Open url redirect on Snapchat being abused in phishing campaigns. Still working.

Live working example: https://click.snapchat.com/aVHG?&af_web_dp=http://old.reddit.com/r/hacking/wiki

Attackers abused open redirects on the websites of Snapchat and American Express in a series of phishing attacks to steal Microsoft 365 credentials.

Open redirects are web app weaknesses that allow threat actors to use the domains of trusted organizations and websites as temporary landing pages to simplify phishing attacks.

They're used in attacks to redirect targets to malicious sites that will either infect them with malware or trick them into handing over sensitive information (e.g., credentials, financial info, personal info).

"Since the first domain name in the manipulated link is in fact the original site's, the link may appear safe to the casual observer," email security firm Inky, which observed the attacks, explained.

"The trusted domain (e.g., American Express, Snapchat) acts as a temporary landing page before the surfer is redirected to a malicious site."

Read more: https://www.bleepingcomputer.com/news/security/snapchat-amex-sites-abused-in-microsoft-365-phishing-attacks/

submitted by /u/DrinkMoreCodeMore
[link] [comments]

from hacking: security in practice https://ift.tt/N28egqH

Comments