This is a div block with a Webflow interaction that will be triggered when the heading is in the view.

The Anatomy of a Russian-Speaking Cybercrime Cluster
We did not create this cluster. It was already there, one of 80,000 clusters the platform already holds. We opened one of them.
This paper is the proof of what was inside. Indicators of compromise (IOCs) describe resources that are already malicious. Indicators of Pre-Attack (IoPAs) describe the resources while they are still being built, held, or wired. Pre-Attack Intelligence is how those IoPAs become lead time.
Key findings
- Cluster first built 15 Jun 2026; seed registered 27 Jul 2026; Malanta IoPA on the still-empty seed 5 Aug 2026. Resource Development lead time before Initial Access or Delivery.
- We started from
2facheck[.]ltd, an empty domain connected to an AMOS brand-impersonation site, and found it already inside a pre-formed cluster. - The corpus was 1,585 domains: 1,025 held by metadata ties, plus 560 more through behavioral connections, with one bridge domain in both.
- On the day we classified it, only 28% (444) was live; 72% was idle or decommissioned. Credential and payment-card phishing was 340 of the 444 live domains (76.6%).
- In the two weeks after 25 Aug 2026, 30 domains joined the cluster. Twenty-seven of 30 carried only a pre-attack classification; three already had an external threat-feed label.
- Only two domains were malware delivery, both ClickFix, yet the hallway behind them held 21 additional hosts, including a cloaker that filters security and AI crawlers.
- Eighteen wallet-drainer lures shared kit atoms that separate builder from buyer; 25 fake ticket windows and 47 operator-side domains sat in the same nexus.
- Most of what we saw first sits in MITRE ATT&CK Resource Development (TA0042): domain acquisition, staging, certificates, bought tools, and cloaking before the IOC stage.
What is inside
- We started with a question that should have been small
- The empty domain was already inside a cluster
- The names were templates, and the templates were the tell
- Only 28% of the corpus was attacking anyone
- The same campaign, three clocks
- Three quarters of what was live was one business
- The factory's pulse, then the two weeks we watched it grow
- Russian is in the room. A name is not.
- The phase an IOC feed does not cover
- What we do with the lead time
- The Bottom Line
- Indicators and notes
Frequently asked questions
What is this paper?
A walkthrough of one already-formed cluster out of about 80,000 the platform holds. It is proof of what sits behind Pre-Attack Intelligence, not a recipe for building the next cluster.
What is an IoPA in this context?
An Indicator of Pre-Attack describes infrastructure while it is still being built, held, or wired, before it earns a conventional IOC. In this corpus, idle reverse proxies, staged brand names with no feed label, and redirect chains that still end on a real site are examples.
How does this relate to MITRE ATT&CK?
Most of what we could see first sits in Resource Development (TA0042): domains, servers, accounts, tools, certificates, and staging. Live phishing, ClickFix execution, and financial theft are later stages that IOC feeds cover.
Where is the full indicator set?
Defanged domains, addresses, hashes, and kit atoms are in the PDF. The August 2026 domain-only IoPA CSV for the 1,585-domain snapshot is published on Malanta's public GitHub.
What publishes with this paper?
The all-audience cut publishes the same day: Most of this infrastructure was not attacking anyone yet. Two deeper posts follow: Two malware domains. Twenty-one hosts behind them. the day after, then Eighteen drainers. One engine. A buyer who is not the builder.








