216.73.217.22

Phishing Pages Delivered Through Refresh HTTP Response Header

· Published 18/09/2024 08:35 · Modified 18/09/2024 09:00

Export JSON

Essential information

Published
18/09/2024 08:35
Modified
18/09/2024 09:00
Tags
2024-09-18 business email compromise credential-theft http header phishing
Related entities
7 observables, 6 techniques (mitre), 7 others

Description

Unit 42 researchers observed large-scale campaigns in 2024 using a refresh entry in the HTTP response header. This technique, unlike traditional HTML-based , occurs before HTML content processing and automatically refreshes webpages without user interaction. Attackers distribute malicious URLs via emails, targeting global financial sector, internet portals, and government domains. The attacks use personalized approaches, embedding recipients' email addresses and displaying spoofed webmail login pages. From May to July, around 2,000 malicious URLs were detected daily. The campaigns predominantly targeted the business-and-economy sector, financial services, and government institutions. This sophisticated method makes it difficult to identify malicious indicators within URL strings and increases the likelihood of successful credential theft.

External references