logo

Make-Shift Brand Impersonation: Abusing Trusted Domains with Open Redirects

ID: b58e6a79-b697-571d-aa73-192ecb7bfd92

STIX ID: report--b58e6a79-b697-571d-aa73-192ecb7bfd92

Feed Name: KnowBe4 Blog

Threat Score
65/100

Date Published: 2025-02-06

Date Updated: 2026-04-28

Author: Martin Kraemer

...
...

KnowBe4 Threat Lab observed a phishing campaign (Oct 2–3, 2024) that abused open redirect (CWE-601) weaknesses in URL-rewriting/redirect services to obfuscate malicious destinations and borrow the reputation of legitimate domains, resulting in 173 reported emails primarily targeting U.S. finance and healthcare organizations; attackers delivered phishing pages via HTML attachments, PDFs with QR codes, manipulated legitimate URLs, hidden JavaScript, and fake Microsoft Teams notifications and the report provides technical details and defensive recommendations emphasizing human risk management, email filtering, MFA, patching, and training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.