Phishing attacks via ‘URL rewriting’ to evade detection escalate

Teilen:

Email attackers are increasingly exploiting “URL rewriting” in phishing attacks to evade detection while spreading malicious links, Perception Point researchers said in a blog post.

URL rewriting is a security measure in which an email protection service such as a Secure Email Gateway (SEG) wraps any URLs contained in a received email with new links under the protection service’s domain. When the rewritten URLs are clicked by the email recipient, the service scans them for potential threats before redirecting the recipient to the intended webpages.

Cybercriminals have been exploiting URL rewriting services by compromising companies that use them and leveraging the compromised email accounts to generate their own seemingly legitimate wrapped links, Barracuda revealed in a July 2024 blog post.

These types of attacks have been increasing in recent months, according to Perception Point, with the company intercepting many emails that used the phishing technique in more sophisticated ways than previously observed.

In some cases, attackers are conducting “double rewrite attacks,” in which malicious links are rewritten twice by two different security vendors to further obscure their origin. In one example from August shared by Perception Point, the attacker first wrapped their link using Proofpoint’s URL defense system and then sent the Proofpoint-wrapped link to an attacker-controlled inbox protected by INKY, generating a link with an additional layer of redirection to evade email security systems.

The final double-wrapped link was sent to one of Perception Point’s customers in an email designed to look like a shared SharePoint document and included a third layer of obfuscation — a CAPTCHA prompt designed to block analysis by automated threat detection systems. The malicious webpage after the CAPTCHA impersonated a Microsoft log-in page and ultimately aimed to steal the user’s Microsoft credentials.

URL rewriting attacks take advantage of the fact that some email security services whitelist their own domains, meaning a URL wrapped by a particular service will not be blocked when subsequently scanned by the same service. This can be useful when an attacker compromises one email account at an organization and seeks to generate phishing links targeting other members at the same organization.

However, Perception Point has also seen attackers using links generated from one organization’s compromised accounts to target multiple other organizations, potentially gaining access to other URL rewriting services to use in subsequent rewrite and double rewrite attacks.

URL rewriting attacks are better detected by dynamic and AI-powered email threat detection systems than traditional URL scanning services, according to Perception Point, as AI-powered systems can access links in a similar manner to a human user in order to analyze their behavior in real time.

By Laura French

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
6:22 am, Juli 11, 2025
Wetter-Symbol 17°C
L: 16° | H: 18°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 83 %
Druck: 1021 mb
Wind: 6 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 35%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:56 am
Sonnenuntergang: 9:15 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
16° | 18°°C 0 mm 0% 8 mph 83 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
19° | 30°°C 0 mm 0% 10 mph 66 % 1019 mb 0 mm/h
So. Juli 13 10:00 pm
Wetter-Symbol
18° | 30°°C 0 mm 0% 7 mph 71 % 1015 mb 0 mm/h
Mo. Juli 14 10:00 pm
Wetter-Symbol
18° | 28°°C 1 mm 100% 15 mph 84 % 1016 mb 0 mm/h
Di. Juli 15 10:00 pm
Wetter-Symbol
14° | 20°°C 1 mm 100% 14 mph 81 % 1017 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 2 mph 83 % 1021 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
20° | 26°°C 0 mm 0% 2 mph 73 % 1021 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
26° | 30°°C 0 mm 0% 3 mph 49 % 1020 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
32° | 32°°C 0 mm 0% 4 mph 26 % 1018 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 6 mph 29 % 1017 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 8 mph 49 % 1019 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
21° | 21°°C 0 mm 0% 5 mph 57 % 1019 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 5 mph 66 % 1018 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,198.17
5.62%
Ethereum(ETH)
€2,553.45
7.64%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€2.20
6.55%
Solana(SOL)
€141.27
5.07%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.170721
10.54%
Shiba Inu(SHIB)
€0.000012
8.57%
Pepe(PEPE)
€0.000011
16.31%
Peanut das Eichhörnchen(PNUT)
€0.251623
22.48%
Nach oben scrollen