A lot of phishing links win on mobile. Smaller screens, hidden URLs, fast thumb taps, zero patience. People aren’t inspecting domains in line at the coffee shop. Attackers know that.
Malicious links are getting better at hiding inside normal workflows. Fake Dropbox shares. Spoofed DocuSign emails. “View invoice” buttons. The attack works because it shows up where people already click without thinking.
Phishing doesn’t need a brilliant hacker movie setup. Sometimes it’s just urgency + a familiar logo + a link that lands on a cloned login page. Cheap, boring, effective.
One thing I keep seeing with malicious links is domains that trick users into clicking them. A swapped letter. An extra dash. A fake subdomain. On a busy day, that’s all it takes.
The most convincing phishing links no longer look sketchy. They look like shared docs, invoice reminders, login alerts, and “you missed a message” emails. That’s the whole game: make the click feel routine.
One of the most common mistakes in URL moderation systems is treating report volume as if it were ground truth.
If a platform automatically downgrades, blocks, or takes down a URL after a fixed number of reports, the system becomes an attack surface.
https://t.co/nSoqi4LJYN
Many systems still make the same mistake: they review the submitted URL and stop there.
Attackers love that.
If the visible link looks harmless enough, they can hide the real risk one or more hops deeper in the chain.
https://t.co/cw8Pw2yhN5
Modern phishing operations are rarely tied to one neat hostname.
Two of the most effective infrastructure tricks are:
Wildcard subdomain routing
rapid domain churn
Together, they let attackers keep the same kit logic while moving the public-facing URL
https://t.co/9wggj3WMpm
For part 1 in this series, we are going to take a look at a fake phishing login page.
Even before looking at the page, the URL gives away several things that deserve immediate scrutiny.
https://t.co/qGZnpPslve
Most phishing campaigns don’t start on shady domains — they hide in plain sight on free hosting.
We’re seeing a surge in abuse on platforms like Vercel, Blogspot, Netlify Pages, GitHub Pages & more.
LinkShield scans & blocks these before they reach your users.
Ever wonder what the most impersonated brands are in phishing attacks?
📧 Microsoft
📦 Amazon
💳 PayPal
📱 Apple
🌐 Facebook
Hackers use these trusted names to trick users into giving up credentials.
🛡️ Link Shield scans links to expose these fakes before you click on them
🚨 Not all domains are created equal. Some TLDs are hotspots for malicious content (.tk, .xyz, .top, .gq, .cf).
🔗 Link Shield scans every URL + follows redirects to uncover hidden threats—so you don’t have to worry where a link ends up.
Attackers are getting smarter.
They put phishing sites behind Cloudflare to block security scanners, so automated tools can’t see the malicious content.
🔍 Link Shield doesn’t stop at the first layer — it will uncover what’s really hiding behind the URL.
That “projectzip” from an unknown sender? 🚩
Attackers hide malware inside compressed files, making them look harmless.
🛡️ With Link Shield, risky links are flagged before the download even starts.
Don’t unzip a disaster.
Hackers love abusing trusted platforms.
📂 A Dropbox link might look safe, but inside is malware waiting to run.
🔍 Link Shield scans shared links and follows redirects so you see the real threat before it spreads.
Stay one step ahead. 🛡️
One of the challenging aspects of building TLY has always been dealing with malicious links. If you let users add content, chances are some will eventually drop a phishing link or malware redirect.
I’ve been building a tool called @linkshieldapi
to help with this. It scans URLs, uses AI, and checks domains against threat sources to catch suspicious behavior before links go live.
That said, there’s no silver bullet, and I’d love to hear how others here are approaching the problem:
Do you rely on services like Google Safe Browsing, VirusTotal, or your own threat feeds?
Do you manually review them? At some point, this will become overwhelming.
Do you block at the domain level, scan in real time, or just monitor after the fact?
How do you balance safety with not creating too many false positives or friction for users?
🚨 Scammers are using throwaway domains to redirect unsuspecting users to Facebook phishing sites.
With Link Shield, you don’t just scan the URL — you follow the redirects too. 🛡️
That means hidden traps get exposed before anyone clicks.
Protect your links. Protect your users.