Post #4178006
2026-07-27 14:22 UTC
@trojanfoxtrot@infosec.exchange Nice, the redirection and captcha-gating chain is exactly the part that eats the hours.
The bit we keep chewing on is each hop: when it lands on SendGrid or a Cloudflare edge, is that the attacker hiding behind a real service, or the real service? Known-good context per hop tells you which ones to stop expanding.
Replies (1)
-
@trojanfoxtrot@infosec.exchange 2026-07-29 00:38
@reput_io@infosec.exchange the way PhantomGraph is doing it is by a deterministic combination based on preceding behaviors and not so reliant on the atomic observable indicator. Even if there are legit human verification gates in the click flow being abused by attacker infrastructure, the method of delivery, header info mismatch, lure language, and content will still and malicious; if the web page had already exhibited phishy behavior before the captcha, it will follow that thread and show the downloaded scripts too!