Threat Advisory

Exploitation of SEG-Encoded URLs to Bypass Email Security

Threat: Phishing Campaign
Targeted Region: Global
Targeted Sector: Technology & IT, Healthcare, Finance & Banking, Government & Defense, Energy & Utilities, Telecommunications, Critical Infrastructure, Retail & E-commerce, Education, Aerospace & Aviation
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Secure Email Gateways (SEGs) play a crucial role in safeguarding organizations from email-based threats such as malware, spam, and phishing. However, threat actors have found ways to exploit SEGs by encoding malicious URLs within emails, effectively bypassing the security measures in place. Security researchers have recently observed a significant increase in such attacks, particularly in the second quarter of 2024. The tactic involves using SEGs to encode or rewrite URLs, which are then trusted by the recipient's SEG without proper reviewing. This loophole allows malicious emails to reach potential victims, posing a significant security threat to organizations relying on SEGs for email protection.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

Secure Email Gateways (SEGs) play a crucial role in safeguarding organizations from email-based threats such as malware, spam, and phishing. However, threat actors have found ways to exploit SEGs by encoding malicious URLs within emails, effectively bypassing the security measures in place. Security researchers have recently observed a significant increase in such attacks, particularly in the second quarter of 2024. The tactic involves using SEGs to encode or rewrite URLs, which are then trusted by the recipient's SEG without proper reviewing. This loophole allows malicious emails to reach potential victims, posing a significant security threat to organizations relying on SEGs for email protection.[emaillocker id="1283"]

 

The core of the problem lies in how SEGs handles encoded URLs. When a SEG encodes a URL, it rewrites it to point to its own infrastructure, apparently to check the link's safety before redirecting the user to the intended destination. However, some SEGs fail to properly scan these already encoded URLs, either by implicitly trusting them or by only scanning the domain of the sending SEG, not the destination. This oversight allows malicious URLs to pass through undetected. Tools most exploited for this purpose include VIPRE Email Security, BitDefender LinkScan, Hornet Security Advanced Threat Protection URL Rewriting, and Barracuda Email Gateway Defense Link Protection. These tools have been used in various phishing campaigns, often spoofing well-known brands like DocuSign and Microsoft to exploit recipients' trust.

 

The rise in attacks exploiting SEG-encoded URLs underscores the need for enhanced email security measures and user awareness. As threat actors become more adept at bypassing traditional security mechanisms, organizations must invest in advanced threat detection technologies and robust training programs for employees. User vigilance remains a critical line of defense, as informed and cautious users are less likely to fall victim to phishing attempts, even when URLs appear to be encoded by trusted SEGs. Ultimately, while SEGs provide valuable protection, their effectiveness can be compromised without continuous improvements and a proactive approach to emerging threats. Organizations must stay aware and adapt to the evolving landscape of email security threats.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access T1566 Phishing
Defense Evasion T1070 Indicator Removal on Host
T1190 Exploit Public-Facing Application
T1027 Obfuscated Files or Information
T1203 Exploitation for Client Execution
T1553 Subvert Trust Controls
T1112 Modify Registry
T1110 Brute Force
T1068 Exploitation for Privilege Escalation
T1564 Hide Artifacts
Credential Access T1078 Valid Accounts
T1056 Input Capture
T1555 Credentials from Password Stores
Persistence T1053 Scheduled Task/Job
T1136 Create Account
T1505 Server Software Component
T1078 Valid Accounts
T1098 Account Manipulation
T1543 Create or Modify System Process
Privilege Escalation T1055 Process Injection
T1068 Exploitation for Privilege Escalation
T1548 Abuse Elevation Control Mechanism
Execution T1059 Command and Scripting Interpreter
T1072 Software Deployment Tools
T1569 System Services
Command and Control T1071 Application Layer Protocol
Collection T1113 Screen Capture
T1125 Video Capture
T1056 Input Capture
T1213 Data from Information Repositories
Impact T1489 Service Stop
T1490 Inhibit System Recovery
T1529 System Shutdown/Reboot

REFERENCES:

The following reports contain further technical details:
https://www.darkreading.com/cyberattacks-data-breaches/threat-actors-ramp-up-use-of-encoded-urls-to-bypass-secure-email

[/emaillocker]
crossmenu