Hackers have found a way to exploit email URL rewriting features, a tool initially designed to protect users from phishing threats. This new tactic has raised alarms among security experts, turning a protective measure into a vulnerability.
URL rewriting is a security feature employed by email security vendors to protect users from malicious links embedded in emails.
According to the Perception Point report, When a user clicks on a link, it is first redirected to the vendor’s server, where it is scanned for threats. If deemed safe, the user is redirected to the intended web content; access is blocked.
There are two main paradigms for URL rewriting:
Organizations often combine these methods, employing tools like Secure Email Gateway (SEG) and Integrated Cloud Email Security (ICES) solutions for enhanced protection.
Since mid-June 2024, attackers have exploited URL rewriting features to insert phishing links. This manipulation takes advantage of the trust users place in known security brands, making even the most vigilant employees more likely to click on seemingly safe links.
Free Webinar on Detecting & Blocking Supply Chain Attack -> Book your Spot
Attackers typically have two options:
Security researchers from Perception Point have observed a surge in phishing attacks exploiting URL protection services. Here are some examples:
Example 1: Double Rewrite Attack
Two email security vendors, Proofpoint and INKY, were exploited in a sophisticated phishing attack. The attacker sent an email with a rewritten phishing link disguised as a legitimate SharePoint document notification.
The URL was rewritten twice, first by Proofpoint and then by INKY. After solving a CAPTCHA challenge, the user was redirected to a phishing site mimicking a Microsoft 365 login page.
Example 2: Exploiting Rewritten URLs Across Multiple Targets
In another attack, a rewritten URL generated through compromised accounts protected by INKY and Proofpoint targeted multiple organizations.
The attackers exploited the rewritten URL to extend their reach, turning a single point of compromise into a widespread phishing campaign.
Example 3: Mimecast’s URL Rewriting Exploit
Perception Point prevented a phishing attack leveraging Mimecast’s URL rewriting service. The phishing link appeared safe due to the Mimecast domain but redirected users to a phishing site designed to steal credentials.
Example 4: IRS Phishing Attack via Sophos URL Rewriting
In this attack, Sophos’s URL rewriting service disguised a malicious link. The phishing email appeared as an urgent verification request from a legitimate organization, and the rewritten URL added legitimacy, making it difficult for recipients to recognize the threat.
Perception Point offers Dynamic URL Analysis to combat these sophisticated attacks, which provides superior protection to traditional URL rewriting.
This approach actively browses new or unknown URLs and analyzes their behavior before the email is delivered.
Hackers’ exploitation of URL rewriting features underscores the need for continuous innovation in email security. As attackers become more sophisticated, security solutions must evolve to avoid these threats.
Organizations are urged to adopt advanced detection methods like Dynamic URL Analysis to protect against these evolving phishing tactics.
Are you from SOC and DFIR Teams? Analyse Malware Incidents & get live Access with ANY.RUN -> Get 14 Days Free Access
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…