Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Inside Multi-Stage Phishing Redirection Chains

0
Medium
Published: 08/12/2026 (08/12/2026, 21:15:23 UTC)
Source: AlienVault OTX General

Description

Recent investigations have uncovered sophisticated phishing campaigns employing multi-stage redirection chains that abuse trusted cloud infrastructure and newly registered domains. One campaign exploits Framer, a no-code web platform, combined with Cloudflare Workers to host deceptive landing pages. These pages utilize HTML redirection smuggling via the Blob API, Web Crypto API for decryption, and anti-debugging techniques to evade detection. Another campaign involves device code phishing targeting OneDrive credentials through three-stage redirections using newly registered domains with randomized alphanumeric strings. Both campaigns employ brand impersonation, custom CAPTCHA challenges, and anti-analysis measures including keyboard shortcut blocking. The threat actors leverage a hybrid infrastructure combining legitimate cloud services with short-lived domains to bypass traditional detection methods.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 10:17:26 UTC

Technical Analysis

Investigations have uncovered phishing campaigns using multi-stage redirection chains that abuse trusted cloud platforms and newly registered domains. One campaign abuses Framer, a no-code web platform, combined with Cloudflare Workers to host deceptive landing pages that utilize HTML redirection smuggling via the Blob API, Web Crypto API for decryption, and anti-debugging techniques to evade detection. Another campaign targets OneDrive credentials through device code phishing involving three-stage redirections with randomized alphanumeric newly registered domains. Both campaigns employ brand impersonation, custom CAPTCHA challenges, and anti-analysis techniques such as keyboard shortcut blocking. The threat actors leverage a hybrid infrastructure combining legitimate cloud services with short-lived domains to bypass traditional detection methods.

Potential Impact

The campaigns aim to steal credentials, including OneDrive credentials, by deceiving users through complex redirection chains and evasion techniques. The use of trusted cloud infrastructure and short-lived domains complicates detection and mitigation by security tools. The anti-analysis and anti-debugging measures increase the difficulty of identifying and blocking these phishing attempts, potentially leading to successful credential theft and subsequent unauthorized access.

Defensive Guidance

No official patches or fixes apply as this is a phishing campaign rather than a software vulnerability. Defenders should update email and web filtering rules to detect and block the identified domains and URLs associated with these campaigns. Awareness training for users about multi-stage phishing and brand impersonation tactics is recommended. Monitoring for the listed domains and URLs can help in early detection. Since the campaigns use short-lived domains and cloud services, continuous threat intelligence updates are essential. There is no vendor advisory indicating these threats are already mitigated or require no action.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.levelblue.com/blogs/spiderlabs-blog/the-infrastructure-relay-inside-multi-stage-phishing-redirection-chains"]
Adversary
null
Pulse Id
6a7ce26b7815e336e5eee192
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domain2934523t5234535323973294afhdsfga.com
domainalasilla.com
domainbl.dase7.shop

Url

ValueDescriptionCopy
urlhttps://bl.dase7.shop/7tr22673862r7436r20348r6243078r627784608263652874635743209043652603485264350263478023352026/3933453326jkjdsbvfvvkzfadfxv.html.html
urlhttps://alasilla.com/frontdeskformationdocusignpaywet/zTlHo9aEUKYakbJYawRlffu6C2imV2To1eOp
urlhttp://2934523t5234535323973294afhdsfga.com
urlhttps://bl.dase7.shop/7tr22673862r7436r20348r6243078r627784608263652874635743209043652603485264350263478023352026/3933453326jkjdsbvfvvkzfadfxv.html.html”

Threat ID: 6a7d94c7bf8831d53902197b

Added to database: 08/13/2026, 09:56:23 UTC

Last enriched: 08/13/2026, 10:17:26 UTC

Last updated: 08/14/2026, 01:07:22 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses