← Back to documentation

Campaign Detection

Automatic identification of coordinated phishing attacks through advanced pattern analysis and infrastructure correlation.

What is a Phishing Campaign?

A phishing campaign is a coordinated attack where threat actors register multiple domains following specific patterns to conduct large-scale phishing operations. Unlike individual suspicious domains, campaigns represent organized, systematic attacks that pose significantly higher risks to your brand and customers.

Our campaign detection system goes beyond simple domain monitoring by identifying relationships and patterns between multiple suspicious domains, helping you understand the scope and sophistication of attacks targeting your brand.

Campaign vs Individual Alerts

Individual Alerts

  • • Single domain detection
  • • No coordination evidence
  • • Could be coincidental
  • • Harder to prioritize

Campaign Detection

  • • Multiple coordinated domains
  • • Clear attack patterns
  • • Organized threat actor
  • • High-priority threat

Pattern Detection Methods

Our system analyzes multiple indicators to identify coordinated campaigns:

Numeric Sequence Patterns

Detection of domains with sequential numbering schemes, indicating bulk registration by the same actor.

Example Campaign:

  • • paypal-verify1.com
  • • paypal-verify2.com
  • • paypal-verify3.com
  • • paypal-verify4.com

Risk: Systematic approach suggests professional threat actor with significant resources

TLD Variation Campaigns

Registration of the same domain name across multiple top-level domains to maximize attack surface and avoid detection.

Example Campaign:

  • • microsoft-security.com
  • • microsoft-security.net
  • • microsoft-security.org
  • • microsoft-security.info

Risk: Increases user confusion and provides fallback options for attackers

Common Prefix Patterns

Domains sharing common prefixes or structural elements, suggesting coordinated branding strategy.

Example Campaign:

  • • secure-paypal-login.com
  • • secure-amazon-account.com
  • • secure-microsoft-auth.com
  • • secure-google-verify.com

Risk: Exploits user trust in "secure" terminology across multiple brands

Infrastructure Correlation

Domains sharing the same IP addresses, nameservers, or registrar information, indicating common ownership or management.

Shared Infrastructure Indicators:

  • • Same IP address hosting multiple suspicious domains
  • • Common nameserver configuration
  • • Identical registrar and registration patterns
  • • Similar SSL certificate authorities

Risk: Reveals threat actor infrastructure and enables broader takedown actions

Campaign Threat Levels

Campaigns are automatically assessed for threat level based on scale, patterns, and infrastructure sophistication:

Critical Risk

10+ domains

Large-scale coordinated attack with professional infrastructure

High Risk

5-9 domains

Significant campaign with clear coordination and shared infrastructure

Medium Risk

3-4 domains

Emerging campaign with identifiable patterns requiring monitoring

Campaign Intelligence Benefits

  • •Threat Attribution: Understand which attacks are coordinated vs opportunistic
  • •Scale Assessment: Quantify the scope and resources behind attacks
  • •Predictive Intelligence: Anticipate additional domains in ongoing campaigns
  • •Coordinated Response: Enable comprehensive takedown actions across campaign infrastructure
  • •Priority Triage: Focus resources on organized threats vs individual incidents

Automated Detection Process

Campaign detection runs automatically whenever new alerts are generated:

1

Alert Aggregation

System collects all alerts for the same keyword within a temporal window

2

Pattern Analysis

Advanced algorithms analyze domain names for structural patterns and similarities

3

Infrastructure Correlation

Cross-reference IP addresses, nameservers, and registration data

4

Campaign Creation

Automatic campaign generation with threat scoring and alert linking

Response Strategies

Coordinated campaigns require different response approaches than individual threats:

Immediate Actions

  • • Coordinated takedown requests across all campaign domains
  • • Infrastructure-level blocking (IP ranges, nameservers)
  • • Expanded monitoring for campaign pattern variations
  • • Threat intelligence sharing with security community

Investigation & Analysis

  • • Threat actor attribution and capability assessment
  • • Campaign evolution tracking and prediction
  • • Infrastructure mapping and ownership research
  • • Attack vector analysis and user impact assessment

Preventive Measures

  • • Defensive domain registrations based on campaign patterns
  • • Enhanced monitoring rules for identified threat actors
  • • Customer education about specific campaign tactics
  • • Legal action preparation and evidence collection

Related Documentation

Explore related features that enhance campaign detection and response: