Geodo (also known as Emotet) malware campaigns are effectively spoofing major US financial institutions in part by including legitimate URLs wrapped in Proofpoints (PFPT) TAP URL Defense wrapping service. This adds an air of legitimacy to the casual observer, designed to increase the chances of malware infection. Cofense Intelligence assesses the improved phishing templates are likely based upon data pilfered with a recently updated scraper module to spoof US banks so effectively. The new inclusion of ProofPoint URLs wrapped with URL Defense adds an additional false sense of security to a user.”]