Redirect Laundering: How Attackers Weaponize Trusted Infrastructure to Bypass Email Security
ID: d561e82e-646c-5f82-ab9c-8d65893c239e
STIX ID: report--d561e82e-646c-5f82-ab9c-8d65893c239e
Feed Name: IRONSCALES
Threat Score
This report documents two high-confidence phishing campaigns that leveraged "redirect laundering"—routing malicious links through trusted security and academic/cloud infrastructure (SafeLinks, Cisco Secure Web, an AAF portal, and Amazon S3) to obscure final credential-harvesting pages—providing redirect chains, IOCs, and analysis showing static URL reputation checks can be bypassed and recommending chain-aware, behavior-based defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
