Tactic or Technique: Open redirect

Attackers abuse open redirect vulnerabilities to make malicious links appear trustworthy. These links begin with a legitimate domain, but when clicked, they send you to a completely different site—often one used for phishing or malware delivery.
It often begins with a link like “trusted-company[.]com/redirect?url=malicious-site[.]com” to bypass filters and build false confidence. Since the domain looks familiar, you’re more likely to trust it and click through. Behind the scenes, you’re immediately redirected to an attacker-controlled page.
This tactic works because many users and security tools only check the start of a URL. It’s frequently used in credential phishing and malware campaigns, especially when combined with realistic branding that makes the message feel like it came from a legitimate source.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Open redirect: Quickbase
10m ago
Oct 6th, 2026
Sublime Security
Service abuse: Lovable-hosted redirect to external phishing page
6h ago
Oct 6th, 2026
Sublime Security
Open redirect: Toradex
1d ago
Oct 5th, 2026
Sublime Security
Open redirect: EWeb logout redirect
4d ago
Oct 2nd, 2026
Sublime Security
Attachment: PDF credential phishing via wkhtmltopdf/Qt with suspicious link
5d ago
Oct 1st, 2026
Sublime Security
Link: Compromised WordPress site redirecting to suspicious root domain
7d ago
Sep 29th, 2026
Sublime Security
Link: Google share.google URL shortener in google.<tld>/share.google path form
8d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS calendar invite with Google share.google URL shortener in google.<tld>/share.google path form
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Google share.google URL shortener in google.<tld>/share.google path form
8d ago
Sep 28th, 2026
Sublime Security
Attachment: ICS invite meeting lure
8d ago
Sep 28th, 2026
Sublime Security
Attachment: Calendar invite with suspicious link leading to an open redirect
8d ago
Sep 28th, 2026
Sublime Security
Link: Google Calendar invite linking to an open redirect from an untrusted freemail sender
8d ago
Sep 28th, 2026
Sublime Security
Open redirect: pmifunds.com
13d ago
Sep 23rd, 2026
Sublime Security
Open redirect: fenc.com
13d ago
Sep 23rd, 2026
Sublime Security
Open redirect: g7.fr
13d ago
Sep 23rd, 2026
Sublime Security
Open redirect: ijf.org
13d ago
Sep 23rd, 2026
Sublime Security
Open redirect: Indeed
13d ago
Sep 23rd, 2026
Sublime Security
Open redirect: IndiaTimes
13d ago
Sep 23rd, 2026
Sublime Security
Open redirect: isadatalab.com
13d ago
Sep 23rd, 2026
Sublime Security
Open redirect: labcluster.com
13d ago
Sep 23rd, 2026
Sublime Security