Hackers Exploit Email Marketing Platforms to Deliver Hidden Malware
## Cybersecurity: Phishing Campaigns Leveraging Email Marketing Platforms
Cybersecurity: Phishing Campaigns Leveraging Email Marketing Platforms
Recently, Trustwave SpiderLabs, a LevelBlue company, has identified an increase in phishing campaigns utilizing legitimate email marketing platforms to conceal malicious links. Attackers exploit established infrastructure and URL redirectors to bypass traditional defenses and deceive recipients into providing sensitive information.
Trustwave's PageML system employs a combination of machine learning, deep learning, and rules-based frameworks to analyze URLs and webpage content in real-time, determining if a destination is malicious. Despite its advanced capabilities, recent phishing campaigns have tested PageML's limits by hiding behind trusted domains and employing multiple redirections.
Email Marketing Platforms as Phishing Vectors
Phishing campaigns have been observed exploiting Klaviyo's click-tracking domain, klclick3.com . Attackers craft phishing emails with links starting with https://ctrk.klclick3.com , masked as voicemail notifications. These links redirect to a phishing page that dynamically fetches the victim’s company logo and disables right-click functionality to prevent analysis.
Phishing emails impersonating DocuSign utilize Drip Global’s tracking domain dripemail2.com . These links redirect to a fake Microsoft Security page with embedded Base64-encoded parameters, leading to credential-harvesting login forms. Trustwave's scanning uniquely detected these malicious redirects early on.
Phishing campaigns have been observed exploiting Klaviyo's click-tracking domain, klclick3.com .
Attackers are also using cloud hosting services to serve phishing pages. Malicious emails posing as payment remittances include links to *.s3.us-east-1.amazonaws.com , mimicking Roundcube Webmail login forms with embedded Cloudflare Turnstile challenges.
Compromised Domains Combined with CAPTCHA
Legitimate corporate domains are being compromised. For example, airswift.ae was found hosting a "Secure Document" phishing page, which uses a Cloudflare CAPTCHA and redirects to a fake Microsoft sign-in page.
Use of Trusted Platforms: Attackers utilize email-marketing and cloud-hosting services to leverage domains with solid reputations. Multi-stage Redirections: Layered URL redirects obfuscate final destinations. Dynamic Content Injection: Scripts customize phishing pages with victim-specific details. CAPTCHA Evasion: Human-verification steps using services like Cloudflare Turnstile delay automated scanning.
Advanced URL Analysis: Implement real-time URL-scanning systems like PageML. Email Platform Monitoring: Track outbound links using third-party domains with strict allow-lists. User Awareness Training: Educate employees on phishing lures mimicking familiar services. Cloud Service Scrutiny: Monitor traffic to cloud-hosting endpoints for unusual patterns.
Organizations must adapt continuously as phishing campaigns evolve, combining traditional tactics with new methods of evasion. Trustwave SpiderLabs remains focused on enhancing detection capabilities and sharing actionable intelligence to counter these threats.
Based on reporting by GBHackers.
