logo

Mind your header! There's nothing refreshing about phishers' latest tactic

ID: 04b57507-14d2-5011-b5a4-90d2b7fc60a4

STIX ID: report--04b57507-14d2-5011-b5a4-90d2b7fc60a4

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2024-09-12

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Unit 42 observed an increasing phishing trend where attackers embed malicious URLs in HTTP Refresh response headers to automatically redirect victims—often via legitimate or compromised domains—to spoofed login pages that harvest credentials; roughly 2,000 large-scale campaigns were detected between May and July, with business and financial sectors heavily targeted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.