Most of this infrastructure was not attacking anyone yet
This is a div block with a Webflow interaction that will be triggered when the heading is in the view.

We did not create this cluster. It was already there, one of 80,000 the platform already holds. We opened one of them.
This is the proof of what was inside. It is not the way a cluster is made. It is what sits behind AI-Powered Threat Intelligence when you stop waiting for an indicator of compromise and start reading infrastructure that is already grouped, including the names that are soon to be malicious and do not yet have a feed entry.
Inside that cluster, one domain had never served a page. Around it sat 1,585 others. On the day we counted them, most of them were not attacking anyone.
The question should have been small
A brand-impersonation site was distributing the AMOS infostealer. Pixel-perfect. The question we were asked was simple: had the operator made more copies?
We did not start on the impersonation page. We started on 2facheck[.]ltd, a domain strongly connected to it. Registered on 27 Jul 2026. First observed two days later. It has never served content.
An IOC workflow would have stopped there. Nothing to sandbox. Nothing to hash. Nothing for a blocklist to bite on. We treated the empty domain as infrastructure, not as a verdict. The cluster around it was already formed. We opened it. What came back was not a single phishing site. It was a corpus: credential and payment-card theft, malware delivery, cryptocurrency wallet draining, ticket scams, impersonation, and the services that keep those campaigns running.
The figure that should change how a leadership team reads threat intelligence is not 1,585. It is 28%.

Seventy-two percent was not live
Of the 1,585 domains, 444 were serving. That is 28.0%. The other 1,141, 72.0%, were idle (567) or decommissioned (574).
Idle does not mean harmless, and it does not mean a campaign is scheduled. The idle set mixes reverse proxies with the origin switched off, CDN blocks, pages we could not tie to this operator, old attacks whose content is gone, placeholders, and hosts that answer with nothing. Fifty-five idle domains had already been used in attacks and were quiet again. A domain can be unused, go live, go quiet, and later be reused. A scan that returns "not malicious today" is a state. It is not a biography.
Decommissioning is not a trophy either. At least 160 of those 574 domains had been active before. Some were suspended. Some were allowed to expire. Against a month in which this operation registered 249 domains, May 2026, losing a domain looks like a cost of doing business.
Of what was live, credential and payment-card theft owned the room: 340 of 444 domains, 76.6%. The rest was a portfolio. Two malware doors sat on a ClickFix hallway with 21 hosts behind them. Eighteen domains were wallet-drainer lures on top of reusable kits. Twenty-five sold fake tickets to real attractions. Forty-seven looked like the operator's own consoles and panels. Two more exposed services the rest of the ecosystem can rent: a cloaking mirror, and a Russian-language factory that mints finished "white" websites, privacy pages included, from an example site.
One misconfigured host made the business model readable. The buyer edits the wallet, the minimum victim value, the Telegram alerts, and the lure. The engine underneath stays obfuscated. The person who built the theft tool and the person who aims it are not the same person. EasyRug, a service this cluster used and did not create, advertised the fee as 25% of profits, later 15%. Those percentages are the vendor's claims. They still show the shape of the market. Capability is a product. A taken-down hostname is a line item.
We walk the ClickFix hallway and the drainer kit in the two posts that follow. The full investigation, with the indicator list, is the technical paper published with this cut: The Anatomy of a Russian-Speaking Cybercrime Cluster. The August 2026 domain corpus is the IoPA CSV on Malanta's public GitHub.
The two weeks that give the lead time away
The longer lead time starts earlier. This cluster was first built on 15 Jun 2026, weeks before the empty seed was registered on 27 Jul. The two weeks below are the feed-lag proof on top of that.
After a 25 Aug 2026 baseline, the cluster added 30 domains in two weeks, about 1.8 a day. Three of the 30 already had an external threat-feed label. The other 27, 90%, did not.
Two of those new names, profiledetails[.]info and 753484474[.]info, already had DNS, certificates, and a redirect chain. The chain ended on the real Gumtree website. Nothing in the final hop was a phishing page. The path that could later carry one was already built. A control that only follows redirects to a known-good site will grade the chain as fine.
That is the setup window. Domains get registered. Servers get configured. Certificates get issued. Redirects, cloaking, and pages get prepared. Some of that work is visible before the campaign has a payload, a phish, or a feed entry. The signals attached to that preparation are Indicators of Pre-Attack (IoPAs). They are not a claim that every quiet domain will be used. They are the lead time between "soon to be malicious" and "already malicious."
We did not record a blocked campaign in this case. We did not compute a Mean Time to Preempt. We recorded the order: infrastructure first, attack later, and a large share of related domains that were not in the "known bad" feed when they showed up.
Russian is in the room. A name is not.
Russian appears in the operator's own development comments, 173 of them across four codebases on one host, and in the admin tools and criminal services around the cluster. Where victim language could be identified, German was 58% and Russian was 23%, with Japanese, Polish, Portuguese, Dutch, and others as well. We recorded the tension. We did not force it into a named group, a nationality, or a location. This writeup will not either.
What changes for a leadership team
The useful question stops being "is this domain malicious?" and becomes three questions. What is this infrastructure connected to? What state is it in? Is that state changing?
One weak link, a shared host or a shared certificate issuer, is not enough to block. The same services carry legitimate businesses. Several independent relationships, plus a change from dormant toward ready, are a different risk. Use the relationships to investigate. Require more evidence before anything becomes a block.
For a CISO, the financial point is about options, not a savings figure this investigation did not calculate. Stopping a phishing domain before Initial Access and Delivery, before employees receive the mail avoids the account resets, session revocations, customer notice, and counsel that follow credential theft. We showed the earlier window. We did not price it.
For a threat intelligence lead, volume of already-malicious indicators is a weak scorecard. A feed of domains that are already bad describes what happened. The sharper test is whether the program saw infrastructure aimed at the business before the mail, the lure, or the charge. In this cluster, that earlier view came from relationships and from pre-attack classification, not from waiting for a third-party feed to agree.
Traditional detection and response still cover the click, the endpoint, and the incident. They do not cover the months of domain registration this cluster showed from November 2025 through August 2026, or the quiet inventory sitting beside the 444 live sites. Pre-Attack Intelligence adds that part of the timeline. It does not replace the stack that handles what already executed.
The Bottom Line
We opened one cluster out of 80,000. We did not invent it. The nexus was first built on 15 Jun 2026, weeks before the empty seed. Cybercrime infrastructure inside it existed before the cybercrime was visible, and most of it was not serving on the day we counted. Twenty-seven of 30 domains added over two weeks had no external feed label when they arrived. The kits, the cloaking, and the website factory stayed useful after any single domain died.
The next gain in threat intelligence is not a longer list of attacks that already happened. It is enough knowledge of the infrastructure behind them to watch the setup, and to act when that setup moves.
Read the full investigation: The Anatomy of a Russian-Speaking Cybercrime Cluster. Domain list: Malanta's public GitHub. Working session on the IOPA feed: ask us.
Pre-Attack Prevention. Hit the source.








