Short Path to Phishing: Identifying Misused URL Shortening Services in the Wild
Zul Odgerel, Yevheniya Nosyk, Jan Bayer, Sourena Maroofi, Louis Bedeschi, Andrzej Duda, Maciej Korczyński · 2025
URL shortening services are commonly used to share long links, which avoids the limits on the number of characters imposed by online platforms. However, cybercriminals exploit these services to obscure link destinations, bypass security filters, and deceive users. Consequently, short URLs involved in phishing appear on popular blocklists, which may trigger abuse notifications to registrars or TLD registries. This misattribution forces them into manual investigations and consumes valuable time on abuse that is not under their direct responsibility. If the role of a domain as a shortening service is not recognized, it risks mistaken suspension despite that most links are benign. We argue that addressing such abuse requires tailored mitigation strategies and that maintaining an accurate and up-to-date list of URL shortening services is essential.In this paper, we propose a classification model to determine if a given domain name belongs to a URL shortening service. We manually curate a ground truth dataset of 211 URL shorteners and collect three groups of features to further train two machine learning models. Our random forest classifier achieves a precision of 98.4%. Next, we apply our method to 1.5 M unlabeled phishing URLs reported to APWG, OpenPhish, and PhishTank. Our model identifies 177 new USS in the wild, not previously seen in our ground truth. Finally, we measure the post-detection uptime of malicious short links from the ten most abused USS, showing that the median mitigation time is within 48 hours.