-
Notifications
You must be signed in to change notification settings - Fork 19
How Actor Attribution Works
PhishDestroy edited this page Nov 29, 2025
·
1 revision
Actors are identified by correlating multiple independent OSINT markers.
Actors often use:
- Same NameServers
- Same hosting providers
- Same registration windows (e.g., 20 domains in 3 minutes)
- Same WHOIS patterns
- JS files reused across domains
- Unique custom drainer code
- Hardcoded API endpoints
- Copy-pasted phishing templates
Actors targeting:
- The same brands
- The same regions
- The same crypto wallets
- URLScan report patterns
- Repeated directories (/auth/, /verify/, /connect/)
- Matching phishing kits
When 3+ independent markers match →
Actor cluster is confirmed.