PERSIST SECURITYPULSE · ATR
Back to all articles

Phishing and BEC: Stopping the Campaign Before It Reaches the Inbox

Published July 30, 20266 min read

Phishing remains the most common initial access vector into organizations, and BEC (Business Email Compromise) attacks — where an attacker impersonates a known business contact — are among those causing the highest direct financial damage. Both families share one trait: they rely on disposable infrastructure built for rapid replacement. That very trait is the defender's opportunity.

What a Modern Campaign Looks Like

A typical phishing campaign runs several components in parallel: an impersonation domain (often one character away from the original), credential-harvesting pages hosted on cloud infrastructure, sending addresses created or compromised for the campaign, and shortened or obfuscated links designed to evade filtering.

A BEC campaign involves more investment: the attacker studies the organization, identifies who approves payments, and sometimes takes over a real mailbox of a supplier or partner. The messages themselves usually contain no malicious file — which lets them slip past signature-based filtering — but they always come from infrastructure that can be identified: a sender address, a domain, a sending server.

The Attacker's Weak Point: Infrastructure

The attacker can craft as convincing a message as they like — but they need infrastructure to send it and to collect victims. That infrastructure gets exposed: new domains are reported, sending addresses are identified in parallel campaigns against other organizations, and harvesting pages are discovered by intelligence operations.

Once the infrastructure is known, the only question is how fast it is blocked in your environment: at the email layer (blocking the sender and domain), at the network layer (blocking the URL and IP address), and at the DNS layer. Coordinated blocking across all three stops both new messages and users clicking links in messages that already arrived.

Why Built-In Email Filtering Is Not Enough

The filtering in Microsoft 365 and Google Workspace is an important line of defense, but it is tuned for broad detection — not for the campaign targeting your market right now. A targeted campaign in a local language, impersonating a local bank or government service, may go uncaught by global filtering during the critical first hours.

This is where local intelligence comes in: indicators originating from local CERT bodies and from SOC teams seeing similar campaigns at other organizations in the same market. A service like PULSE streams these indicators directly into email systems — sender blocks in Microsoft 365, Secure Email Gateway updates — alongside blocking the domains and addresses at the network layer.

Defense in Layers: What Gets Blocked Where

When a campaign's indicators are distributed correctly, each layer catches a different part:

  • Sender and sending domain — blocked in the email system: new messages stop arriving
  • The harvesting page URL — blocked at the Web Gateway: clicking an existing link fails
  • The campaign domain — blocked at DNS: even alternate channels can't reach it
  • The infrastructure's IP address — blocked at the firewall: the door closes for reuse too

And the Users Who Already Clicked?

Fast blocking also limits damage already done: a user who clicked before the block will hit a blocked page when they try again, and malware that managed to download will fail to reach its control server if the C2 addresses were blocked. That is why indicator distribution must cover the full chain — not just the initial domain.

In phishing and BEC, time is the deciding variable: a campaign blocked in the first quarter hour is a marginal event; the same campaign after half a day is an organization-wide incident. Coordinated, real-time infrastructure blocking is how you stay on the right side of that equation.

Want to see how PULSE works in your environment?

The Persist Security team will be glad to walk you through the service and assess the fit for your organization.

Book a Consultation

More articles