logo

Attackers Abuse URL Rewriting to Evade Security Filters

ID: 0fd99063-5ae3-5fc4-a140-603b6dbad3fb

STIX ID: report--0fd99063-5ae3-5fc4-a140-603b6dbad3fb

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2024-10-08

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

Attackers are abusing URL-rewriting features in email security solutions to disguise phishing links: they first compromise a legitimate account, cause the platform to rewrite a novel URL, then send that rewritten URL from the compromised account to victims. Because the link appears to originate from a trusted account and contains a rewritten URL from a security control, secure email gateways deliver it; victims who follow the link are prompted to install an OAuth application that grants attackers persistent access to Microsoft 365 accounts (only removable by deleting the add-on).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.