The urlscan Threat Research Team identified a suspicious IP address hosting a cluster of phishing sites predominantly targeting UK banks, including HSBC , Lloyds , Metro Bank , Barclays , and Revolut . Pivoting from this IP address using shared nameserver infrastructure revealed a much broader network, including two distinct administrative panels self-identified as FluxPanel and FastFlux, a historic nameserver pair still carrying the same targeting pattern, and an overlapping second cluster. Analysis of the panels’ source code, combined with direct interaction with a live deployment, indicated