The Blind Spot: How “Bulletproof” Phishing Redirectors Slip Past SEGs
ID: 61692e47-0879-5ef9-9eb2-4c26ca57d5b3
STIX ID: report--61692e47-0879-5ef9-9eb2-4c26ca57d5b3
Feed Name: KnowBe4 Blog
The report documents an active phishing campaign using a "Bulletproof" blind redirector kit that hides AiTM backends behind disposable compromised legitimate websites; it resolves campaign tokens server-side, serves a fake OneDrive loading lure with a JavaScript timed window.location.replace redirect, fingerprints visitors via a persistent bp_redir_sess PHP session cookie to evade scanners, and forwards only validated victims to downstream AiTM platforms (Sneaky2FA, Tycoon 2FA) that can bypass MFA — the analysis includes hosts, path indicators, token formats, delivery senders (notably QuickBooks/DocuSign abuse), examples of per-recipient tracking, and mitigations such as phishing-resistant FIDO2, conditional access, and monitoring for token replay.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
