Video: Your Brand Is the Lure: Inside the ClickFix Campaigns Targeting Trusted Names in 2026 | Duration: 3168s | Summary: Your Brand Is the Lure: Inside the ClickFix Campaigns Targeting Trusted Names in 2026 | Chapters: Welcome and Introductions (6.08s), Speaker Introductions (56.4s), Speaker Introduction (80.18s), Session Agenda (100.545s), ClickFix Campaign Report (172.67000000000002s), ClickFix Explained (219.365s), Campaign Case Studies (458.05s), QuickBooks Campaign Evolution (597.9449999999999s), BirdEye Campaign Analysis (699.3599999999999s), Tracking Artifacts (875.185s), Evolution and Adaptability (1161.145s), Detection Methodologies (1319.48s), Filtering and Prioritization (1482.92s), Automated Threat Detection (1617.65s), Digital Risk Protection (1893.9850000000001s), Malicious Sites Overview (2150.495s), Collection Pipeline Strategy (2492.115s), Takedowns and Collections (2586.81s), Detection Analytics Evolution (2671.685s), Closing Remarks (2873.185s), Closing Remarks (3127.16s)
Transcript for "Your Brand Is the Lure: Inside the ClickFix Campaigns Targeting Trusted Names in 2026": Hello, everyone, and welcome. So as you might have heard, last week, Recorded Future revealed the launch of digital risk protection. This solution was built to protect companies from the threats that target their brand name, their logo, their employees, their customers, and their executives. In this webinar, we'll be digging into the click fix campaigns our Insikt Group reported on and how the new digital risk protection capabilities played a big role in helping them uncover some of these findings. First, let's start with some introductions. I'm Maddy Maletz. I'm a product marketer here at Recorded Future focused on our digital risk protection solution, and I'll be moderating today's session. And then I'm joined by our very own Patrick Arnold and Tristan too. Patrick, would you like to introduce yourself first? Hey. Good morning, everyone. As Maddie said, my name is Patrick Arnold. I'm one of the principal threat intelligence analysts, in Insikt Group Recorded Future working on the technical research and analysis team, focusing on malicious infrastructure, advanced persistent threats, and, cybercrime, and trying to find anything and all that we can around that to generate reports. Tristan, over to you. Thank you very much, Maddie. My name is Tristan Tew. I'm one of our collections leads at Recorded Future, focused primarily on looking at, open web data, finding ways for us to most efficiently, index and analyze that information, and working on analytics that allow our partners and in you, the prospect or client, to drive value from that data. Awesome. Okay. Just a quick look at what we'll cover today. We already got got through the introductions, and I'll just have one more quick slide to talk through just to continue setting the scene a bit. But then I'll pass it over to Patrick, who will really get into click fix, what it is, how it's being used, some of the historic campaigns along with it. And then from there, Tristan will really take it away by showcasing our new digital risk protection piece starting with how we can index and analyze at scale and then a really close look at our malicious sites monitoring use case. After that, we'll open it up for q and a, and then I'll close out with what's coming. One quick sort of housekeeping note as we do with all of our webinars. As we get going, please go ahead and put your questions in the chat throughout the session, and we'll make sure to get to them at the end during the q and a. If not if we can't respond to them throughout. If we don't get to your questions live, we'll make sure to follow-up, with email or or whatever the best way to get in contact is with you afterward. So with that, let's dive in. Just to continue setting the scene really quickly, I wanted to surface, this report as this is really what serves as the foundation for this webinar given the connection between these findings and our digital risk protection launch. So I, of course, will not take credit for the great work that Patrick and his team have produced and published with the this Insikt Group blog, but this is what went out earlier this year back in March, on the click fix campaigns. And even though it was published back a few months ago, click fix is still very relevant today, and we don't really anticipate that changing anytime soon. So, Patrick, do you want to take us into what click fix actually is and isn't? No. Absolutely, Maddy. Thank you so much. I appreciate it. So kinda wanna dive in, talk about a little bit of what is click fix. As Maddy said, we did this report back in March is when we released it, and it was really, really interesting to look at. And it was a really neat opportunity for us to collaborate, a little differently than we had, look at an internal dataset, and really be able to kinda dive in there and drive the research in a different way than we would normally. And then, again, as she said, it's still growing. We still see it today. We're still tracking it. We're still looking at new variants, new evolutions. So, what we did in March is still very relevant to what we're looking today. So in a nutshell, what is Click Fix? When we look at all of it, it's not a malware. I think the name kind of is a little deceiving because it has a name that doesn't seem like it would be anything but, but it is actually, an attack vector. It's a social engineering technique that is used to, in effect, weaponize the victim itself into infecting their own system using means that would normally look safe and are very familiar to the victim as well. You know, it's not static. We see it change constantly. Kinda like we just said, we still see it growing and evolving today, and it's scalable and repeatable. The only limit that we see with click fix really is the scope of what a threat actor is wanting to do and their own ability to manage their own malicious infrastructure in that attack. It's agile, and it's adaptable. We see it adjusting to new operating systems. We see it focusing on new visuals, updated graphics to maintain that trend of how they are actually working. And it's easily accessible to threat actors as well. We see it, being sold in forums on the dark web. On the right, you can kinda see a post by a user in the exploit forum trying to sell quick fix as well. So it's very easily accessible to these threat actors in order to build these campaigns in order to attack a victim. So that said, in its core, it's very simplistic as far as what it's actually doing to go after a victim and what it wants to do. It's leveraging what most would think is safe, which is what they see in the check with your human turnstiles and the CAPTCHA version twos, which is kind of at its core by social engineering and why this is such a big deal for what we're going after. It follows this chain very simply, presenting, you know, are you human? Please click to respond and say, I am not a robot. Something all of us have encountered anytime that we're working or browsing online, and it's something that we are very familiar with, to ensure that what we do keeps not us not only us safe, but the brands and what we would normally be looking at online. Click fix, when they're doing this, takes that step one step further and gives victims a second false verification step, and this is actually where they are infected. So after the the user or victim has gone in and clicked say, I'm not a robot, they're presenting, you know, with, hey. We need to better prove that you are not, in fact, a robot. We need you to actually put this command in on your computer with the, a run command or terminal depending if the user is working on Windows or Unix, and that is where we actually get to. We are bypassing normal security techniques and their social engineering to weaponize the victim to open that run terminal and put in a command that doesn't actually, of course, verify that they're not a robot, but instead is actually having the victim's machine reach out to a malicious command and control server to download whatever malicious payload the threat actor has determined. And this is what makes it so dangerous. It is bypassing what a lot of security, centers and a lot of security standards would set up in a corporate environment to get around those normal techniques. So what we'd like to do is kinda step through a few of the campaigns that we have seen, historically in ways that this kind of affected not only, victims, but kinda how it leveraged what, brands offer and why that makes this such a big deal when we're tracking this. Because it doesn't just affect the victim, but it's also affecting the brands that we look at. It uses their reputation in order to lure these victims, but it's also going to be, you know, using that in order to affect them. And it affects the reputation, so that's why we think it's important to track as well. So back in March, we did focus on several campaigns. These were three that really kind of drove home what was at its core of click fix and kind of how it layered that social engineering technique to really get to, the victims. This was one that we saw, targeting, booking, traveling site, and followed a lot of the same steps that we just talked about as well, but it did several different things in order to really keep it looking legitimate. So this one specifically used a fake site that was spoofed called the state reserve. And and looking at it so it also used the logo, and it used the black the page on the back as a backsplash to make it look more legitimate, use that branding to make a victim think they were actually on the real site when they were not, in fact, and make it seem that when they were presented with the verification step, they were actually being protected in a legitimate way. So once the user clicks that, they're once again taken here as we kinda talked about before to see, you know, this is the verification step. The second part, please put it in, which, of course, did an infection. They are once again trying to leverage that brand's reputation in order to give that extra level of false safety to the victims. So even the favicon that would normally appear is actually being used here in order to be like, hey. This is actually booking asking you for this, not a different brand or company. So it's giving that extra level to fool the victim. And at this point, if they had finished the step, open the terminal, they would have been successfully infected, at that point. Another that was very similar that we looked at around that same time was a QuickBooks spoofing campaign. Intuit QuickBooks was what they were looking at here. It followed very, very similar guidelines for what they had done in other campaigns previously. On here as well, the backsplash of the page is very much the brand of QuickBooks. You see the logo on the page as well. Follow the same steps, check that you are human, and then second, verification. Something that was interesting on this one, and it's a subtle difference, but it is a difference that makes this a little bit broader of a potential attack from one of these threat threat actors, is that instead of using the brand's Favicon logo on the actual turnstile, they're using CloudFlare, which on this one, I think, actually adds a different level of false security for victims when we're looking at it. I think all of us at one point have seen we're browsing normally on a page, and we get a pop up from Cloudflare asking us to verify that we actually are not a bot. Something in our clicks has changed that timing. So it's something we're very familiar with. It's something we see constantly. So the victim is less inclined to think something is wrong or that something is malicious at that point in time. So that settled on this one. That was a subtle difference that we see, and these are part of what highlights that adaptability and that evolution that Click Fix has in making it non static. We see it grow to trends. We see them focusing on what is more successful in these attacks and how they can. And all of those elements are part of what when we're researching give us not only a better idea of what they're doing, but it does help us to be better at tracking it. So this was need to see just a subtle evolution kind of in how this was growing as we went on through time. Third campaign that we looked at focused on, targeting the reputation of a company called BirdEye, and this one was really interesting. Again, these all follow very much that same attack chain that we observed and showed at the beginning. This one did the exact same steps, asking users to, once again, do a first verification, and then after that, do a second false verification in order to give, the the ability for the threat actor to download the malware. What was interesting on this one was that after a victim had gone through, finished the second false verification, and actually themselves initiated that, malicious download onto their own systems to be infected, the threat actors' campaign actually redirected the victim to the legitimate bird eye page, which was something that we hadn't seen in a couple of the other campaigns we did. This one, you can see on the left at the top, ace bird rep was what was used in the spoof campaign, and that it was not actually at all the domain that is used for bird eye properly. And we tracked across the time on this one about 30 plus, different domains that used bird, as a part of that naming convention. So not quite the type of squatting, but definitely leveraging that familiarity with the word bird to deceive victims into thinking this was a legitimate page. And looking at that redirecting, it was an interesting way to make the user feel or a victim feel safe about what they had just done. They're like, oh, okay. I actually did complete this step. And that wasn't something we had seen. Other campaigns we see after they complete the second malicious step, it just kind of goes back to the beginning and says, well, we need to verify you, and it gets caught in a loop. This one actually sent them to the brand's page, which gives a little bit more of that, we're good here, and the victim is not suspecting as much. So we do see that evolution over time. We do see these little nuances. And, you know, as we go through these, it does layer onto that that click fix wall. The technical side of it as far as how a threat actor might manage their infrastructure can have complexity. What's presented to a victim is not complex. It's very simple. It's very straightforward, and it's very effective as well. As we see with a lot of social engineering attacks, threat actors really try to leverage that fear factor of you have to do this right now and kind of creating that anxiety. This one isn't necessarily creating anxiety. It's giving the sense to a victim that they're safe, and they have to do this to get what they want in a proper way. And that's why we wanted to do this or track this and really kinda leveraging these brands of reputations in order to actually give that is making these attacks very successful across the board, but it's also hurting the brands in the process, which is why it's important for us to track so that we can better protect our customers and find new attacks as they pop up. So in all of this, when we're looking at it, you saw on here there's a number of different aspects that appear over time when we're looking at the different artifacts that appear with click fix. When when we're trying to track it, it's really important for us on a number of different ways, not in just turning out reports, but we're wanting to see not only how large a current campaign might be with Clif Fix, but tracking these different artifacts allows us to see the new and emerging campaigns, infrastructure, and also what these threat actors are using at the end step as far as the malware that they're delivering to a victim. Being able to track these artifacts also too helps us to identify more brands that are being affected, in a very timely manner at that point. The sooner that we can get it, the sooner that we can start to do alerts. In addition to that timeliness, we are able to do and enable better takedowns of these clusters so that they stop targeting victims at a point in time before this gets too widespread. Looking at the malware that these campaigns are delivering at the end of it is important because it gives us better idea of what the threat actors are wanting to do. Are they trying to do delivery of an info stealer so that they can get information off of a victim's machine, potentially turn around and sell that on the dark web later? It's also a easy attack vector and and an infection point for ransomware groups in order to try to get ransomware onto a box as well. And, similarly, is it also an attempt to put down a remote access Trojan? Those are all different aspects that help us categorize what a campaign is and what these threat actors are doing. And that trend over time of how this is being used and who that main malicious threat actor customer is on the dark web as well. And as we track these in addition to seeing the malware that happens at the end, we're able to look at how this attack is growing over time and see those changes and better be able to pivot and track wider and further. So a few of the things that we kind of look at, and we were able to highlight some of these in the reports. And this is just a little bit of what we saw we were going through, but they are definitely elements that we look at and we're paying attention to when we're doing our research is what what's involved in the page, what is going on on the HTML, specifically what is presented in the HTML that's loaded on, the front end on the victim's machine that may not be conventionally seen or something that we can, under a totality of circumstances, if you will, be able to look at. Okay. We have these different aspects. All of these create for us a positive indication that this is actually a malicious site. On the left, you see two commands that would have been put into run or the Windows run and a UNIX terminal respectively. This is actually what is provided to a victim from the click fix system when they are doing that second malicious verification step. One is running PowerShell. It's actually telling, in this case, to run PowerShell quietly in the background in order for it to really reach out to that malicious site and start to download the malware. Second as well is an encoded version with base 64 that's run-in a UNIX terminal and does very much the similar aspect of this. On the right, just a few highlights of things that we can kind of look at that are trackable, but also indicators to us when we're looking at everything combined. We looked we mentioned things such as with the bird domains on the bird eye campaign. That naming convention was something we were able to look at as a strong indicator as a member of that clustered campaign. Other things we can look at in this as well, if we see it happen over time, if they're consistent with their use of, like, a false CloudFlare logo, if that hash appears multiple times, we can begin to look at that as an indicator that this site itself is actually malicious. Different wording that these pages use as well, to better prove you are not a robot. We see all the time, you know, verify you're a human. But to better prove is a little bit newer of a convention that is kind of unique to that second layer of attack. In addition to the other something else I wanted to mention with the two commands that we're seeing on the left since we're talking about what's seen in the HTML, the commands are not commonly seen as something that would be a part of what's presented to a user in HTML. That's an indicator as well that we're looking at, not just the pattern that these commands follow for that malicious attack, but the fact that they're presented in very plain text, on a user's machine. That's something else that is very much a trend. We don't often expect to see echo or PowerShell executable being presented at that point to a user. So with that as well, the variations, the evolutions, and adaptability of this, we've really kinda highlighted a lot of those as we went as we've talked through this already, and we see it very clearly as we continue to grow, especially since this is a social engineering technique that really does rely on victims to be, if you will, the attack vector against their own machines. It's harder to secure against. It's really something that is difficult for a security posture of a corporation, large or small, to really try to to stop more domains that we can provide that say this is actually an indicator of block this or the ability for us to do takedowns or to enable a takedown of these sites to prevent that is huge. But we have seen in other things where when our or, excuse me, in previous attacks, we see it where the instructions that are given to a victim is something like, please use the win r in order to open your run command. We can see it where a lot of corporations go in, like, okay. Well, let's block the ability of one of our user endpoints to use that command. It's very adaptable and is a very simple pivot for a lot of these threat actors. They won't use win plus r. They'll now use win x as the command to open up the prompt enabled to enable that malicious execution. We see it as well that it's growing not only in targeting different operating systems, but we did track one campaign where it was able to actually intelligently deliver, the appropriate commands based on the operating system information that's naturally given to the browser. So if the system was on a Macintosh, a UNIX, or a Windows, it would pivot accordingly and present the proper command and the proper guidance in order to successfully, infect that victim. So we do see them evolving over time and getting more adaptable. All of these artifacts and the ability to track it is one of the awesome things that we've had in this collaboration to leverage tools like HTML analysis, and working with Tristan's team, we're able to see this in a different reality. We're able to track this in a different way using a lot of the information, and we're able to display it to customers in a very different way. And that's made this something very exciting for us and that we can not only do research to write good reports and put good indicators out there, but we're leveraging one of our in house data sources, and we're able to give that information in a brand new light. And that's been something really awesome from us on an analysis side. So with that, I'm going to hand it off to Tristan to dive into a little bit more of what there is on the new click fix detection operation. Thank you very much, Patrick. And I think I would just echo the sentiment that, it's been incredibly helpful to work with your team, learning how click fix works and then being able to scale our detections far beyond, the initial findings. So it's certainly something we appreciate as well. So for the rest of the presentation today, we're gonna pivot a little bit away from what is click fix, how does it work, and more so to as a client of recorded future, as a potential future client of recorded future, how can you operationalize the information that we just talked about today? So the first thing that I would want to mention is that we've invested quite a bit in our detection methodologies in the last let's get the slide here. Perfect. So we spent the last year or two really scale scaling up our detection methodologies quite a bit. We can see that we have the funnel over here starting with our sort of three buckets of discovery and detection. If there's one takeaway that I want you to have from this entire presentation today beyond the wonderful work that Patrick and his team have brought forth, it would be that Recorded Future is indexing, analyzing as much of the content as we can see every day. Our current number sits at approximately 100,000,000 candidate domains and URLs per day. And what that really means is that we're focused on trying to find all of the different sources. So whether that's public data, certificate transparency logs, and domain reg, that sort of most vendors in the space would have access to, indexing that well, indexing it efficiently, but also investing in strategic partnerships and even proprietary discovery cases to kinda build out a full portfolio. As many of the folks on this call may know, you can look at certificate transparency logs, domain reg. You can get pretty far in terms of finding threats on the Apex domain level. But what those methodologies may struggle with is looking at URLs, subdomains, specifically in cases where there's a wildcard certificate or it's it's sort of a web hosting service. We've worked with internal teams, including our attack service intelligence organization, really to focus on proprietary discovery in the subdomain space in the last year. So when you look at the top of this funnel, I wouldn't generalize it to just domains or Apex domains you might find in domain discovery, traditional domain discovery sources. Really, we've, started from the beginning with collections and saying, how can we be as broad as possible, finding the threats that are relevant to your organization, and how can we innovate, discover new sourcing that allows us to close the gaps that are most relevant to your organization? So it really starts with discovery being as broad as possible. Once we go as broad as possible, the next most important thing for your organization is that we filter and prioritize appropriately. We look at the p and I think the other thing to mention here is there are kind of two levels of analytics here. So as we filter or prioritize these candidates, figure out what to analyze, how to analyze them, we end up putting them in two distinct streams. And I think I saw a, question in the comments earlier on sort of about how does this tie to your organization. This section sort of answers that. So when we get a candidate, we analyze it. We have two tracks. So first, we look at the page content. And in the next slide, we'll talk about some of the methodologies on how we do our predicting. But at a high level, we we split it into multiple tracks. We figure out that the page is bad based on the content, and then we use screenshot analysis. So looking for OCR, object character recognition, looking for strings referring to your brand, or using machine learning, logo detection models to say your logo is definitely in the top left corner of that page. Really, the power of this pipeline and what we've been able to do in the last year and a half, two years has been splitting those two tracks and then being able to join those together. As we get we'll get to see later in the slides, that's kind of the core tenant of how our malicious sites detection works. So the last thing I'd mentioned here is there's a lot of good things that happen in digital risk protection as a function of this pipeline, but there are a couple different places as well that will you you'll be you would be able to see even if you weren't a DRP customer with Recorded Future. So we'll make sure that we hit on those as well. So going back to what Patrick Arnold said a little bit, click fix detections change over time. Threat actor behavior changes over time. How does recorded future stay up to stay up excuse me. How do we stay on track with threat actors and their changes? And, really, it starts with aggregating different methodologies for sort of different tiers of, threats. So as Patrick and his team mentioned, there are ways that we can effectively signature query our internal indices to say, what's a part of this campaign? As part of that pipeline that I mentioned before, again, well, over 100,000,000 candidates today, when something goes through that pipeline, all of the signatures that Patrick's team have written related to their research, to the one that we saw today, all of the other ones, those are automatically assessed as they come in. So we did a scan. It matches their signature. That's gonna be, added to the Recorded Future intelligence graph. The domain or URL will have risk score. And that's sort of the the tightest way that we can do this. When our when our researchers have a signal we should pay attention to, we start with that in this pipeline. Kinda moving beyond that, we have to think about notions of similarity in machine learning. So threat actors change their behavior over time. Sometimes it's a very subtle difference. Sometimes it's very large. Often, we observe that it's small changes that if a signature is written in a very brittle manner, the tracker can evade you. That's why we started have started to rely on similarity matching. That is if we've seen a bad website, we have a fingerprint for that page content. As scans continue to come in, what we're gonna do is make sure that the page, does or doesn't look like that. The page looks like a bad site based on what we already have in our database. We're gonna surface that information to you in the intelligence graph. The thing I would mention here is we already have thousands of templates that automatically run through this. So it's a way for us to really scale beyond, writing signatures ourself by looking at similarity. We know something that's bad. We make sure that we continue to propagate that risk. I think that I would slip in here. When you are a client with takedowns with Recorded Future, very important signal that we get is whether or not a takedown is successful, whether or not it was valid. When one of those signals comes through Recorded Future, we can then use that information to go find campaigns for you. That is you took down a website. We know the fingerprint of the bad website. We automatically add that to our detection system. That'll and that has led to, in the last three, four months or so, a tease amount of success for several clients who kind of observe campaigns directly targeted at their organization. And the benefit to leaning on similarity as opposed to purely looking at signatures is now we've kind of gone from someone has to research and validate their claims to us having an automated system that says this was a bad site. We validated that it was bad. We validated it's not a false positive, and let's go continue to hunt for that. So similarity is kind of our next step up. And the final one, it it really goes back to classical machine learning. So we have signatures. We have similarity. We have a very strong understanding of what's sort of marked bad in the world. We know what isn't marked bad in the world. We have then used that to deploy a few models. We have two more that are sitting in the final stages of testing right now, looking at a few different, buckets of risk. But, we really use machine learning as that next layer to abstract again, going from a signature to it looks like something else to using that broadest form of it might not exactly match. It might not be highly similar to a previous threat, but there are certain characteristics, that make that domain suspicious or malicious. So, again, we really apply we lead with the Insikt research, lean on to our experts. Now what we've done is try to scale that in different ways to give you sort of a comprehensive way to, observe threats in your, in your environments as well as the external environment affecting your clients. So I wanted to take it back a step for one moment, kind of going back to Patrick Arnold's research, the team's research, looking at one of the examples that we had in the paper. So on the discovery so this is one of the domains. You see the screenshot at the bottom of the page, sort of how that propagates through our pipeline. This particular example happened to be there was a new certificate registered for the domain. We were able to pick that up. We then passed that through our pipeline. It was a new domain. We hadn't seen it before, so we did our content analysis. As we can see in the middle of the page, the HTML came back as bad. And then going specifically to the question in the chat, it's then joining the fact that we have this HTML content analysis event with the fact that the screenshot very clearly uses a company's brand. When we have these two data points, we're able to join those together. I'll talk about that a little bit more with DRP. But at a high level, it's it's taking two tracks, focusing the analytics on what they're going to be good at, and then aggregating that information and joining it in a useful manner. So this is great example, I think, of how Patrick Arnold's team was able to sort of benefit from this pipeline that you as the client or prospective client can benefit from as well. Before we get into DRP, digital risk protection, I did wanna call out that if you're using cyber ops or a threat module, there are a couple different ways that you or other modules. There are other ways for you to interact with this data. So recorded feature maintains threat lists. These are indicator lists that meet certain criteria. The click fix domains will end up in our malware delivery rules. So if you use our risk list, threat lists, that would be one place to look at this data. And the other one is collective insights. So this is a capability we use. It's effectively taking the the logs from your organization, so Splunk, XOR, and the like, and joining that to the Recorded Future Intelligence Graph, enriching those events. At at a high level, let's say someone in your organization happened to go to one of these websites. Insikt Group is sort of the feature that allows you to enrich, analyze, and go from that detection to action. Bringing it back to the platform, one more thing I'll mention is there's actually a dedicated resource research center in the platform as well. It's on the left side of the platform right in the drop down menu. But if you enjoyed this webinar and you really wanna just go dive into some of the work that Patrick and his team have done, open up that tab. As you can see in the middle of the screen, you can filter to a specific entity, attack vector, malware, and so forth. So if this was something that you're particularly interested in, you are certainly welcome to, go read up as well. So sort of back on topic with digital risk protection, we're gonna walk through sort of the malicious websites model for the next couple of minutes, and then I'll give you a very brief overview of sort of the other capabilities. But I wanna leave that open for a webinar we're doing next week. More on that in a minute. So before we talk about malicious websites, what is digital risk protection? This capability that we released last week, it's really about centralizing your different digital risk workflows. So this is finding the risky mentions of your brand across the Internet, and giving you context to act on it as quickly as possible. So the critical thing here, there are five different use cases. I'll talk about malicious sites most predominantly. But our goal is really to have comprehensive protection across dark web forums, across, Telegram, across social media platforms, and across sort of the broader open web along with your code repo, use cases. The point is this is really a one stop shop. And as we can see on the call out on the slide, that that really is number one with this release is not only do we reinvest in our data pipelines to make sure that you have the highest quality data actionability, but or data with those actionability, but also making sure that it's easy to use, intuitive to use, and that you can actually take action as opposed to sifting through data. We have basically what we call the alerts and detections model. At a very high level, detections are telling you that there's something relevant to your organization. But through the individual use cases and prioritization and analytics on top of those, including our AI triage agent, that's sort of what allows you to go from this might be a mention of your brand to this is a click fix domain that is also using your brand. You should probably go take that down. And just so I don't glance over it, one of the sort of keystone features in this analysis pipeline across all use cases, there are two currently deployed right now. The rest will be covered this fall. But it's really leaning on this AI triage agent. We've invested as much time as we can in piling up assessments so that there's rich context for the agent to make those decisions to elevate critical things to you. And so far, we've gotten great feedback. Highly encourage you if you're a current client, take a chance, or a current client, highly recommend you take a shot at a trial. And if you're a prospect, highly highly recommend you reach out for a POV. It's completely revamped from what we had with our previous brand module, identity modules. So speaking of revamping, how do we go from volume to value of malicious sites? So going back to what I had said before, it it really starts with broad sourcing. We reinvested in our detection pipelines, making sure that we can cover sort of traditional cases that Recorded Future leaned on such as typosquatting, and then joining that to our rich collection of phishing sites that come from not only the pipeline that I mentioned today, but the other sources, within the Intelli2Graph, both first and third party. And, really, the trick with our broad sourcing, again, is finding everything that matters, joining those two relevant cases, and then being able to prioritize on top of it. So as we look at bullet number two and sort of the middle of this funnel, I'd say the most critical component here is taking your organizational context. So So whether that's your watch list, whether these are the custom keywords you may or may not add to these detections, whether it's a custom prompt that you add to the AI agent, all of those components help inform risk, not just in a vacuum, but what's relevant to your organization. I believe we found several cases where folks are going from thousands of detections a day to a handful of alerts. And when I say handful, ten, five, ten, fifteen, something like that, really able to distill the noise away. Number three, as we look at it again here, really, it's the the AI agent has been critical in allowing us to, continue to work on that filtering. And the last thing I'd mentioned is in malicious sites specifically, we have one click takedown. So if you have takedowns purchased with recorded future, this packet, because we've sort of already put it together, can automatically propagate that to the takedown provider, make it very simple for you. If you don't have takedowns with recorded future, we also have a button for you, and that'll give you a nice export you can give to whoever the takedown provider is. Really, again, just to focus on the workflow and the data pipeline for you. That's that's what we're offering with malicious sites. Perhaps the last thing I would mention while we're on this slide as well, because I I put the word typosquat on here. Historically, with the domain abuse offering, the focus was treating a domain as an entry point. So that's saying that Recorded Future+1character.com is a type of squad of your organization or a similar domain. Maybe there's a substring match that you particularly care about. Malicious sites does cover those use cases as detections, but, really, we lean into the, analytic pipeline, the HTML content analysis, all of the other components that I've mentioned, including logo and OCR, sort of help you appropriately, prioritize those cases. So militia sites comprehensively serves as a replacement to domain abuse in a number of legacy alerts for logo and OCR, sort of by consolidating, and reinvesting in the analytics that help drive takedowns for you. Just to bring it to life for you for a moment, here's a screenshot of an example alert that we have in the platform. As we walk through sort of what I was describing before, the entry point for this particular alert is that there's a logo detection. That's your, second bubble from the top. So we detected this particular brand's logo on a page. That was the entry point to say, this might be a suspicious website. We then join that to the HTML content analysis data. That lets us say, not only is this using your brand, but it's actually doing something peculiar. You can then click into the, you can click into the analysis report, all these other things from that alert. In this particular case, I believe it was a fake shop or something like that based on the the fraudulent content TTP. But the point really is we have the high interest logo detection to say this is your brand. We have the phishing scam malicious data. We join those together, pass it to the agent, and it says you should absolutely go take this down. Generalizing back to the original question, it works exactly the same way if it's a click fix case. So you're gonna see that there's phishing scam data associated with the data packet. And if it's relevant to your brand, logo and OCR are gonna bring that detection into your, organization. Let's see. Yeah. We'll talk about malicious sites for one moment here. I I saw one question I wanna hit on at the beginning of the QA. So, Kyle, we'll we'll get to your question first in the QA. But before we get there, malicious sites is really just the tip of the iceberg with digital risk protection. We have, again, four other use cases already released. The AI triage agent being expanded to more of the use cases is something that we're focused on doing this fall. But, again, the portfolio is leading with your with your assets that are relevant to the brand and making sure that we can comprehensive look for those. So whether it's looking at dark web mentions, again, on Telegram, dark web forums, impersonation of executives or companies on social media platforms, code depository mentions, so leaked keys, suspicious references to your organization, source code, or, of course, this this traditional malicious site sort of use case. We're on top of our existing identity intelligence module looking for exposures relevance to your org so that if a credential is leaked, you can make sure that that's taken care of, preventing a much larger situation. Really bringing all these capabilities together to protect your work in a one stop shop is what TRP is all about. We'll have a webinar in a week. Maddy will tell you more about that in a moment. But if any of this sounds interesting to you as a client or client or prospect, I highly recommend that you try and take a trial. It's a completely different experience from what we've had before, and the early returns from clients who have taken that leap have been extremely fruitful. So I think that's all we've got moving to QA. But, Kyle, if I could hit your question first, because I think that's a it's a great question as we relate to our collection pipeline. Pipeline. So looking at sort of different domains, or rather where do I put this? Our our collection pipeline, our objective is sort of to be domain agnostic. And what we mean by that is we go as broad as we can on sourcing. So wild card looking at wild card certificate cases in our subdomain discovery, looking at different URL sources for, iffy cases where you actually need a token or something else in the URL string to get the desired content or our traditional use cases. Again, DomReg, CTL data. Really, our objective is, to be domain agnostic, be as broad as possible. So I would say that seeing shifts to a particular TLD tends not to be a huge problem with kinda how we've changed this, how we sort of changed and reimagined our collection. As we see sort of new trends or particular gaps that we might have in sourcing, we work with our attack sir attack surface intelligence organization, and a few other teams internally to sort of figure out how we can go expand discovery in those cases. But for the most part, I would say that we're quite comprehensive in that regard, and as threat actors swap over to different TLDs, for the most part, we already have that covered, and we tend to see those trends over time, as they come in. So I'll give it back to Maddy for the rest of the QA. Yeah. We're getting a couple other great questions in the chat. This one is if record feature detects malicious site, is it possible to request the site to removal a takedown through Recorded Future? Just I don't know if you wanna take that. one. Absolutely. So, yes, we offer a takedown product. As I had said to kind of in the the previous slide, a big part of the workflow with malicious sites just going back to the slide for a moment. Yeah. This is a great spot. most critical part here is that you can actually take action. So if there's a click fix site that's using their your brand, yes. You can absolutely go take that down using recorded future. I recommend that you reach out sort of your to your account manager to make sure that, if that's something you're interested in, that's part of your license that you can kind of enjoy. Enjoy that feature and keep your organization, in a safe spot. Yep. And then, back to the collections, I kinda have, like, a two parter on this. So with the 100,000,000 source coverage, right, that we start with, like, first, I guess, is this, how does this sort of set us apart from some of the other competitors in the industry? And then also with the collection, does it adjust targeting methodologies based on, like, risk and threat patterns as well? It's kind of a double whammy there. Yeah. So I guess two components there. We'll start with the how do I put it? The target methodologies. Collection is intentionally broad. Yeah. We we we really collect as broadly as possible. And then once we have that information so the analytics do evolve over time. We're we're talking about moving to sort of similarity or machine learning. The signals are a bit fuzzier perhaps to to you and me as the humans looking at it versus, a signature or a query that's incredibly easy to discern compared to looking at model weights. But, over time, I wouldn't say that our collection methodologies change. I'd say we always try to be as broad as possible. The methods that we use to, you know, risk score domains change over time, and we intentionally balance sort of human in the loop with automation, so that we can have a comprehensive but also maintain the quality of the things that we're detecting. The one thing I would say is if we see that our collection system is struggling with, picking up information in the first place, under certain circumstances, that's something we monitor and make sure that our, indexing system, is trying to stay ahead or at least on pace with the threat actors. So I'd say, collections wise, we don't really change the domains too much, unless we start to see trends that we're willing to add those. But we do invest quite a bit in the analytics and the systems that allow us to, see those websites in the first place. There's a second question there, Maddy. Right? Yeah. More just about the, like, breadth of the coverage. Right? How does that compare to what maybe some competitors are doing? Yeah. So I think the in going back to that original slide, I kind of denoted proprietary sourcing, public sourcing, and sort of partner sourcing. Without going into too much detail, there are certainly some sources, such as the certificate transparency log data, that most competitors, most folks in the space definitely start with as a basis. We obviously use that. We use that as a core of our detection. But, really, what we've been leaning into the last year has been optimizing URL detection, finding the novel and interesting places where threat actors are deploying their attacks so that we can get the right tokens so we're not blocked when we just look at a an Apex domain or something like that. No. I think the other part too is subdomain discovery. Our attack surface folks have done really a tremendous job on what's a very difficult problem. If I don't have a certificate for something, if I don't have sort of an artifact in a more easily accessible stream, I mean, yeah, it's an incredibly difficult problem to try and get every subdomain in those cases, but we have a dedicated team of folks, who are taking client feedback, looking at research in the sort of in the industry, and bringing that all together to not only, you know, deliver what's in the public space very well, but actually have many different sources, cross pass at DNS, other different sorts of methodologies that allow us to be comprehensive in the places that you that the threat actors want to hide. So I would say it's starting with a core competency on what's out there, your CTLs and similar, and that's augmenting it in the places that matter, and having dedicated resources to do that on a continuous basis. Yeah. Great. Okay. I think that's a great segue into, a lot of these questions. A lot of these things will be brought to life within this webinar that we've been teasing a little bit for next week where you'll get to see a live demo of digital risk protection. So you'll actually find the link right in the chat as well sent from Kathleen. But please please please, as Tristan said, if this has been interesting to you to dive into more of these digital risk protection capabilities and see how we start with this large source of collection and then filter it down into, eventually take down worthy, you know, alerts, I think you should definitely join. It'll be worth your time. And then I wanted to also include since digital risk protection is brand new as of last week, we have tons of customers that have already started enabling it and starting to get adjusted to this new experience. But, yeah, I see the excitement in the chat too. So we're super excited that it's been very highly adopted and activated, and people are having great experience. But we wanna support you through that as well, so please join our office hours coming up in September as well. Look out for those invites coming soon so that you can feel continue to feel supported through this transition because it is a big change, but it's a good change. So we're very excited to be bringing this to you all. I did see the question come up a couple times of is this recorded, and is will the slides be available? The recording will be shared with you all. It should be shared out within at least twenty four hours. So just keep an eye out on that. This was recorded, and you will be able to refer back to this presentation because I know there's a lot a lot of goodness within there from both Patrick and Tristan. With that, any closing remarks, Patrick, Tristan? I think I would just slip in. I saw a few questions about managed takedown services. Vocoder feature does have a managed monitoring offering as well. So when we talked about takedowns in the abstract, if that's something that you don't wanna take on in your organization, you'd like for Recorded Future to do that for you. That's something that we offer as well. So it's very much not just the button platform. Reach out to your your account team sort of to get set up there. But, yeah, manage takedowns. If you have questions on sort of the methodologies there, I think I saw a few of those. Again, I'd recommend you reach out to the to your account team, look at our support pages, and certainly go from there. We want you to do takedowns on malicious sites. So whatever you need to be successful in that regard, that's what we're here to do. No. Absolutely. Just a couple of things on that one. I think I saw a couple of things at the beginning. I wanted to touch real quick on click fix. I apologize. I didn't see the channel as I was going. Couple people mentioned the copying from user when they're given that second level of malicious verification. That's actually something that's interesting and we can see as well. There's actually no copy from a victim on this one. It's a command that's actually done, on the front end presented, and it happens behind the scenes where that malicious command is automatically put in a victim's clipboard. So there's actually an interesting thing on the attack. So they never really see it until they're getting ready to execute it. But I did wanna kinda circle back from my second point here as well. I know a lot of people mentioned the the different things that we're tracking. Tristan Tew talked about it wonderfully with the way they keep that aperture open. We do the same in our research as far as the way we're looking at it and the validation steps we go through when we're doing that. And I think it just really highlights from the research and analysis portion the exciting nature of just how it is that we get to collaborate with these other teams for things like the HTML analysis and, DRP to be able to really take our research and help in help that be enriched in this other way. And that keeps that communication going, I think, to help it grow as well from what we see and to pass that knowledge on firsthand when we're seeing it. So that's really exciting nature that I see in this, and it's been an awesome relationship to have building up to this as well. Great. Yeah. Thanks for bringing that, back up and addressing those those sort of last minute questions that I might have I might have missed in the queue. So appreciate you guys getting to those. That is where we will leave you. We have rounded out the webinar. I think I think there's a lot of great takeaways, and we appreciate you guys rolling through this with us. But, hopefully, this was worth your time. I think it definitely was, But please stay tuned for the recording and more to come, and, hopefully, we'll see you next week on the demo. Thanks all.