Phishing remains a significant challenge for security operations centers (SOCs) and managed security service providers (MSSPs) in the US. While the initial focus was on identifying suspicious emails, the landscape has evolved. Today, a single malicious link could lead to a newly registered domain, a compromised website, or a series of redirects, often involving legitimate cloud services that make detection more challenging.
The Complexity of Phishing Campaigns
Phishing strategies have grown more sophisticated. Attackers now utilize legitimate platforms to host content, leverage compromised websites, and employ various redirection techniques to mask their activities. Some phishing pages even adapt their behavior based on the visitor’s profile, complicating automated detection.
According to ANY.RUN’s Cyber Risk Report for the first half of 2026, OAuth device-code phishing attacks surged by 483.7%, highlighting the increasing sophistication of phishing tactics. The report also noted a 90.7% rise in cloud infrastructure abuse by attackers, reflecting a trend towards using trusted services in phishing schemes.
Why Early Detection is Crucial
The aftermath of a phishing attack can be severe, with stolen credentials potentially leading to account takeovers or unauthorized access to sensitive systems. For US organizations, campaigns targeting platforms like Microsoft 365 or using remote-management software pose significant risks, as evidenced by the CSuite campaign that primarily targeted US entities.
Early detection is vital for mitigating these risks. Identifying just one domain or URL linked to a phishing campaign can serve as a pivotal starting point for broader investigations into related infrastructure and potential threats.
Leveraging Threat Intelligence for Better Security
Threat intelligence offers SOCs and MSSPs a comprehensive view of the phishing landscape, enabling them to correlate suspicious activities with known malicious infrastructure. This intelligence is valuable across various stages of a phishing campaign, enhancing the ability to detect emerging threats before they impact users.
Interactive sandbox environments, like ANY.RUN’s, facilitate real-time analysis by allowing analysts to simulate phishing scenarios and observe network activities, providing insights beyond static URL or file assessments. This capability aids in faster decision-making and threat response.
Incorporating threat intelligence into existing security frameworks is not about replacing current systems but enhancing them. By integrating threat data with email alerts, DNS logs, and endpoint activities, SOCs and MSSPs can improve detection and response strategies, minimizing manual intervention and enabling more efficient operations.
