Tactic or Technique: Open redirect

Attackers abuse open redirect vulnerabilities to make malicious links appear trustworthy. These links begin with a legitimate domain, but when clicked, they send you to a completely different site—often one used for phishing or malware delivery.
It often begins with a link like “trusted-company[.]com/redirect?url=malicious-site[.]com” to bypass filters and build false confidence. Since the domain looks familiar, you’re more likely to trust it and click through. Behind the scenes, you’re immediately redirected to an attacker-controlled page.
This tactic works because many users and security tools only check the start of a URL. It’s frequently used in credential phishing and malware campaigns, especially when combined with realistic branding that makes the message feel like it came from a legitimate source.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Service abuse: Google OAuth with suspicious redirect destination
18d ago
Mar 12th, 2026
Sublime Security
Link: Commonly Abused Web Service redirecting to ZIP file
20d ago
Mar 10th, 2026
Sublime Security
Link: Multistage landing - ClickUp abuse
1mo ago
Feb 27th, 2026
Sublime Security
Link: URL redirecting to blob URL
1mo ago
Feb 24th, 2026
Sublime Security
Open redirect: embluemail.com
1mo ago
Feb 12th, 2026
Sublime Security
Attachment: QR code with encoded recipient targeting and redirect indicators
1mo ago
Jan 30th, 2026
Sublime Security
Open redirect: designsori.com
2mo ago
Jan 12th, 2026
Sublime Security
Open redirect: pmifunds.com
2mo ago
Jan 12th, 2026
Sublime Security
Open redirect: easycamp.com
2mo ago
Jan 12th, 2026
Sublime Security
Open redirect: vconfex.com
2mo ago
Jan 12th, 2026
Sublime Security
Open redirect: VK
2mo ago
Jan 12th, 2026
@vector_sec
Open redirect: amaterasu-for-website-5.com
2mo ago
Jan 12th, 2026
Sublime Security
Open redirect: whitefox.pl
2mo ago
Jan 12th, 2026
Sublime Security
Open redirect: YouTube --> Google Redirection Chain
2mo ago
Jan 12th, 2026
Sublime Security
Open redirect: Cartoon Network
2mo ago
Jan 12th, 2026
Sublime Security
Open redirect: xfinity.com
2mo ago
Jan 12th, 2026
Sublime Security
Open redirect: storematch.jp
2mo ago
Jan 12th, 2026
Sublime Security
Low reputation link to auto-downloaded HTML file with smuggling indicators
2mo ago
Jan 12th, 2026
Sublime Security
Open redirect: agena-smile.com
2mo ago
Jan 12th, 2026
Sublime Security
Open redirect: astroarts.co.jp
2mo ago
Jan 12th, 2026
Sublime Security