VYPR
researchPublished Aug 21, 2026· 1 source

Scammers Leverage $25 Website Template to Build Hundreds of 'Phantom Bank' Domains

Cybercriminals are using an inexpensive website template to construct a vast network of fake bank domains, designed to facilitate various fraud schemes.

A seemingly innocuous phrase on a suspicious website led researchers at Allure Security to uncover a widespread operation involving hundreds of 'phantom banks.' The investigation began when a domain resembling a financial services client's brand was found to display an unrelated bank, prompting a deeper dive into its origins and purpose.

Upon discovering the phrase "one of the largest digital banking providers" on the imposter site, researchers initiated a search that identified approximately 2,200 matching domains. The initial question was why a fabricated bank would be associated with a domain linked to another brand, which suggested the sites were not intended for direct brand impersonation but served a different fraudulent function.

Further analysis revealed that nearly half of these domains, specifically 1,095, hosted working web pages. Of these, a significant portion, 838, still contained the original search phrase. The research indicated that a staggering 97% of these 838 sites utilized parts of 'Cuex,' a front-end template marketed for currency exchange and digital banking sites, often for as little as $25. This template provided a foundation for creating convincing, albeit fake, banking interfaces.

Adding to the legitimacy stacking, the Cuex template was frequently paired with Laravel, a PHP framework found on 94% of the sites, which handles essential functions like logins, sessions, registration, and account access. The presence of common elements such as a misspelled heading "Curreny Charts" on 90% of the sites further solidified the pattern of using a shared, low-cost infrastructure.

These phantom bank sites were meticulously constructed to appear credible, incorporating features like banking interfaces, investment products, corporate details, and support contacts. Researchers observed that 770 of the sites presented login pages, 767 set session cookies, and 729 included anti-forgery tokens, all indicative of applications designed to capture and process user data.

The discovered phantom financial sites fit a familiar fraud model where a victim is introduced to an unfamiliar financial institution by a broker, romantic contact, loan agent, or other intermediary. The fake portal then provides a persistent interface for managing accounts, viewing balances, tracking investment gains, and handling transfers, often culminating in fabricated withdrawal problems to extort victims.

A critical clue emerged when one site, branded as Classtands Crest, inadvertently exposed its origins through a sloppy copy-paste error. The account-creation page's source code still contained the title "Create an Account- Remedy bank," a remnant from its source. This registration form was configured to send submitted data to a separate domain, remedycodes[.]site, which had previously been flagged for suspected fraud.

Allure Security advises investigators to look for tell-tale signs such as the "Curreny Charts" typo, shared website paths and code, matching cookies and contact details, and forms submitting data to common destinations. Independent verification of financial institutions' claims and meticulous evidence preservation are crucial steps in combating these sophisticated, yet often sloppily executed, fraud operations.

Synthesized by Vypr AI