Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Phishing Attacks Bypass Security With Trusted Email and URL Cloaking
September 15, 2026
Google Search Update Hides URLs, Increases Phishing Risk
September 15, 2026
Critical WooCommerce Bug Lets Attackers Take Over WordPress Sites
September 15, 2026
Home/Threats/Phishing Attacks Bypass Security With Trusted Email and URL Cloaking
Threats

Phishing Attacks Bypass Security With Trusted Email and URL Cloaking

Key Takeaways Sophisticated phishing campaigns are leveraging trusted email infrastructure and advanced URL cloaking techniques to bypass conventional security defenses. Attackers are sending...

Jennifer sherman
Jennifer sherman
September 15, 2026 5 Min Read
2 0

Key Takeaways

  • Sophisticated phishing campaigns are leveraging trusted email infrastructure and advanced URL cloaking techniques to bypass conventional security defenses.
  • Attackers are sending seemingly legitimate emails, such as account alerts or invoices, from authenticated domains, making them difficult for automated filters to detect.
  • The attacks utilize multi-stage redirect chains, browser fingerprinting, and dynamic content delivery to present benign content to security scanners while delivering malicious payloads or phishing pages to human users.
  • The primary goals of these campaigns include credential theft, payment fraud, and cryptocurrency/NFT fraud, rather than direct malware delivery.
  • Defenders must adopt advanced detection methods that analyze the entire click path and post-load behavior of URLs, rather than relying solely on initial email checks.

A new wave of phishing attacks is circumventing traditional email security measures by originating from trusted email systems and employing sophisticated URL cloaking. Instead of relying on obviously malicious sender addresses, these campaigns mimic legitimate communications, such as account notifications, invoices, and renewal reminders, to lure victims into web-based traps.

Table Of Content

  • Key Takeaways
  • New Phishing Attacks Use Trusted Email Infrastructure
  • Why Familiar Lures Still Work
  • What You Should Do

This evolving strategy shifts the point of compromise into a dynamic click path that can adapt in real-time. An email might successfully pass authentication checks and contain no malicious attachments, yet it can still guide a recipient through a series of redirects, browser fingerprinting, and deceptive landing pages designed to harvest sensitive information.

During its Q3 2026 testing period, researchers identified phishing samples utilizing this model. These campaigns cleverly combined familiar social engineering themes with infrastructure specifically designed to conceal the ultimate malicious destination from automated security checks. The findings are detailed in a report shared with Cyber Security News (CSN) by Virus Bulletin, which highlights the critical challenge these attacks pose to existing security paradigms.

The implications of these tactics extend beyond a single deceptive email. A fraudulent antivirus renewal notification might aim to steal payment card details, an overdue invoice could steer a victim toward cryptocurrency-related scams, and a fake banking alert could target login credentials. As Virus Bulletin said in a report, each of these scenarios leverages a believable prompt and a destination that can exhibit different behaviors when accessed by security scanners versus a human user.

New Phishing Attacks Use Trusted Email Infrastructure

An incident observed in August involved a German-language email concerning an overdue payment, urging recipients to open a “Mahnschreiben” (payment reminder). This message was delivered via Amazon Simple Email Service (SES) from a domain with a valid DKIM signature, leading many email filters to classify it as legitimate.

Antivirus renewal phishing sample (Source - Virus Bulletin)
Antivirus renewal phishing sample (Source – Virus Bulletin)

Notably, the email contained no attachment for security systems to inspect. Instead, the embedded link led to a page featuring decoy content, hidden text, a minuscule iframe, and obfuscated code. This page meticulously collected browser and time-zone data from the user. Following this, it initiated a hidden request before redirecting to OpenSea during analysis, indicating a cloaked path toward cryptocurrency or NFT fraud rather than the delivery of malware.

This attack vector underscores why leveraging trusted cloud services is so effective for phishing. The email delivery platform itself can be legitimate, the sending domain can pass authentication checks, and the initial landing page might appear harmless when examined outside the specific browser, geographical location, or time intended by the attacker. This sophisticated cloaking mechanism allows malicious content to remain hidden until the precise conditions for the target are met.

Another campaign, written in Romanian, mimicked the branding of BCR S.A. and falsely claimed that a PSD2 consent renewal was necessary to prevent banking access restrictions. This email, while DKIM-aligned, originated from an unrelated sender domain. The embedded link utilized an IPv6-mapped address, a format that complicates automated assessment of the destination. During verification, this link resolved through an additional redirect before eventually landing on Google, further obscuring its true purpose.

Invoice phishing sample redirecting to OpenSea (Source - Virus Bulletin)
Invoice phishing sample redirecting to OpenSea (Source – Virus Bulletin)

Researchers concluded that this operation aimed for credential theft. They noted that the active phishing page might have expired, been cloaked, or been configured to display benign content selectively. This inherent uncertainty renders simple reputation lookups and one-time scans significantly less effective against such adaptive threats.

Why Familiar Lures Still Work

These phishing campaigns do not necessitate novel malware to achieve their objectives. They effectively exploit universal human anxieties: an infected device, an outstanding bill, restricted banking access, or an expiring subscription. For instance, a Dutch-language renewal email falsely warned of “631 dangerous viruses,” threatened account closure, and offered a discount to pressure victims into a hasty decision.

These messages capitalize on a fundamental disconnect between technical email authentication and human trust. While passing SPF, DKIM, or DMARC verifies that an email originated from an authorized domain, it offers no guarantee regarding the legitimacy of the underlying business request. The Amazon SES phishing example demonstrates this perfectly, where technically authenticated mail was weaponized to bypass reputation-based blocking mechanisms.

What You Should Do

  • Verify Independently: Never click on links in unexpected emails for invoices, renewal notices, or banking updates, even if the sender appears legitimate. Instead, navigate directly to the service’s official website by typing its known address or using a saved application.
  • Confirm Alerts In-Account: If an email alerts you to an issue, log into your account directly through official channels to verify the notification. This prevents engagement with malicious redirect chains.
  • Enable Multi-Factor Authentication (MFA): Implement MFA on all critical accounts to add an essential layer of security, making it significantly harder for attackers to compromise accounts even if they obtain credentials.
  • Advanced Email Gateway Configuration: Security teams should configure email gateways to inspect the *entire* click path, including redirects, unusual IP-based links, browser fingerprinting attempts, and post-load behavior. Relying solely on initial URL checks is insufficient.
  • Employee Training and Awareness: Regularly educate staff on the latest phishing tactics, emphasizing the dangers of urgent requests and the importance of verifying sender legitimacy and link authenticity independently.
  • Threat Hunting: Actively hunt for indicators of compromise (IoCs) related to these advanced phishing techniques. Review messages that mimic payment, banking, or renewal workflows for suspicious elements.

Indicators of compromise (IoCs):-

Type Indicator Description
Hostname 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net Redirect infrastructure used in the antivirus renewal scareware phishing flow
Domain loadswage[.]com Redirect infrastructure associated with the antivirus renewal phishing sample
Domain eightindigostove[.]com Domain hosting the unsubscribe path in the antivirus renewal phishing sample
Sender domain moolaah[.]com DKIM-aligned sender domain used for the cloaked overdue-payment invoice lure
URL website-2df62808[.]mvplineup[.]com/audacity/underside First-stage cloaking page used in the invoice phishing redirect chain
Domain opensea[.]io Final destination reached after the cloaking and browser-fingerprinting stage
Sender domain xmasbrick[.]com DKIM-aligned but unrelated sender domain used in the Romanian banking phishing email
URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the banking phishing message
IPv4 address 103[.]193[.]179[.]223 IPv4 address represented by the IPv6-mapped URL notation
URL web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ Redirect destination in the Romanian PSD2 banking phishing chain

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwarephishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Google Search Update Hides URLs, Increases Phishing Risk

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP With $159 DDR5 Device
September 15, 2026
Critical Gitea RCE Vulnerability Under Active Exploitation
September 15, 2026
Critical Marimo RCE (CVE-2024-XXXX) Lets Attackers Steal AWS Credentials
September 15, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us