Campaign Detection
Automatic identification of coordinated phishing attacks through advanced pattern analysis and infrastructure correlation.
What is a Phishing Campaign?
A phishing campaign is a coordinated attack where threat actors register multiple domains following specific patterns to conduct large-scale phishing operations. Unlike individual suspicious domains, campaigns represent organized, systematic attacks that pose significantly higher risks to your brand and customers.
Our campaign detection system goes beyond simple domain monitoring by identifying relationships and patterns between multiple suspicious domains, helping you understand the scope and sophistication of attacks targeting your brand.
Campaign vs Individual Alerts
Individual Alerts
- • Single domain detection
- • No coordination evidence
- • Could be coincidental
- • Harder to prioritize
Campaign Detection
- • Multiple coordinated domains
- • Clear attack patterns
- • Organized threat actor
- • High-priority threat
Pattern Detection Methods
Our system analyzes multiple indicators to identify coordinated campaigns:
Numeric Sequence Patterns
Detection of domains with sequential numbering schemes, indicating bulk registration by the same actor.
Example Campaign:
- • paypal-verify1.com
- • paypal-verify2.com
- • paypal-verify3.com
- • paypal-verify4.com
Risk: Systematic approach suggests professional threat actor with significant resources
TLD Variation Campaigns
Registration of the same domain name across multiple top-level domains to maximize attack surface and avoid detection.
Example Campaign:
- • microsoft-security.com
- • microsoft-security.net
- • microsoft-security.org
- • microsoft-security.info
Risk: Increases user confusion and provides fallback options for attackers
Common Prefix Patterns
Domains sharing common prefixes or structural elements, suggesting coordinated branding strategy.
Example Campaign:
- • secure-paypal-login.com
- • secure-amazon-account.com
- • secure-microsoft-auth.com
- • secure-google-verify.com
Risk: Exploits user trust in "secure" terminology across multiple brands
Infrastructure Correlation
Domains sharing the same IP addresses, nameservers, or registrar information, indicating common ownership or management.
Shared Infrastructure Indicators:
- • Same IP address hosting multiple suspicious domains
- • Common nameserver configuration
- • Identical registrar and registration patterns
- • Similar SSL certificate authorities
Risk: Reveals threat actor infrastructure and enables broader takedown actions
Campaign Threat Levels
Campaigns are automatically assessed for threat level based on scale, patterns, and infrastructure sophistication:
Critical Risk
10+ domainsLarge-scale coordinated attack with professional infrastructure
High Risk
5-9 domainsSignificant campaign with clear coordination and shared infrastructure
Medium Risk
3-4 domainsEmerging campaign with identifiable patterns requiring monitoring
Campaign Intelligence Benefits
- •Threat Attribution: Understand which attacks are coordinated vs opportunistic
- •Scale Assessment: Quantify the scope and resources behind attacks
- •Predictive Intelligence: Anticipate additional domains in ongoing campaigns
- •Coordinated Response: Enable comprehensive takedown actions across campaign infrastructure
- •Priority Triage: Focus resources on organized threats vs individual incidents
Automated Detection Process
Campaign detection runs automatically whenever new alerts are generated:
Alert Aggregation
System collects all alerts for the same keyword within a temporal window
Pattern Analysis
Advanced algorithms analyze domain names for structural patterns and similarities
Infrastructure Correlation
Cross-reference IP addresses, nameservers, and registration data
Campaign Creation
Automatic campaign generation with threat scoring and alert linking
Response Strategies
Coordinated campaigns require different response approaches than individual threats:
Immediate Actions
- • Coordinated takedown requests across all campaign domains
- • Infrastructure-level blocking (IP ranges, nameservers)
- • Expanded monitoring for campaign pattern variations
- • Threat intelligence sharing with security community
Investigation & Analysis
- • Threat actor attribution and capability assessment
- • Campaign evolution tracking and prediction
- • Infrastructure mapping and ownership research
- • Attack vector analysis and user impact assessment
Preventive Measures
- • Defensive domain registrations based on campaign patterns
- • Enhanced monitoring rules for identified threat actors
- • Customer education about specific campaign tactics
- • Legal action preparation and evidence collection
Related Documentation
Explore related features that enhance campaign detection and response: