Cybercriminals Abuse Email URL Manipulation to Embed Phishing Links

Cybercriminals have discovered a new way to exploit email URL rewriting, a security feature originally designed to safeguard users from phishing attacks. This technique has transformed a protective tool into a potential security flaw, prompting concern among cybersecurity professionals.

URL Rewriting Explained

URL rewriting is a mechanism used by email security providers to defend against malicious links in emails. When a user clicks on a link, it first gets routed through the provider’s server for a security check. If the link is deemed safe, it then redirects the user to the intended website; if not, access is blocked.

Two Approaches to URL Rewriting

URL rewriting generally follows two models:

  • Traditional Security Approaches: These methods use predefined rules and threat signatures to rewrite URLs for subsequent analysis. They rely on updated threat databases but may only catch threats after an initial compromise has occurred.
  • Advanced Security Solutions: These use real-time technologies like machine learning and computer vision to analyze links at the moment of the click. They assess the behavior of URLs instantly, offering a more proactive defense compared to traditional methods.

Many organizations use a combination of these strategies, integrating tools such as Secure Email Gateways (SEG) and Integrated Cloud Email Security (ICES) for enhanced protection.

Recent Exploits of URL Rewriting

Since mid-June 2024, attackers have been manipulating URL rewriting features to insert phishing links. This exploitation capitalizes on the trust users place in well-known security brands, making even careful employees more susceptible to clicking on deceptive links.

Methods of Exploitation

Hackers typically use two strategies:

  • Compromising Email Accounts: This common method involves breaching legitimate email accounts protected by URL rewriting. Attackers then send emails containing URLs that appear clean but are actually phishing attempts. After the URL passes through the security service and is rewritten to include the vendor’s branding, it gains a layer of perceived safety.
  • Abusing Whitelisting Practices: Some email security services whitelist their URL rewriting domains. Attackers exploit this by modifying the destination of a rewritten URL once it is whitelisted, redirecting users to phishing sites while bypassing further security checks.

Notable Examples of Exploitation

Researchers from Perception Point have identified several phishing attacks leveraging URL protection services:

  • Double Rewrite Attack: In a sophisticated attack, attackers used rewritten links processed by both Proofpoint and INKY. The email contained a phishing link disguised as a legitimate SharePoint notification. After passing through two levels of URL rewriting, the user was redirected to a phishing site mimicking a Microsoft 365 login page.
  • Broad-Based Phishing Campaign: Another attack involved a rewritten URL from compromised accounts protected by INKY and Proofpoint. This allowed attackers to target multiple organizations with a single compromised URL, expanding their phishing campaign.
  • Mimecast Exploit: Perception Point detected a phishing attempt where Mimecast’s URL rewriting service was used to mask a malicious link. Despite appearing safe due to the Mimecast domain, the link directed users to a phishing site designed to steal credentials.
  • IRS Phishing Attack: Sophos’s URL rewriting service was used in an attack where the phishing email seemed like an urgent verification request from a legitimate organization. The rewritten URL added an extra layer of credibility, making it challenging for recipients to identify the threat.

Dynamic URL Analysis: A Superior Solution

To address these advanced threats, Perception Point offers Dynamic URL Analysis, which provides a more effective defense compared to traditional URL rewriting. This approach actively evaluates URLs and their behavior before they reach the user’s inbox.

Key Features of Dynamic URL Analysis:

  • Real-Time Detection: Scans and assesses URLs instantly, preventing malicious content from reaching the inbox.
  • Advanced Evasion Countermeasures: Capable of overcoming evasion tactics such as CAPTCHA and geo-fencing.
  • Post-Delivery Reassessment: Utilizes big data to autonomously rescan and re-evaluate links even after delivery.
  • Enhanced Browser Security: Monitors URLs upon click, ensuring real-time detection of any harmful activity.

The exploitation of URL rewriting features highlights the necessity for continuous advancements in email security. As attackers refine their tactics, security solutions must evolve to stay ahead. Organizations are encouraged to implement advanced detection methods like Dynamic URL Analysis to defend against these emerging phishing threats.

More Articles & Posts