Attackers Using HTTP Response Headers to Redirect Victims to Phishing Pages
ID: 7098a189-e93a-503c-9cb4-edb8968e6231
STIX ID: report--7098a189-e93a-503c-9cb4-edb8968e6231
Feed Name: KnowBe4 Blog
Unit 42 researchers observed a large-scale 2024 phishing campaign technique where attackers use the HTTP response header "refresh" directive to auto-redirect browsers to credential-harvesting pages without user interaction. Campaigns (≈2,000 malicious URLs/day detected May–July) targeted finance, government, education and business sectors, leveraged legitimate or compromised domains, and used URL parameters and deep linking to pre-fill and personalize spoofed webmail login pages delivered via tailored phishing emails.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
