Tactic or Technique: IPFS

Attackers use IPFS, the InterPlanetary File System, to host phishing pages, malware, and other malicious content in a way that’s difficult to take down. Unlike traditional hosting, IPFS is decentralized, so content is distributed across many nodes instead of sitting on a single server.
A phishing email may include a link that appears to lead to a legitimate website but actually points to an IPFS gateway. Blocking one gateway isn’t enough—the content stays live as long as it’s being shared, and can be accessed through any public node. Each file has a unique identifier, making it easy for attackers to keep it online and hard for defenders to remove.
This tactic gives attackers persistence and reach. Security tools that rely on domain reputation or blocklists often miss these links, creating longer exposure windows for malware delivery or credential theft.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: EML file with IPFS links
8d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/attachment-eml-file-with-ipfs-links-1fe9d7e7
Vendor compromise: GovDelivery message with suspicious link
3mo ago
Aug 5th, 2025
Sublime Security
/feeds/core/detection-rules/vendor-compromise-govdelivery-message-with-suspicious-link-0d2d5172
Link: IPFS
3mo ago
Jul 16th, 2025
Sublime Security
/feeds/core/detection-rules/link-ipfs-19fa6442
Credential phishing: Engaging language with IPFS link
1y ago
May 3rd, 2024
Sublime Security
/feeds/core/detection-rules/credential-phishing-engaging-language-with-ipfs-link-996c4d83