- The Hidden Infrastructure Behind Phishing Campaigns
- Why Earlier Phishing Detection Matters for US Organizations
- How Threat Intelligence Improves Phishing Detection
- Keeping Up with New Phishing Infrastructure
- Investigating Suspicious Phishing Indicators
- Understanding Emerging Phishing Threats
- Making Threat Intelligence Work with Existing Controls
- Measuring the Impact on SOC and MSSP Operations
- Turning Phishing Intelligence into Earlier Action
Phishing remains one of the most persistent problems for security teams, as the challenge is no longer limited to identifying suspicious emails.
Behind a single malicious link there may be a newly registered domain, a compromised website, a redirector, a phishing kit, a credential-harvesting page, or infrastructure used by several related campaigns.
Attackers can also rely on legitimate cloud services and authentication mechanisms, making individual pieces of the attack look less suspicious on their own.
For US-based SOCs and MSSPs, that creates a visibility problem. Blocking a known phishing URL is useful, but it does little for the next URL the attacker registers.
Investigating one malicious domain is useful too, but the real question is whether that domain is connected to other infrastructure already targeting the organization.
Threat intelligence gives security teams a broader view, creating more opportunities to identify phishing infrastructure before it escalates into an incident and impacts the business.
The Hidden Infrastructure Behind Phishing Campaigns
Phishing used to be relatively easy to describe. An attacker created a fake website, sent a convincing message, and waited for someone to enter their credentials.
With modern campaigns, the supporting infrastructure is considerably more complicated.
Attackers can host content on legitimate platforms, compromise existing websites, redirect victims through several destinations, and use authentication mechanisms that employees already recognize.
Some phishing pages are designed to behave differently depending on the visitor, making automated analysis and reputation-based detection more difficult.
ANY.RUN’s H1 2026 Cyber Risk Report found that OAuth device-code phishing surged by 483.7% during the first half of 2026.
The report also found that cloud infrastructure abuse increased by 90.7%, reflecting attackers’ growing use of legitimate services and infrastructure in phishing campaigns.

In addition, researchers observed techniques such as custom CAPTCHA pages, browser fingerprinting, calendar invitations, and legitimate services being incorporated into phishing activity.

For US enterprises, these developments have a practical consequence: An attacker does not necessarily need infrastructure that looks malicious at first glance.
A campaign can use a legitimate service for one stage, a newly registered domain for another, and a compromised website somewhere else in the attack chain.
The indicators will change, while the campaign may not. That makes relationships between indicators increasingly valuable.
Why Earlier Phishing Detection Matters for US Organizations
The consequences of a phishing attack depend heavily on what happens after the victim clicks.
A stolen password can lead to account takeover. A compromised Microsoft 365 session can provide access without requiring the attacker to immediately use the stolen credentials.
A compromised executive or finance account can introduce risks that go well beyond the original phishing message.
The CSuite campaign analyzed by ANY.RUN offers a recent example. The operation used lures impersonating services including Adobe, DocuSign, Zoom, SharePoint, and Microsoft 365. The campaign incorporated phishing, Microsoft 365 session theft, and legitimate remote-management software.
According to the collected data, US organizations represented 60% of identified victim organizations and 51% of related Interactive Sandbox submissions in the research.

The campaign is notable because the phishing page was not the end goal. It was part of a broader attack chain involving identity and remote-access techniques.
For SOCs and MSSPs, finding one of the domains or URLs associated with that chain can therefore provide a starting point for a much broader investigation.
Strengthen phishing investigations with fresh intelligence from 700K+ analysts and improve threat detection. Get access to ANY.RUN TI
How Threat Intelligence Improves Phishing Detection
Threat intelligence gives security teams additional context around suspicious activity, helping analysts determine whether a domain, URL, or IP address is connected to known malicious infrastructure or a wider campaign.
For phishing, that context can be useful at several stages. Fresh intelligence can help identify new infrastructure before it reaches users, while investigation tools can connect individual indicators to related domains, IPs, and campaigns.
Threat intelligence reports can also help teams understand emerging techniques and adjust their defenses accordingly.
Much of that intelligence can originate from analyzing threats as they actually behave. Interactive sandbox environments, for example, allow analysts to open suspicious URLs or execute files in a controlled environment, observe redirects and network activity, and identify indicators that may not be visible from a static URL or file alone.
ANY.RUN’s Interactive Sandbox is designed for this type of real-time analysis of malware and phishing activity.

The result is a more informed response: analysts can spend less time researching individual indicators and more time determining what needs to be investigated, blocked, or hunted across the environment.
Keeping Up with New Phishing Infrastructure
Threat intelligence feeds help SOCs and MSSPs keep pace with constantly changing phishing campaigns.
They continuously deliver indicators such as malicious domains, URLs, and IP addresses that can be integrated into SIEM, SOAR, email security, DNS, firewall, and endpoint controls.
That matters because attackers can abandon a known domain and move to new infrastructure quickly.
A continuously updated feed gives security teams access to newly identified indicators without requiring analysts to manually search for and add every IOC.
ANY.RUN’s Threat Intelligence Feeds (TI Feeds), for example, provide malicious IP addresses, domains, and URLs derived from malware and phishing investigations and are continuously updated.
99% of the IOCs added to its TI Feeds are unique, high-confidence indicators after validation, which can help teams avoid filling their detection systems with duplicate or low-value data.

The feeds are built from live Interactive Sandbox investigations, giving the indicators behavioral context rather than relying only on static reputation data.
For SOCs and MSSPs dealing with large volumes of alerts, that combination of fresh indicators and high-confidence data can make it easier to update defenses without adding another layer of manual filtering and validation.
Give your security team earlier visibility into phishing infrastructure with fresh threat intelligence from 16K+ organizations. Explore TI Feeds
Investigating Suspicious Phishing Indicators
A suspicious domain or URL rarely tells the whole story. Lookup capabilities allow analysts to investigate an indicator, find related infrastructure, review previous observations, and determine whether it is connected to a known campaign.
That additional context can turn an isolated phishing alert into a broader investigation. ANY.RUN’s Threat Intelligence Lookup (TI Lookup) supports more than 30 search parameters, including domains, URLs, IPs, hashes, files, and TTPs.
The solution can return threat context with a 2-second response time, allowing analysts to investigate suspicious indicators without spending as much time moving between different sources.

For security teams, faster access to related infrastructure and historical observations can shorten triage and make it easier to determine whether a phishing indicator is isolated or part of a wider campaign.
Understanding Emerging Phishing Threats
Individual IOCs tell analysts what has already been observed. Threat intelligence reports (TI Reports) add context around the campaigns, techniques, targeting patterns, and changes in attacker behavior behind those indicators.
That broader context can also translate into faster investigations. ANY.RUN’s TI Reports contribute to 21-minute reduction in MTTR and highlight how quickly accessible threat context can help analysts move from identifying an alert to understanding and responding to it.

That broader view can help security leaders prioritize detection improvements before emerging phishing techniques become familiar problems inside the organization.
Making Threat Intelligence Work with Existing Controls
Threat intelligence is not a replacement for email security, EDR, DNS protection, or identity controls. Its value comes from connecting information across them.
A phishing domain identified through threat intelligence can enrich an email alert, trigger a search across DNS logs, or help analysts investigate endpoint activity.
The same intelligence can feed detection rules and threat-hunting workflows.
Integration therefore matters when evaluating a threat intelligence provider. Intelligence that requires analysts to constantly switch between separate tools is harder to operationalize than intelligence that fits into existing workflows.
Measuring the Impact on SOC and MSSP Operations
The number of IOCs in a feed says little about its actual value. More useful measures include investigation time, previously unknown infrastructure discovered, detection coverage, automatically enriched alerts, and the time between detection and response.
The commercial question is ultimately less about how much threat data a team can collect and more about how effectively that data improves security operations.
If SOCs and MSSPs can investigate phishing alerts faster, identify related infrastructure sooner, and update controls with less manual work, the operational gains can accumulate across thousands of alerts and investigations.
Expand threat visibility by up to 58% and catch attacks that bypass standard defenses. Power up your SOC
Turning Phishing Intelligence into Earlier Action
Phishing infrastructure changes quickly, making timely visibility increasingly important. Threat intelligence can help SOCs and MSSPs identify new infrastructure, connect related indicators, and understand emerging campaigns.
Combined with existing security controls, it allows US organizations to detect phishing earlier and respond before a malicious link becomes a larger security incident.

