An independent email security test found phishing messages sent from verified addresses with no attachment, where the harmful page only appeared after the recipient clicked a link.

 

What happened

Phishing operators are moving away from malicious attachments toward trusted delivery services, authenticated sending domains, and multi-stage URL cloaking, GBHackers reported on September 15, 2026, covering Virus Bulletin's continuously running VBSpam comparative test. The assessment ran under the Anti-Malware Testing Standards Organization standard AMTSO-LS1-TP207 against wanted, unwanted, and malicious mail streams. Campaigns observed during testing used familiar business pretexts including unpaid invoices, banking consent updates, antivirus renewals, and subscription alerts. What distinguished them was the absence of the indicators legacy controls detect most readily. The malicious behaviour emerged only after a victim clicked, passing through redirects, browser fingerprinting checks, hidden POST requests, and destination pages served selectively.

 

Going deeper

One email in the test posed as an antivirus subscription renewal and carried no attachment at all, according to Virus Bulletin's test report. It used a genuine-looking sender address and included ordinary features such as an unsubscribe link, so it read like a routine commercial notice. The website behind its link changed where it sent people depending on the time, their location, or who appeared to be visiting, which meant a security tool checking the link once would see nothing wrong. A second email, styled as an overdue payment reminder, was sent through Amazon's bulk email service from an address that passed standard sender verification. Its link opened a page designed to look empty, with hidden code that recorded details about the visitor's browser and time zone before quietly passing them on to the attacker.

 

What was said

Organizations should treat SPF, DKIM, and DMARC "as sender-authentication controls, not proof that an email is safe," the testing report concluded, as summarized by GBHackers. Its recommended defences cover normalizing obfuscated URLs, following and repeatedly reassessing redirect chains rather than checking once, detecting browser-fingerprinting behaviour, and correlating email telemetry with web, DNS, and identity signals.

 

In the know

URL formatting itself became an evasion technique in one banking lure. Sent from a DKIM-aligned but entirely unrelated domain, the message embedded an address written in IPv6-mapped notation, a format that represents an ordinary IPv4 address in a way that simple link extraction and reputation checks can fail to parse, according to Virus Bulletin's test report. The link then redirects through an intermediate domain before reaching its destination. Cloaking compounds the problem by returning harmless content to automated crawlers while serving the real page to human visitors, so a filter that fetches the link during inspection sees something different from what the recipient sees. Sender IP geolocation in the test feed put 67.54% of spam samples in the United States, Cyberpress reported, which describes where the sending infrastructure sat rather than where the operators are.

 

The big picture

Authentication records confirm that a message came from a domain the sender controls, and an attacker who registers their own domain and publishes valid records passes every one of those checks. Federal guidance treats filtering as one layer among four, with CISA, the NSA, the FBI, and the Multi-State Information Sharing and Analysis Center recommending secure email gateway configuration alongside outbound web-browsing protections, endpoint hardening, and endpoint protection, in their joint phishing guidance. That guidance also recommends a protective DNS resolver and stripping hyperlinks from inbound mail where workflows allow. For healthcare organizations, the lures in this test map directly onto what administrative staff receive daily, covering invoices, subscription renewals, and payment reminders from outside parties. The instruction that survives every evasion technique described here is for staff to reach billing, banking, and subscription portals through a bookmark or typed address rather than through any link in an unsolicited message.

 

FAQs

What does DMARC actually prove about a message?

That the message came from a domain whose owner authorized the sending server, and that the domain in the visible From address aligns with the authenticated one. It says nothing about the sender's intent, and an attacker controlling their own domain can satisfy it fully.

 

Why does following a redirect chain once produce an unreliable verdict?

Attacker infrastructure can serve different destinations depending on time, location, browser characteristics, or whether the request looks automated. A link that resolves to harmless content during inspection may resolve to a credential harvesting page when the recipient clicks it minutes later.

 

What is browser fingerprinting and why does a phishing page use it?

Collecting characteristics of the visitor's browser, screen, timezone, and configuration to build a profile. Phishing operators use it to distinguish real targets from security scanners and researchers, then serve the malicious page only to the former.

 

How can a filter handle a link written in an unusual address format?

By normalizing addresses into a single canonical form before evaluation, so that alternative notations for the same destination resolve to the same reputation check. Filters that extract links using simple pattern matching can miss formats that are technically valid but rarely used.

 

Should organizations strip links from inbound email?

It is workable for some populations and disruptive for others, which is why federal guidance frames it as an option rather than a default. Organizations that cannot strip links broadly can apply it to higher-risk groups, or pair link rewriting with checks performed at the moment of the click rather than at delivery.