Mandiant reported that threat actors are using URL schema abuse to disguise malicious destinations and make phishing or malware-delivery links appear less suspicious to users and security tools. The technique manipulates how URLs are parsed and displayed, allowing attackers to hide the true destination behind crafted schemes and obfuscated formatting that can evade casual inspection and some automated detections.
The report highlights URL obfuscation as a practical social-engineering and defense-evasion method that can increase click-through rates and complicate incident response. For defenders, the findings underscore the need to normalize and fully parse URLs during inspection, validate scheme handling in security controls, and train users to treat unusual or malformed links as potentially malicious even when the visible text appears benign.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Mandiant published a blog post detailing URL obfuscation techniques that abuse URI schemas, describing the tactic as a security-relevant finding. No earlier discrete real-world events are provided in the reference content.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.