Weaponization of Cisco Safe Links in Phishing Campaigns
Arjun4 min read
THREAT INTELLIGENCE#cisco#safe-links#phishing

Weaponization of Cisco Safe Links in Phishing Campaigns

Raven AI has uncovered a phishing campaign exploiting Cisco's Secure Links feature to deliver credential-harvesting payloads. By abusing trusted Cisco domains, attackers bypass defenses and exploit end-user trust.

Share:

What was found

In August 2025, Raven AI researchers spotted a phishing campaign abusing Cisco's Safe Links feature — a core piece of its Secure Email Gateway (SEG) — to deliver credential-harvesting payloads.

  • Malicious URLs were hidden behind rewritten Cisco Safe Links (e.g., https://secure-web.cisco.com/...).
  • Those trusted Cisco-branded URLs let attackers slide past filtering tools and trade on end-user confidence.
  • It signals a new phishing paradigm: adversaries aren't just impersonating brands anymore — they're misusing the infrastructure of trusted security providers themselves.

I build detections for a living, and this is the kind of campaign that quietly defeats a lot of rule sets. If your logic stops at the domain, a secure-web.cisco.com wrapper sails right through.


How the campaign worked

The way in

  • Phishing emails carried embedded malicious URLs that had been rewritten by Cisco Safe Links.
  • Targets clustered around finance, legal, and operations staff.
  • Inside Job – Compromised accounts inside Cisco-protected orgs auto-generated Safe Links.
  • Trojan Horse – Malicious URLs dropped into legitimate email threads.
  • SaaS Backdoor – Links smuggled in through legitimate SaaS notifications (e-signature portals, invoice tools).
  • Recycling Program – Attackers reused still-valid old Safe Links in fresh waves.

Lures and payload

  • Impersonated services: DocuSign, HR portals, finance systems.
  • Common bait: "document review," remittance notices, digital signatures.
  • The wrapper domain (secure-web.cisco.com) sold the legitimacy.
  • Final payload: credential-harvesting portals dressed up as corporate login pages.

What the attackers were after

  • Credential Theft → corporate SaaS platforms (O365, Google Workspace, ERP).
  • Persistence → keeping unauthorized account access alive with harvested credentials.
  • Monetization → setting up Enterprise Email Compromise (BEC) and payment fraud.

Why this is a bigger deal than it looks

This campaign marks a shift in phishing strategy:

  • Attackers weaponize brand trust in security vendors rather than relying purely on obfuscation or novel malware.
  • Cisco's domain (secure-web.cisco.com) is commonly whitelisted, which dims detection by security teams.
  • Trust itself becomes the attack surface — adversaries cash in on the implicit credibility we hand to Cisco's infrastructure.

From a detection-engineering seat, the lesson is blunt: any allowlist is a gift to an attacker who can route through it. That's the same trust-abuse pattern we unpacked in the HeartCrypt EDR-killer analysis — defenders trusting a signal that the adversary now controls.


What to do about it

For Organizations

  • Inspect the entire redirect chain, not just the Cisco base domain.
  • Tune SEG/EDR/ML detection to evaluate where Safe Links actually land.
  • Build defense-in-depth: DNS filtering, proxy-based URL inspection, zero-trust access.
  • Run phishing simulations using Safe Links–style URLs to measure how your people hold up.

For Employees / End Users

  • ⚠️ Don't assume Cisco Safe Links = safe.
  • Cross-check sensitive requests (payments, signatures) over a second channel.
  • Hover over Safe Links to preview the full destination before you click.
  • Report anything suspicious to your security team.

A detail I'd add from the detection side: the credential pages are the goal, so make the credentials worthless. Seed your login flows and SaaS tenants with decoy accounts that no real person uses. The moment a harvested honeytoken gets replayed, you've got a high-fidelity alert with almost zero false positives. We go deeper on that in stopping AI-driven credential theft with honeytokens.


Final word

The weaponization of Cisco Safe Links is a real evolution in phishing tradecraft: attackers are abusing trusted security infrastructure to cloak their intent.

  • Organizations have to analyze beyond the trusted wrapper.
  • Employees need to internalize that "Cisco Safe Links ≠ safe by default."
  • Security teams should plan for a world where trust abuse is a core phishing tactic.

The takeaway: trust in a branded domain isn't enough on its own. Inspecting full redirect paths, governing SaaS integrations, and running continuous phishing awareness are how you push back. To catch the credential theft these campaigns aim for, see how Mine2's deception tokens turn a stolen login into an instant, high-confidence alert.

M2

Arjun

Lead Detection Engineer, Mine2

Arjun builds detection logic at Mine2, focusing on the blind spots EDR and SIEM leave behind and how honeytokens close them.

Share this article

Secure Your Network Today

Ready to implement advanced cyber deception in your organization? See how MINE2 can transform your threat detection capabilities.