The Blind Spot: How “Bulletproof” Phishing Redirectors Slip Past SEGs

The Blind Spot: How “Bulletproof” Phishing Redirectors Slip Past SEGs

By Shikhar Dalela and Jeewan Singh Jalal

The operators named the kit themselves.

Buried inside compromised legitimate websites, the hidden staging directory is sometimes literally called “/.bulletproof”, and the PHP session cookie the kit sets on every visitor is named “bp_redir_sess.” The “bp” stands for bulletproof, which is an unusual degree of candor from a threat actor whose entire design philosophy is concealment.