Tactic or Technique: Open redirect

Attackers abuse open redirect vulnerabilities to make malicious links appear trustworthy. These links begin with a legitimate domain, but when clicked, they send you to a completely different site—often one used for phishing or malware delivery.
It often begins with a link like “trusted-company[.]com/redirect?url=malicious-site[.]com” to bypass filters and build false confidence. Since the domain looks familiar, you’re more likely to trust it and click through. Behind the scenes, you’re immediately redirected to an attacker-controlled page.
This tactic works because many users and security tools only check the start of a URL. It’s frequently used in credential phishing and malware campaigns, especially when combined with realistic branding that makes the message feel like it came from a legitimate source.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: ICS invite meeting lure
1h ago
Aug 27th, 2026
Sublime Security
Link: Google Cloud Storage link with redirect.html in URL
3d ago
Aug 24th, 2026
Sublime Security
Evasion: Suspicious TLD link redirecting to Wikipedia
6d ago
Aug 21st, 2026
Sublime Security
Link: Credential phishing with obfuscated JavaScript redirect
6d ago
Aug 21st, 2026
Sublime Security
Link: .su domain link redirection from new sender domains
14d ago
Aug 13th, 2026
Sublime Security
Link: Observed malicious URL path /redirect/redirect/
15d ago
Aug 12th, 2026
Sublime Security
Link: URL shortener chaining to workers.dev redirect
17d ago
Aug 10th, 2026
Sublime Security
Low reputation link to auto-downloaded HTML file with smuggling indicators
29d ago
Jul 29th, 2026
Sublime Security
Link: Compromised WordPress site redirecting to suspicious root domain
1mo ago
Jul 27th, 2026
Sublime Security
Open redirect: Shibboleth SSO Logout Return Parameter
1mo ago
Jul 27th, 2026
Sublime Security
Open redirect: Recipient address embedded in redirect URL pointing to newly registered domain
1mo ago
Jul 24th, 2026
Sublime Security
Open redirect: Diesel.az
1mo ago
Jul 14th, 2026
Sublime Security
Open redirect: JustPaste.it
1mo ago
Jul 2nd, 2026
Sublime Security
Link: Google Cloud Storage link with index.php in URL
1mo ago
Jun 30th, 2026
Sublime Security
Link: Google Cloud Storage redirect to external domain
1mo ago
Jun 30th, 2026
Sublime Security
Brand impersonation: Microsoft logo or suspicious language with open redirect
2mo ago
Jun 5th, 2026
Sublime Security
Open Redirect: Google domain with /url path and suspicious indicators
2mo ago
Jun 5th, 2026
Sublime Security
Constant Contact link infrastructure abuse
2mo ago
Jun 5th, 2026
Sublime Security
Open redirect: Mailtrack Korea
2mo ago
Jun 4th, 2026
Sublime Security
Open redirect: Hakumonkai.org
2mo ago
Jun 1st, 2026
Sublime Security