Scenario Brief: AI-Powered Phishing Tradecraft Targeting Indian Fintech

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
May 22, 2026
2 min read
Read as
Scenario brief — not a report of a live incident
This is a RingSafe Threat Scenario designed for SOC training, tabletop exercises, and board-level cyber discussions. Specific CVE identifiers, advisory numbers, organisation references, dates, and figures used below are illustrative. Always verify against authoritative sources (CERT-In, NVD, vendor advisories, regulator websites) before taking operational action.
An active phishing campaign tracked as “MorphLure (scenario actor)” is targeting Indian fintech and payments-aggregator employees using LLM-generated lookalike domains and AI-rendered voice deepfakes of senior leadership. Twelve confirmed victims across four PA-PG entities since 9 May. Severity: high.

RingSafe Threat Bulletin — Tracker ID RST-XXXX-XXXX (illustrative) — 22 May 2026

Campaign profile

MorphLure (scenario actor) is a financially motivated cluster operating since at least November 2025, but its Indian-fintech focus is new. The actor uses ChatGPT-class LLMs to generate (a) hyper-realistic spear-phishing emails referencing the target’s actual recent calendar entries scraped from leaked Calendly metadata, (b) lookalike domains using IDN homoglyphs registered through Cloudflare-fronted hosting, and (c) 8-12 second voice deepfakes used in follow-up vishing calls.

Observed kill chain

  • Recon — LinkedIn scraping of finance, treasury, compliance roles at Indian PA-PGs, neobanks, lending NBFCs.
  • Initial access — spear-phish email containing a OneDrive lookalike link that delivers a stub loader signed with a recently-stolen Authenticode certificate.
  • Credential harvest — Microsoft 365 lookalike login page that proxies the real auth flow (Evilginx2 variant) and captures session cookies post-MFA.
  • Pivot — deepfake voice call to a junior finance staffer impersonating the CFO, requesting urgent wire transfer override.

RingSafe analysis

This is the cleanest example we have seen of an AI-native fraud kit being operationalised against the Indian BFSI surface. Two things matter: the actor has solved the “uncanny valley” voice problem that defeated earlier deepfake fraud, and they have built tradecraft around stealing Authenticode certs, which means traditional code-signing trust assumptions in your EDR policy now create a blind spot.

Detection signals

  • Outbound DNS to *.workers.dev subdomains containing Devanagari or Cyrillic homoglyphs of your corporate domain.
  • Microsoft Entra ID sign-in from a new device immediately followed by an OAuth consent grant to an unknown enterprise app.
  • Authenticode-signed executables in %APPDATA%LocalTemp from publishers not in your signed-binary inventory.

What CISOs should do this week

  • Add a verbal-callback policy on all wire transfers above ₹5 lakh, using a fresh phone number from HRMS — not the number on the requestor’s email signature.
  • Enable Microsoft Defender for Cloud Apps “anomalous OAuth grant” policy if not already on.
  • Brief the C-suite that their public conference talks are now training data for deepfake voices; restrict high-fidelity audio output.
Worried about your exposure?

Get a free attack-surface review

We check what an attacker would see about your business — leaked credentials, exposed services, dark-web mentions. 30 minutes, no obligation.

Book exposure review Replies in 4 working hrs · India-only · Senior consultants