Gmail short.gy Phishing Lure Redirecting to chongdaotang.net (T1566.002)
This rule detects a multi-stage phishing campaign involving Gmail-hosted emails containing 'short.gy' URLs. It monitors for three distinct signals: (1) Outbound network connections to 'chongdaotang.net', (2) User clicks on 'short.gy' links arriving from Gmail addresses, and (3) Inbound or BCC-delivered emails from Gmail senders containing 'short.gy' links. This combination is highly indicative of a phishing operation attempting to redirect users to a malicious infrastructure.
Microsoft Sentinel (KQL)

