Attackers Abuse URL Rewriting to Evade Security Filters
ID: 0fd99063-5ae3-5fc4-a140-603b6dbad3fb
STIX ID: report--0fd99063-5ae3-5fc4-a140-603b6dbad3fb
Feed Name: KnowBe4 Blog
Attackers are abusing URL-rewriting features in email security solutions to disguise phishing links: they first compromise a legitimate account, cause the platform to rewrite a novel URL, then send that rewritten URL from the compromised account to victims. Because the link appears to originate from a trusted account and contains a rewritten URL from a security control, secure email gateways deliver it; victims who follow the link are prompted to install an OAuth application that grants attackers persistent access to Microsoft 365 accounts (only removable by deleting the add-on).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
