Phishing Pages Delivered Through Refresh HTTP Response Header
ID: 3d6eec7b-45b1-588a-8524-afb4eae72b99
STIX ID: report--3d6eec7b-45b1-588a-8524-afb4eae72b99
Feed Name: Palo Alto Networks Unit 42
Unit 42 observed widespread phishing campaigns (May–July 2024) that abused HTTP response header "Refresh" entries to automatically redirect recipients—often with their email address embedded—to tailored credential-harvesting pages impersonating webmail/login portals; the report includes detection statistics (thousands of malicious URLs and ~2,000 URLs/day at peak), sample URL chains, a CSV of 58 sanitized IOCs, targeted industry breakdowns, and mitigation recommendations including Palo Alto Networks Advanced URL Filtering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
