EXECUTIVE SUMMARY
Secure Email Gateways (SEGs) play a crucial role in safeguarding organizations from email-based threats such as malware, spam, and phishing. However, threat actors have found ways to exploit SEGs by encoding malicious URLs within emails, effectively bypassing the security measures in place. Security researchers have recently observed a significant increase in such attacks, particularly in the second quarter of 2024. The tactic involves using SEGs to encode or rewrite URLs, which are then trusted by the recipient's SEG without proper reviewing. This loophole allows malicious emails to reach potential victims, posing a significant security threat to organizations relying on SEGs for email protection.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
Secure Email Gateways (SEGs) play a crucial role in safeguarding organizations from email-based threats such as malware, spam, and phishing. However, threat actors have found ways to exploit SEGs by encoding malicious URLs within emails, effectively bypassing the security measures in place. Security researchers have recently observed a significant increase in such attacks, particularly in the second quarter of 2024. The tactic involves using SEGs to encode or rewrite URLs, which are then trusted by the recipient's SEG without proper reviewing. This loophole allows malicious emails to reach potential victims, posing a significant security threat to organizations relying on SEGs for email protection.[emaillocker id="1283"]
The core of the problem lies in how SEGs handles encoded URLs. When a SEG encodes a URL, it rewrites it to point to its own infrastructure, apparently to check the link's safety before redirecting the user to the intended destination. However, some SEGs fail to properly scan these already encoded URLs, either by implicitly trusting them or by only scanning the domain of the sending SEG, not the destination. This oversight allows malicious URLs to pass through undetected. Tools most exploited for this purpose include VIPRE Email Security, BitDefender LinkScan, Hornet Security Advanced Threat Protection URL Rewriting, and Barracuda Email Gateway Defense Link Protection. These tools have been used in various phishing campaigns, often spoofing well-known brands like DocuSign and Microsoft to exploit recipients' trust.
The rise in attacks exploiting SEG-encoded URLs underscores the need for enhanced email security measures and user awareness. As threat actors become more adept at bypassing traditional security mechanisms, organizations must invest in advanced threat detection technologies and robust training programs for employees. User vigilance remains a critical line of defense, as informed and cautious users are less likely to fall victim to phishing attempts, even when URLs appear to be encoded by trusted SEGs. Ultimately, while SEGs provide valuable protection, their effectiveness can be compromised without continuous improvements and a proactive approach to emerging threats. Organizations must stay aware and adapt to the evolving landscape of email security threats.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Defense Evasion | T1070 | Indicator Removal on Host |
| T1190 | Exploit Public-Facing Application | |
| T1027 | Obfuscated Files or Information | |
| T1203 | Exploitation for Client Execution | |
| T1553 | Subvert Trust Controls | |
| T1112 | Modify Registry | |
| T1110 | Brute Force | |
| T1068 | Exploitation for Privilege Escalation | |
| T1564 | Hide Artifacts | |
| Credential Access | T1078 | Valid Accounts |
| T1056 | Input Capture | |
| T1555 | Credentials from Password Stores | |
| Persistence | T1053 | Scheduled Task/Job |
| T1136 | Create Account | |
| T1505 | Server Software Component | |
| T1078 | Valid Accounts | |
| T1098 | Account Manipulation | |
| T1543 | Create or Modify System Process | |
| Privilege Escalation | T1055 | Process Injection |
| T1068 | Exploitation for Privilege Escalation | |
| T1548 | Abuse Elevation Control Mechanism | |
| Execution | T1059 | Command and Scripting Interpreter |
| T1072 | Software Deployment Tools | |
| T1569 | System Services | |
| Command and Control | T1071 | Application Layer Protocol |
| Collection | T1113 | Screen Capture |
| T1125 | Video Capture | |
| T1056 | Input Capture | |
| T1213 | Data from Information Repositories | |
| Impact | T1489 | Service Stop |
| T1490 | Inhibit System Recovery | |
| T1529 | System Shutdown/Reboot |
REFERENCES:
The following reports contain further technical details:
https://www.darkreading.com/cyberattacks-data-breaches/threat-actors-ramp-up-use-of-encoded-urls-to-bypass-secure-email