body
When the hyperlink is clicked, the victim is redirected to a fake login page, as shown in Figure 2. Many phishing emails place the victim’s email address in the URL so the login field is auto filled when the page is loaded. However, this campaign intentionally requires the user to enter their email address manually, mimicking the usual login experience and making the phishing attempt more difficult to detect.

Figure 2. Fake login page disguised as a genuine sign-in screen
Once the victim attempts to log in, the entered email address and password are transmitted to the attacker’s C2 server. The page then displays a message claiming that an automatic renewal attempt has failed and encourages the user to click “Resume my subscription.”

Figure 3. Account credentials transmitted to the C2 (test sample)
Figure 4. Fake subscription renewal page
Clicking this prompt leads to another fake webpage, shown in Figure 5, requesting credit card information. Similar to the fake login page, the website transmits the victim’s name, phone number, and credit card details to the C2 server, as shown in Figure 6.
Figure 5. Fake credit card entry page

Figure 6. Credit card information sent to the C2 (test sample)
When viewing emails from unknown senders, users must exercise extreme caution. It is essential to verify whether the sender is legitimate and avoid clicking suspicious links or opening unexpected attachments. Emails that request personal or financial information should be treated with even greater scrutiny and verified through trusted channels.
In recent cases, attackers have increasingly abused legitimate platforms as C2 servers, enabling phishing campaigns to bypass security controls and operate with minimal visibility. As a result, users must remain even more vigilant and review such messages carefully to avoid falling victim to these threats.