Phishing attacks via ‘URL rewriting’ to evade detection escalate

Teilen:

Email attackers are increasingly exploiting “URL rewriting” in phishing attacks to evade detection while spreading malicious links, Perception Point researchers said in a blog post.

URL rewriting is a security measure in which an email protection service such as a Secure Email Gateway (SEG) wraps any URLs contained in a received email with new links under the protection service’s domain. When the rewritten URLs are clicked by the email recipient, the service scans them for potential threats before redirecting the recipient to the intended webpages.

Cybercriminals have been exploiting URL rewriting services by compromising companies that use them and leveraging the compromised email accounts to generate their own seemingly legitimate wrapped links, Barracuda revealed in a July 2024 blog post.

These types of attacks have been increasing in recent months, according to Perception Point, with the company intercepting many emails that used the phishing technique in more sophisticated ways than previously observed.

In some cases, attackers are conducting “double rewrite attacks,” in which malicious links are rewritten twice by two different security vendors to further obscure their origin. In one example from August shared by Perception Point, the attacker first wrapped their link using Proofpoint’s URL defense system and then sent the Proofpoint-wrapped link to an attacker-controlled inbox protected by INKY, generating a link with an additional layer of redirection to evade email security systems.

The final double-wrapped link was sent to one of Perception Point’s customers in an email designed to look like a shared SharePoint document and included a third layer of obfuscation — a CAPTCHA prompt designed to block analysis by automated threat detection systems. The malicious webpage after the CAPTCHA impersonated a Microsoft log-in page and ultimately aimed to steal the user’s Microsoft credentials.

URL rewriting attacks take advantage of the fact that some email security services whitelist their own domains, meaning a URL wrapped by a particular service will not be blocked when subsequently scanned by the same service. This can be useful when an attacker compromises one email account at an organization and seeks to generate phishing links targeting other members at the same organization.

However, Perception Point has also seen attackers using links generated from one organization’s compromised accounts to target multiple other organizations, potentially gaining access to other URL rewriting services to use in subsequent rewrite and double rewrite attacks.

URL rewriting attacks are better detected by dynamic and AI-powered email threat detection systems than traditional URL scanning services, according to Perception Point, as AI-powered systems can access links in a similar manner to a human user in order to analyze their behavior in real time.

By Laura French

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:35 am, Juni 28, 2025
Wetter-Symbol 19°C
L: 18° | H: 20°
broken clouds
Luftfeuchtigkeit: 84 %
Druck: 1022 mb
Wind: 8 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:45 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
18° | 20°°C 0 mm 0% 11 mph 84 % 1025 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 31°°C 0 mm 0% 7 mph 79 % 1025 mb 0 mm/h
Mo. Juni 30 10:00 pm
Wetter-Symbol
21° | 35°°C 0.2 mm 20% 9 mph 69 % 1021 mb 0 mm/h
Di. Juli 01 10:00 pm
Wetter-Symbol
22° | 32°°C 0 mm 0% 10 mph 70 % 1017 mb 0 mm/h
Mi. Juli 02 10:00 pm
Wetter-Symbol
20° | 28°°C 0.85 mm 85% 14 mph 69 % 1018 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 9 mph 84 % 1022 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
22° | 24°°C 0 mm 0% 10 mph 76 % 1023 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 11 mph 55 % 1024 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 10 mph 50 % 1023 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 9 mph 57 % 1023 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 8 mph 66 % 1025 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 7 mph 69 % 1025 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 5 mph 79 % 1025 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,459.63
-0.12%
Ethereum(ETH)
€2,065.78
-0.85%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€1.86
3.58%
Solana(SOL)
€122.26
1.44%
USDC(USDC)
€0.85
0.01%
Dogecoin(DOGE)
€0.138169
-0.17%
Shiba Inu(SHIB)
€0.000009
0.44%
Pepe(PEPE)
€0.000008
-0.56%
Nach oben scrollen