logo

Redirect Laundering: How Attackers Weaponize Trusted Infrastructure to Bypass Email Security

ID: d561e82e-646c-5f82-ab9c-8d65893c239e

STIX ID: report--d561e82e-646c-5f82-ab9c-8d65893c239e

Feed Name: IRONSCALES

Threat Score
75/100

Date Published: 2026-03-25

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

This report documents two high-confidence phishing campaigns that leveraged "redirect laundering"—routing malicious links through trusted security and academic/cloud infrastructure (SafeLinks, Cisco Secure Web, an AAF portal, and Amazon S3) to obscure final credential-harvesting pages—providing redirect chains, IOCs, and analysis showing static URL reputation checks can be bypassed and recommending chain-aware, behavior-based defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.