Abusing trusted application domains to forward victims to malicious endpoints via unvalidated JavaScript sinks.
The link looks authentic because it starts with the victim's domain, but the JS logic handles the final bounce to the fake page.