Hackers Leverage Safe Links and URL Rewriting to Evade Detection
#1
Information 
Quote:Threat actors were already abusing URL rewriting mechanisms in phishing campaigns to mask malicious domains.

URL rewriting is designed to protect users by replacing original links with security-vendor URLs that scan destinations at click time.

These rewritten links route traffic through the provider’s infrastructure so they can analyze the page in real time, block known malicious sites, and log user activity for administrators. In normal operation, this is a defensive layer that helps filter out obviously bad destinations.​

Threat actors, however, are turning this model on its head. By operating from compromised mailboxes that already use URL rewriting, they generate “pre-wrapped” safe links and then reuse those trusted-domain URLs in external phishing campaigns.

[Image: Fig01_examplephishlink.png?width=628&hei...shlink.png]Example of an original phishing link (Source : LevelBlue

SpiderLabs).The end result is a phishing link that visually and technically appears to belong to a reputable security or productivity provider, even though it eventually leads to a credential-harvesting site.

From late 2024 into 2025, LevelBlue SpiderLabs observed a sharp rise in multi-layered URL rewriting chains, where attackers nest multiple already‑rewritten links together.

Continue Reading...
Reply


Messages In This Thread
Hackers Leverage Safe Links and URL Rewriting to Evade Detection - by harlan4096 - 10 hours ago

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Movies! Movies!
Nuremberg A WWII ...jAcos — 13:16
TV Series
A Knight of the Seve...jAcos — 13:11
QOwnNotes
26.3.12  Added a ...Kool — 12:27
uBOLite 2026.315.1814 (already released ...
uBOLite 2026.315.1...harlan4096 — 12:12
Microsoft Edge 146.0.3856.62
Release Summary of...harlan4096 — 12:11

[-]
Birthdays
Today's Birthdays
avatar (38)francisnj3
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (38)Charlesfibre
avatar (43)artmaGoork

[-]
Online Staff
There are no staff members currently online.

>