logo

Weaponizing Safe Links: Abuse of Multi-Layered URL Rewriting in Phishing Attacks

ID: 5bc24b56-5900-548d-8be1-58813c33b2c6

STIX ID: report--5bc24b56-5900-548d-8be1-58813c33b2c6

Feed Name: LevelBlue SpiderLabs Blog

Threat Score
70/100

Date Published: 2026-03-12

Date Updated: 2026-04-28

Author: John Kevin Adriano

...
...

This report explains how threat actors are increasingly abusing trusted URL‑rewriting services to build multi‑vendor, multi‑layer redirect chains that obscure final phishing destinations; PhaaS frameworks like Tycoon2FA and Sneaky2FA use these chains to perform AiTM MFA bypasses, enabling account takeover and downstream BEC, data exfiltration, and ransomware. The document provides case studies, observed vendor chains, sample IOCs, and recommends defenses including behavioral detection, phishing‑resistant MFA, continuous monitoring, and user training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.