Attackers can use t.m1.email.samsung.com to redirect targets to a malicious domain. The format of the link would be as follows: https://t.m1.email.samsung.com/r/?id=hdbbbab34,71b0ad58,6b55baa5&p1=[phishing-link]
Command and Control
None
Exfiltration
None
Download
Attackers can use t.m1.email.samsung.com to masquerade a direct download link.