Phishing attacks have become more sophisticated as criminals find ways to abuse the very defenses meant to stop them. The latest scheme, documented by Cloudflare and reported by The Hacker News, abuses link‑wrapping services provided by email‑security vendors like Proofpoint and Intermedia to hide phishing URLs behind multiple layers of redirection. Link wrapping ordinarily works by scanning a destination when a user clicks; if it’s malicious, the link is blocked. However, threat actors discovered that if the wrapped link hasn’t been flagged yet, the system will allow the redirect, letting the phishing page load.
How the attack works
In recent months, attackers have been embedding shortened Bitly links inside legitimate‑looking emails that appear to come from trusted organizations. When recipients click the link, it first redirects through Bitly and then through Proofpoint’s URL Defense service, effectively concealing the true destination. Because the link passes through two obfuscation layers, defenses may fail to recognize it as malicious until it is too late.
The phishing emails often pretend to be voicemail notifications or invitations to view a document or unread message on Microsoft Teams. Clicking the embedded button takes the user to a counterfeit Microsoft 365 login page designed to harvest credentials. In some campaigns, attackers have sent messages claiming a Zoom meeting has timed out and urging the recipient to “rejoin”; victims who click the link are redirected through the same multi‑layer chain before being asked to enter their credentials. Once the credentials are submitted, they are immediately exfiltrated to the attacker via Telegram and other channels.
What makes this tactic particularly dangerous is that it can involve legitimate email accounts already using link‑wrapping protection. If an employee’s account is compromised, any malicious URL they send is automatically rewritten by the security service (e.g., urldefense.proofpoint.com/v2/url?u=<malicious>). Attackers then reuse the rewritten link in further phishing campaigns, knowing it will appear trustworthy to recipients and may not be blocked.
Additional techniques
Cloudflare notes that the multi‑layer redirect abuses coincide with a wider surge in phishing attacks using Scalable Vector Graphics (SVG) files. SVG files are written in XML and can contain scripts and hyperlinks; hackers embed malicious code inside seemingly innocuous images attached to emails. When opened, the image triggers a redirect to a credential‑harvesting site. Additionally, campaigns have embedded fake Zoom or Teams links that initiate similar redirection chains.
Defenses and mitigation
Email‑security vendors are aware of these abuses. Proofpoint said it flags the campaigns using behavioral AI detection and blocks the final URLs in the redirect chain. Nevertheless, these attacks underscore the need for layered defenses:
- Verify URLs before clicking. Hover over links to see if they point to unexpected domains; be cautious of heavily shortened or obfuscated URLs.
- Educate employees about phishing. Train staff to recognize voicemail and document‑sharing scams and to report suspicious emails.
- Enable multi‑factor authentication (MFA). Even if a password is stolen, MFA can prevent unauthorized access.
- Restrict third‑party access. Configure Microsoft 365 and other cloud services to require admin approval for OAuth applications and to block legacy authentication protocols.
Please subscribe to the Newsletter so that you do not miss any critical update
