logo

The Redirect That Lied About Its Own Destination

ID: 5778da9f-935f-5f53-9d43-8285e4593023

STIX ID: report--5778da9f-935f-5f53-9d43-8285e4593023

Feed Name: IRONSCALES

Threat Score
75/100

Date Published: 2026-08-18

Date Updated: 2026-08-18

Author: [email protected] (Audian Paxson)

...
...

A spearphishing email impersonating a hospital targeted a foundation gift officer with a single "View Emails" CTA that used a TikTok bio-link redirector decorated with ad-network parameters and a per-recipient base64 fragment; automated URL scans returned clean while an observed successful traversal resolved to a disposable .vu domain serving a checkbox bot-gate. The sender display name impersonated the hospital but the header-from belonged to an unrelated nonprofit (DMARC p=none), and the message was delivered via Amazon SES; Adaptive AI flagged it as credential-harvesting phishing and quarantined the single impacted mailbox.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.