Hackers caught abusing URL security tools to hide phishing links

Cybersecurity researchers recently discovered that hackers are abusing URL security tools to send phishing links to unsuspecting victims. “Hundreds of companies, if not more,” have been targeted.

When someone receives an email with a link, the tool copies and rewrites it, then embeds it in a new, rewritten link. So as soon as the recipient clicks on that link, a security scan is performed. In this new campaign, which is expected to start in mid-May 2024, the rewritten link led recipients to a phishing site.