Inside Multi-Stage Phishing Redirection Chains
Recent investigations have uncovered sophisticated phishing campaigns employing multi-stage redirection chains that abuse trusted cloud infrastructure and newly registered domains. One campaign exploits Framer, a no-code web platform, combined with Cloudflare Workers to host deceptive landing pages. These pages utilize HTML redirection smuggling via the Blob API, Web Crypto API for decryption, and anti-debugging techniques to evade detection. Another campaign involves device code phishing targeting OneDrive credentials through three-stage redirections using newly registered domains with randomized alphanumeric strings. Both campaigns employ brand impersonation, custom CAPTCHA challenges, and anti-analysis measures including keyboard shortcut blocking. The threat actors leverage a hybrid infrastructure combining legitimate cloud services with short-lived domains to bypass traditional detection methods.
AI Analysis
Technical Summary
Investigations have uncovered phishing campaigns using multi-stage redirection chains that abuse trusted cloud platforms and newly registered domains. One campaign abuses Framer, a no-code web platform, combined with Cloudflare Workers to host deceptive landing pages that utilize HTML redirection smuggling via the Blob API, Web Crypto API for decryption, and anti-debugging techniques to evade detection. Another campaign targets OneDrive credentials through device code phishing involving three-stage redirections with randomized alphanumeric newly registered domains. Both campaigns employ brand impersonation, custom CAPTCHA challenges, and anti-analysis techniques such as keyboard shortcut blocking. The threat actors leverage a hybrid infrastructure combining legitimate cloud services with short-lived domains to bypass traditional detection methods.
Potential Impact
The campaigns aim to steal credentials, including OneDrive credentials, by deceiving users through complex redirection chains and evasion techniques. The use of trusted cloud infrastructure and short-lived domains complicates detection and mitigation by security tools. The anti-analysis and anti-debugging measures increase the difficulty of identifying and blocking these phishing attempts, potentially leading to successful credential theft and subsequent unauthorized access.
Mitigation Recommendations
No official patches or fixes apply as this is a phishing campaign rather than a software vulnerability. Defenders should update email and web filtering rules to detect and block the identified domains and URLs associated with these campaigns. Awareness training for users about multi-stage phishing and brand impersonation tactics is recommended. Monitoring for the listed domains and URLs can help in early detection. Since the campaigns use short-lived domains and cloud services, continuous threat intelligence updates are essential. There is no vendor advisory indicating these threats are already mitigated or require no action.
Indicators of Compromise
- domain: 2934523t5234535323973294afhdsfga.com
- url: https://bl.dase7.shop/7tr22673862r7436r20348r6243078r627784608263652874635743209043652603485264350263478023352026/3933453326jkjdsbvfvvkzfadfxv.html.html
- url: https://alasilla.com/frontdeskformationdocusignpaywet/zTlHo9aEUKYakbJYawRlffu6C2imV2To1eOp
- url: http://2934523t5234535323973294afhdsfga.com
- url: https://bl.dase7.shop/7tr22673862r7436r20348r6243078r627784608263652874635743209043652603485264350263478023352026/3933453326jkjdsbvfvvkzfadfxv.html.html”
- domain: alasilla.com
- domain: bl.dase7.shop
Inside Multi-Stage Phishing Redirection Chains
Description
Recent investigations have uncovered sophisticated phishing campaigns employing multi-stage redirection chains that abuse trusted cloud infrastructure and newly registered domains. One campaign exploits Framer, a no-code web platform, combined with Cloudflare Workers to host deceptive landing pages. These pages utilize HTML redirection smuggling via the Blob API, Web Crypto API for decryption, and anti-debugging techniques to evade detection. Another campaign involves device code phishing targeting OneDrive credentials through three-stage redirections using newly registered domains with randomized alphanumeric strings. Both campaigns employ brand impersonation, custom CAPTCHA challenges, and anti-analysis measures including keyboard shortcut blocking. The threat actors leverage a hybrid infrastructure combining legitimate cloud services with short-lived domains to bypass traditional detection methods.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Investigations have uncovered phishing campaigns using multi-stage redirection chains that abuse trusted cloud platforms and newly registered domains. One campaign abuses Framer, a no-code web platform, combined with Cloudflare Workers to host deceptive landing pages that utilize HTML redirection smuggling via the Blob API, Web Crypto API for decryption, and anti-debugging techniques to evade detection. Another campaign targets OneDrive credentials through device code phishing involving three-stage redirections with randomized alphanumeric newly registered domains. Both campaigns employ brand impersonation, custom CAPTCHA challenges, and anti-analysis techniques such as keyboard shortcut blocking. The threat actors leverage a hybrid infrastructure combining legitimate cloud services with short-lived domains to bypass traditional detection methods.
Potential Impact
The campaigns aim to steal credentials, including OneDrive credentials, by deceiving users through complex redirection chains and evasion techniques. The use of trusted cloud infrastructure and short-lived domains complicates detection and mitigation by security tools. The anti-analysis and anti-debugging measures increase the difficulty of identifying and blocking these phishing attempts, potentially leading to successful credential theft and subsequent unauthorized access.
Defensive Guidance
No official patches or fixes apply as this is a phishing campaign rather than a software vulnerability. Defenders should update email and web filtering rules to detect and block the identified domains and URLs associated with these campaigns. Awareness training for users about multi-stage phishing and brand impersonation tactics is recommended. Monitoring for the listed domains and URLs can help in early detection. Since the campaigns use short-lived domains and cloud services, continuous threat intelligence updates are essential. There is no vendor advisory indicating these threats are already mitigated or require no action.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.levelblue.com/blogs/spiderlabs-blog/the-infrastructure-relay-inside-multi-stage-phishing-redirection-chains"]
- Adversary
- null
- Pulse Id
- 6a7ce26b7815e336e5eee192
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domain2934523t5234535323973294afhdsfga.com | — | |
domainalasilla.com | — | |
domainbl.dase7.shop | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://bl.dase7.shop/7tr22673862r7436r20348r6243078r627784608263652874635743209043652603485264350263478023352026/3933453326jkjdsbvfvvkzfadfxv.html.html | — | |
urlhttps://alasilla.com/frontdeskformationdocusignpaywet/zTlHo9aEUKYakbJYawRlffu6C2imV2To1eOp | — | |
urlhttp://2934523t5234535323973294afhdsfga.com | — | |
urlhttps://bl.dase7.shop/7tr22673862r7436r20348r6243078r627784608263652874635743209043652603485264350263478023352026/3933453326jkjdsbvfvvkzfadfxv.html.html” | — |
Threat ID: 6a7d94c7bf8831d53902197b
Added to database: 08/13/2026, 09:56:23 UTC
Last enriched: 08/13/2026, 10:17:26 UTC
Last updated: 08/14/2026, 01:07:22 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.