Malicious Link
Emails contain hyperlinks designed to trick victims into visiting credential-harvesting sites, downloading malware, or engaging with fraudulent content. These links may be disguised using text-based deception (e.g., misleading anchor text), obfuscation techniques, or URL redirection.
Mapped to
MITRE ATT&CK®
Sub-techniques
TE0006.1
Open Redirect
Attackers exploit legitimate websites to route victims through trusted domains (e.g., google.com, sendgrid.net or youtube.com) before landing them on a phishing site. The redirect is visible in the email link as a redirect parameter in the URL (e.g., ?q=, ?url= or ?redirect=). This technique reduces suspicion and bypasses some security filters.
TE0006.2
URL Shortener
Attackers use third-party URL shortening services (e.g., bit.ly, tinyurl.com) to hide the actual URL. These services convert full URLs into short aliases. This technique intentionally hides the actual link, making it harder for users to assess the legitimacy of the link before clicking.
Connected in PH!SH
Themes
TH0001Media Service Impersonation
TH0002Email Service Impersonation
TH0003Crypto-Related Service Impersonation
TH0004Travel Service Impersonation
TH0005Document Sharing Service Impersonation
TH0006Postal Service Impersonation
TH0008Social Media Service Impersonation
TH0013Advance Fee Scams
TH0014Commercial Deception
TH0018Data Exploitation and Illicit Sales
TH0019Voicemail Phishing
TH0020Fax Phishing
TH0021Survey Phishing
TH0025Website/Domain Hosting Service Impersonation
TH0027Telecommunications Company Impersonation
TH0028Benefit Service Impersonation
TH0029Collaboration Platform Impersonation
TH0030Energy Industry Impersonation
TH0031Apple Impersonation
TH0032Google Impersonation
TH0033Full Storage
TH0034Expiring Password
TH0036Account Deletion
TH0037Suspicious Login
TH0038Security Update
TH0039Update Information
TH0041Secure Message
TH0042Event Phishing
TH0045Account Authentication
TH0047Delivery Failure
TH0048Health Service Impersonation