logo

Hackers Leverage Safe Links and URL Rewriting to Evade Detection

ID: aaaab8bc-2c0d-573b-824c-18e4cffec177

STIX ID: report--aaaab8bc-2c0d-573b-824c-18e4cffec177

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-17

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

LevelBlue SpiderLabs observed a growing trend (late 2024–early 2026) of threat actors abusing URL-rewriting services to create multi-layer redirect chains that disguise phishing links as trusted security or productivity domains; attackers using Tycoon2FA and Sneaky2FA AiTM kits captured credentials and session cookies via nested vendor-branded redirects and HTML attachments, enabling account takeover, business email compromise, and downstream data theft or ransomware—mitigations include behavioral detection of unusual redirect chains, layered email/web/identity controls, phishing-resistant MFA, and monitoring/conditional access to limit stolen-session impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.