Listen to this Post

A Dangerous New Twist in Phishing Campaigns
Cybercriminals have found a cunning new method to bypass traditional email security. By exploiting the very systems designed to protect users, a threat actor has successfully abused link-wrapping services from reputable tech companies to mask phishing URLs and trick users into giving away their Microsoft 365 login credentials. Between June and July 2025, these attackers weaponized the trusted names of cybersecurity giants like Proofpoint and Intermedia, slipping through defenses under the guise of legitimacy. This development not only highlights a dangerous vulnerability in existing email protection infrastructure but also signals an evolution in phishing sophistication that should put enterprises on high alert.
How Hackers Used Link Wrapping to Launch Stealthy Phishing Campaigns
Security researchers from Cloudflare’s Email Security team recently uncovered a phishing campaign where attackers disguised malicious URLs behind trusted link-wrapping services. These services—used by companies like Proofpoint and Intermedia—typically rewrite URLs to a secure format and scan them for threats. However, hackers exploited this very feature by compromising email accounts protected by these services.
Once inside, the attackers sent phishing emails that mimicked voicemail alerts or shared Microsoft Teams notifications. The links appeared legitimate because they were passed through Proofpoint or Intermedia’s link wrapping system. In some cases, hackers added another layer of deception by shortening the malicious URLs before sending them through the compromised email accounts, making the final links nearly impossible to identify as threats.
Victims who clicked the wrapped and shortened links were redirected through multiple layers before landing on phishing pages designed to look like Microsoft Office 365 login portals. These pages captured the user’s credentials and transmitted them directly to the attackers.
The campaign abusing Intermedia’s service was particularly deceptive. Emails appeared as secure messages from “Zix” or as fake Teams alerts about new messages. These used Constant Contact—a legitimate marketing platform—as the final redirect host, making the phishing destination seem even more trustworthy.
By leveraging link-wrapping security features from respected cybersecurity providers, the attackers increased their chances of bypassing detection tools and user skepticism. This approach of “laundering” phishing links through legitimate platforms is not new, but exploiting link-wrapping technology marks an alarming evolution in phishing tactics.
What Undercode Say:
Exploiting Trust: The New Currency of Cybercrime
One of the most insidious aspects of this attack lies in its exploitation of user trust. Link-wrapping services are designed to enhance security by scanning for malicious destinations. But when these same services are compromised, they become a weapon. Users are trained to trust URLs from known domains like Proofpoint or Intermedia. By embedding phishing links within those wrappers, attackers short-circuit skepticism and increase click-through rates.
A Strategic Multi-Layered Deception
The strategy here isn’t just technical—it’s psychological. The attackers relied on social engineering, combining fake voicemails, Microsoft Teams messages, and secure document alerts to pique curiosity and urgency. Adding layers of URL shortening and redirection helps avoid detection from both users and automated scanners. Every detail was designed to mimic legitimate workflows, from the email subject lines to the interface of the final phishing pages.
Why Traditional Defenses Are Falling Short
Most email security tools are configured to trust link wrappers from reputable vendors. That’s what makes this tactic so dangerous—it turns a safety mechanism into a liability. Moreover, because the initial emails came from previously trusted accounts, these messages often bypassed spam filters altogether. It’s a textbook example of how trust can be weaponized in modern cyberwarfare.
Implications for Enterprise Security
This isn’t just a technical flaw. It’s a structural vulnerability in how organizations implement email security. The fact that attackers can compromise a few email accounts and then use them as a distribution base for “legitimized” phishing links shows how fragile perimeter-based defenses really are. This kind of campaign could easily spread through a large organization before being detected, especially if the phishing emails are crafted well enough to appear authentic.
Link Wrapping: From Safety Net to Attack Vector
Link wrapping used to be a reliable layer of defense. But with this shift, it’s now a potential attack vector. Enterprises must rethink how they handle trusted domains and review their reliance on automated scanning. More advanced behavioral analytics and context-aware filtering might be necessary to catch these stealthy campaigns.
The Role of Third-Party Platforms
Using Constant Contact as a redirect host is another clever move. Marketing platforms often have a good reputation score, so they are less likely to be flagged by security tools. This shows that attackers are now blending infrastructure from multiple legitimate services to create complex attack chains. It’s no longer enough to block suspicious domains—security solutions need to analyze behavior, context, and intent.
What Can Be Done?
Mitigation won’t be easy. Enterprises should start by disabling link-clicking automation where possible, enabling strict DMARC policies, and enforcing multi-factor authentication (MFA) to reduce the impact of stolen credentials. Additionally, security awareness training must evolve to include education about seemingly “safe” URLs.
The Bigger Picture
This campaign is a warning sign. As phishing tactics evolve, attackers are finding ways to manipulate the very tools meant to protect us. It’s no longer about detecting fake links—it’s about understanding the entire ecosystem and how each part can be misused. Cybersecurity needs to shift from static defenses to dynamic, intelligence-driven models.
🔍 Fact Checker Results:
✅ Attackers used Proofpoint and Intermedia’s link-wrapping services to hide phishing URLs
✅ Compromised legitimate email accounts were used to distribute these emails
✅ Cloudflare confirmed Microsoft 365 credentials were the target of the phishing pages
📊 Prediction:
Expect to see more phishing attacks that abuse trusted security infrastructure rather than relying on spoofed domains. Future campaigns may integrate AI to generate even more convincing fake notifications and escalate credential theft at scale. The next frontier will be phishing links that not only look real but evolve dynamically to bypass real-time security filters. 🚨
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: www.bleepingcomputer.com
Extra Source Hub:
https://www.linkedin.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




