EXECUTIVE SUMMARY:
Threat actors are exploiting vulnerabilities in URL rewriting, a feature used by email security solutions to protect users from malicious links. By abusing this security mechanism, attackers mask phishing links behind the trusted domains of well-known email security vendors. This technique leverages the credibility of these services to bypass detection and deceive even vigilant users, leading to an alarming rise in phishing campaigns.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Threat actors are exploiting vulnerabilities in URL rewriting, a feature used by email security solutions to protect users from malicious links. By abusing this security mechanism, attackers mask phishing links behind the trusted domains of well-known email security vendors. This technique leverages the credibility of these services to bypass detection and deceive even vigilant users, leading to an alarming rise in phishing campaigns.[emaillocker id="1283"]
URL rewriting works by replacing original URLs in emails with modified links that direct recipients through a security vendor’s server for scanning. Once the URL is verified as safe, the recipient is redirected to the legitimate destination. However, attackers are now using compromised email accounts protected by URL rewriting to send phishing links to themselves. These links are then rewritten with the security vendor's trusted domain, adding an additional layer of legitimacy. The attackers can later weaponize these URLs by changing the destination to a phishing site, by passing further security checks. Techniques like CAPTCHA evasion and geo-fencing are also employed to circumvent analysis by security vendors, increasing the success rate of the attack.
The abuse of URL rewriting highlights the increasingly creative tactics used by threat actors to circumvent traditional email security tools. Organizations need to bolster their defense strategies by implementing real-time dynamic URL analysis and enhancing their awareness of evolving phishing techniques. Training employees to recognize suspicious links, even those appearing to come from trusted sources, is crucial in reducing the success of these phishing attacks.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Reconnaissance | T1592 | Gather Victim Host Information |
| Resource Development | T1587 | Develop Capabilities |
| Initial Access | T1566 | Phishing |
| Execution | T1204 | User Execution |
| T1569 | System Services | |
| Defense Evasion | T1070 | Indicator Removal |
| T1027 | Obfuscated Files or Information | |
| Credential Access | T1110 | Brute Force |
| T1539 | Steal Web Session Cookie | |
| Collection | T1114 | Email Collection |
| T1090 | Proxy | |
| Command and Control | T1568 | Dynamic Resolution |
| Exfiltration | T1048 | Exfiltration Over Alternative Protocol |
| Impact | T1499 | Endpoint Denial of Service |
REFERENCES:
The following reports contain further technical details:
https://cybersecuritynews.com/hackers-abuse-url-rewriting-in-sophisticated-phishing-attack/