The Redirect That Lied About Its Own Destination
ID: 5778da9f-935f-5f53-9d43-8285e4593023
STIX ID: report--5778da9f-935f-5f53-9d43-8285e4593023
Feed Name: IRONSCALES
A spearphishing email impersonating a hospital targeted a foundation gift officer with a single "View Emails" CTA that used a TikTok bio-link redirector decorated with ad-network parameters and a per-recipient base64 fragment; automated URL scans returned clean while an observed successful traversal resolved to a disposable .vu domain serving a checkbox bot-gate. The sender display name impersonated the hospital but the header-from belonged to an unrelated nonprofit (DMARC p=none), and the message was delivered via Amazon SES; Adaptive AI flagged it as credential-harvesting phishing and quarantined the single impacted mailbox.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
