Patent attributes
Methods and systems for malicious message detection and processing are provided. An example method includes detecting, via an intermediary node, a link included in a message, the link being associated with an unknown resource or a known malicious resource. The intermediary node may have a processor and a memory for storing executable instructions to perform the method. The example method further includes hashing a unique identifier for each recipient of the message; coupling each of the hashed unique identifiers with the link to create an unique updated link for each recipient; and for each recipient, replacing the link in the message with their corresponding unique updated link. The method may include causing forwarding of the updated message with the corresponding unique updated link to each recipient. If the resource is a malicious resource, the unique update link may be to a block webpage associated with a trusted resource.