Threat Advisory

Hackers Exploit URL Rewriting Attacks to Deliver Phishing Links

Threat: Phishing Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Threat actors are exploiting vulnerabilities in URL rewriting, a feature used by email security solutions to protect users from malicious links. By abusing this security mechanism, attackers mask phishing links behind the trusted domains of well-known email security vendors. This technique leverages the credibility of these services to bypass detection and deceive even vigilant users, leading to an alarming rise in phishing campaigns.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Threat actors are exploiting vulnerabilities in URL rewriting, a feature used by email security solutions to protect users from malicious links. By abusing this security mechanism, attackers mask phishing links behind the trusted domains of well-known email security vendors. This technique leverages the credibility of these services to bypass detection and deceive even vigilant users, leading to an alarming rise in phishing campaigns.[emaillocker id="1283"]

URL rewriting works by replacing original URLs in emails with modified links that direct recipients through a security vendor’s server for scanning. Once the URL is verified as safe, the recipient is redirected to the legitimate destination. However, attackers are now using compromised email accounts protected by URL rewriting to send phishing links to themselves. These links are then rewritten with the security vendor's trusted domain, adding an additional layer of legitimacy. The attackers can later weaponize these URLs by changing the destination to a phishing site, by passing further security checks. Techniques like CAPTCHA evasion and geo-fencing are also employed to circumvent analysis by security vendors, increasing the success rate of the attack.

The abuse of URL rewriting highlights the increasingly creative tactics used by threat actors to circumvent traditional email security tools. Organizations need to bolster their defense strategies by implementing real-time dynamic URL analysis and enhancing their awareness of evolving phishing techniques. Training employees to recognize suspicious links, even those appearing to come from trusted sources, is crucial in reducing the success of these phishing attacks.

 

THREAT PROFILE:

Tactic Technique Id Technique
Reconnaissance T1592 Gather Victim Host Information
Resource Development T1587 Develop Capabilities
Initial Access T1566 Phishing
Execution T1204 User Execution
T1569 System Services
Defense Evasion T1070 Indicator Removal
T1027 Obfuscated Files or Information
Credential Access T1110 Brute Force
T1539 Steal Web Session Cookie
Collection T1114 Email Collection
T1090 Proxy
Command and Control T1568 Dynamic Resolution
Exfiltration T1048 Exfiltration Over Alternative Protocol
Impact T1499 Endpoint Denial of Service

 

REFERENCES:

The following reports contain further technical details:
https://cybersecuritynews.com/hackers-abuse-url-rewriting-in-sophisticated-phishing-attack/

[/emaillocker]
crossmenu