Offensive Threat Hunting - Tracing The Cyber Criminals Behind a Phishing Campaign

The associated user profile indicates a long-standing online presence, with an account creation date dating back to 2010 and a more recent update within the past year. While this demonstrates sustained use of the identity over time, it does not in itself provide conclusive evidence of involvement in phishing activity. Such temporal OSINT indicators may be useful for contextual enrichment, but they must be correlated with stronger technical and behavioral evidence before drawing attribution-related conclusions.
During security operations at a confidential organization, I identified a suspicious email flagged by SentinelOne, targeting the company’s CEO with a request to modify bank transfer details to redirect funds to an attacker-controlled account. Within minutes of initiating a detailed investigation, I began an incident response workflow to determine the scope and intent of the activity.
Further analysis confirmed that the incident was part of a coordinated phishing campaign. The adversary leveraged a malicious domain, “trust-reins.com”, which served as the initial pivot point for threat hunting and intelligence gathering.
Using the indicators of compromise (IOCs) extracted from the email and associated telemetry, I conducted a structured threat intelligence investigation to map infrastructure, identify related artifacts, and trace the broader campaign. The following outlines the techniques and methodologies applied to attribute and track the activity across the adversary’s infrastructure.
DNS Resolving for the Phishing Domain
I was able to identify the resolving IP address associated with the phishing domain by performing a basic DNS resolution using a simple ping request against the domain. This initial step provided the first infrastructure pivot point, enabling further enrichment and analysis of the adversary’s hosting environment.

After resolving the domain to its associated IP address, I leveraged the threat intelligence platform Censys to conduct deeper infrastructure analysis. This allowed me to enrich the initial indicator with contextual data, including exposed services, host metadata, and potential links to additional malicious infrastructure associated with the adversary’s campaign.
After resolving the domain to its associated IP address, I leveraged the threat intelligence platform Censys to conduct deeper infrastructure analysis. This allowed me to enrich the initial indicator with contextual data, including exposed services, host metadata, and potential links to additional malicious infrastructure associated with the adversary’s campaign.

Further analysis of the infrastructure revealed that the primary resolved domain associated with the phishing activity was “gogohost.com”, which appeared to be hosting the phishing content.
Upon closer inspection, this domain was identified as a deliberate impersonation of the legitimate hosting provider “gogohost.co.uk”, likely designed to deceive victims and lend credibility to the phishing campaign.
This discovery provided a critical attribution pivot, linking the adversary’s infrastructure to a lookalike domain used to support social engineering efforts and reinforce the legitimacy of the fraudulent email chain.
Cyber Threat Intelligence Analysis Section
I went through some indicators which were found in the investigation. The adversary has impersonated the real ‘gogohost.co.uk’ with the ‘gogohost.com’ which behaves as a hosting server with almost all the services running including cPanel.
(This is the legitimate gogohost.co.uk hosting service Website)

This appears to be an impersonated website and does not provide any visible web-based interface for legitimate hosting services. Instead, it functions as a minimal or non-interactive infrastructure endpoint leveraged by the adversary, further indicating its role as part of a malicious hosting setup rather than a genuine service platform.

After conducting further investigation, I was able to identify registration details associated with the impersonated domain used in the phishing campaign. The domain registration information indicated a user identifier associated with the name “willy”, which appeared in the domain’s registration records.
This detail provided an additional attribution signal, helping to further map the infrastructure and supporting entities involved in the phishing operation.

From the analysis of the email artifacts and associated registration data, I identified that the same email address had been used to register a total of seven domains. These domains were all linked to the same infrastructure pattern and appeared to be part of a coordinated phishing campaign operated by the same threat actor.
This clustering of domains strongly suggested a structured and reusable setup, indicating that the adversary was systematically creating multiple impersonation domains to support a broader and more sustained phishing operation.

As the initial compromise originated from the “trust-reins.com” domain, this investigation further confirms that the infrastructure extends beyond a single phishing endpoint. Analysis of related indicators revealed multiple additional domains hosted under the same campaign, indicating a broader and more distributed phishing infrastructure operated by the adversary.
This pattern demonstrates that the threat actor maintained several parallel domains to increase campaign resilience, evade detection, and expand the attack surface beyond the initially observed entry point.

To validate these findings, I cross-referenced the seven identified domains using VirusTotal intelligence. The analysis confirmed that these domains are consistently flagged across multiple security engines and threat intelligence feeds as being associated with phishing activity.
This corroborates the initial hypothesis that the infrastructure is not isolated to a single domain, but rather forms part of a broader phishing campaign leveraging multiple domains to increase reach, persistence, and operational redundancy.
Offensive Operation Towards the Adversaries’ Infrastructure.
While investigating the incident, I took the approach of an Ethical Hacker to compromise the infrastructure of the adversary in order to get some information about the person behind the campaign.
Overview of the phishing Websites
All the phishing Websites are made with wordpress, which is a Content Management System used to build landing pages and Ib applications using drag and drop utility. Fuzzing the endpoints of the domains found that all the Ibsites had “wp-json” file and the services running in the hosting platform was plenty.

The number and nature of services observed on “gogohost.com” appear suspicious and inconsistent with what would typically be expected from a legitimate hosting provider. The exposed service footprint suggests a deliberate attempt to mimic the branding and functionality of the legitimate “gogohost.co.uk” platform.
However, the configuration does not align with normal production hosting environments, where service exposure is usually minimal, well-structured, and professionally maintained. Instead, the observed setup indicates potential infrastructure staging or impersonation, likely designed to support phishing operations rather than provide genuine hosting services.

Exploitation of the Wordpress site
I conducted a server security assessment on the phishing Websites and was able to successfully find vulnerabilities on the website.

Further analysis of the identified WordPress-based sites revealed multiple security weaknesses and misconfigurations, which are inconsistent with professionally maintained infrastructure. These issues suggest that the environments were rapidly deployed and poorly secured, aligning with patterns commonly observed in phishing-related staging websites rather than legitimate hosting platforms.
In addition, during the technical review and crawling of the infrastructure, server-side metadata indicated a timezone configuration set to “Africa/Cairo”. While this does not provide definitive attribution, it serves as a supporting indicator that may suggest the operational origin or administrative environment associated with the deployment of these sites. This observation contributes to the broader contextual understanding of how and where the phishing infrastructure may have been provisioned.

During the review of crawled pages across the WordPress infrastructure, I identified a username embedded within one of the blog entries. Using basic open-source intelligence (OSINT) techniques, I was able to further analyze this artifact and correlate it with external references.
This correlation provided strong indications that the adversary was attempting to impersonate a real individual or identity in order to increase credibility and establish trust with potential victims. This social engineering element further reinforces the phishing nature of the campaign, where both infrastructure and identity spoofing were used to enhance deception.

The email address “willy@gogohost[.]com”, along with the name “Farkouh” discovered within the phishing infrastructure, appears to correlate with previously identified registration and web artifacts associated with the campaign.
This overlap suggests a potential link between domain registration details, hosted content, and identity references embedded within the phishing pages. However, it is important to note that this correlation alone is not sufficient to definitively attribute the activity to any specific individual. The use of potentially stolen, fabricated, or impersonated identities is common in phishing infrastructure, and attribution should therefore remain cautious and evidence based.
As such, while these indicators strengthen the understanding of the campaign’s structure and possible operator identities, they do not conclusively confirm whether the named individual is the actual threat actor or themselves a victim of identity misuse.
The profile of “William Farkouh”, who is recorded as having earned a degree in Pennsylvania, United States, presents a geographical proximity correlation when compared with the infrastructure region associated with the hosting services used in the campaign. The estimated proximity—within approximately an eight-hour travel range—adds an additional contextual layer to the investigation.
Additional Intelligence
However, while this may appear as a meaningful geographic alignment, it is important to treat this strictly as a supporting OSINT observation rather than attribution evidence. Threat actors frequently reuse, spoof, or arbitrarily select identity data and infrastructure locations, meaning geographical proximity alone cannot be used to establish operational responsibility.
Overall, this detail contributes to the broader intelligence picture, but attribution must remain based on a combination of technical indicators, infrastructure linkage, and corroborated behavioral patterns rather than location-based inference alone.

North Carolina is where the “gogohost.com” domain was hosted. Coming across few other intelligence the I found, I would like to say that the user “William Farkouh” is an impersonated person who is not related to this phishing campaign but a person who goes by the name “Walaa Henein” is the one who has impersonated the previous user and used his name to register all the domains and the websites who thought to be lived in “Egypt”.

The above user has 2 linkedin pages one represents that he is the founder of “gogohost” which is the not the real hosting server and the next he represents himself that he is working as a systems admin in a telecommunication company.

The user profile associated with the identifier shows a long-standing online presence, with the account originally created in 2010 and a recent update within the past year. While this indicates sustained usage of the identity over time, there is insufficient evidence to directly associate this activity with phishing operations. Such temporal characteristics may be relevant in contextual OSINT analysis, but they should not be interpreted as proof of malicious intent without supporting technical or behavioral indicators.
Conclusion
Based on the analysis, I have determined that this is not a targeted phishing campaign but rather a long-term operation conducted by threat actors originating from Egypt, aimed at harvesting users' personal information. While the campaign does not appear to focus on specific individuals or organizations, its persistence and scope warrant proactive mitigation measures.
.