Phishing remains one of the simplest yet most effective cyber‑attacks out there - and spotting the infrastructure behind it can make all the difference. Recently, our Cypex AIM platform flagged an OVH-hosted IP in France that was quietly serving up dozens of “.es” domains posing as legitimate Spanish sites. Weeks before this IP showed up on any public blocklist, we’d already calculated its high risk and alerted our users.
In one attack chain, the sender claimed that the malicious file attached was a list of enterprises scheduled for tax inspection and asked the receiver to forward the information to their company's treasurer.
Preemptive Detection of RedDelta’s PlugX Campaign Across Asia
Attackers added exfiltration tools to the infrastructure to steal data, enabling unauthorized data transfer and breaches