Common signs include large clusters of lookalike hostnames, rapid domain turnover, IPs tied to fraudulent trading or gambling sites, and wallet activity that clusters around service providers instead of legitimate users. Investigators should also watch for links to hosting, domain management, and payment infrastructure that consistently reappear across separate scam campaigns.
Infrastructure patterns that separate isolated scams from organised pig butchering
pig butchering operations depend on reusable infrastructure, not just persuasive messaging. That means the telltale signs are often visible in the supporting stack: domain registration churn, short-lived hosting, shared certificates, recurring nameserver patterns, and payment or wallet activity that behaves more like a relay network than ordinary customer use. These patterns matter because they let investigators move from one suspicious account or site to the wider criminal ecosystem. For a broad control view of how organisations should secure and monitor such infrastructure, NIST SP 800-53 Rev 5 Security and Privacy Controls is a useful reference point for logging, monitoring, access control, and system integrity. In practice, many teams only recognise the pattern after several apparently separate scams have already been linked by the same hosting and registration choices.
How scam infrastructure shows up in practice
The infrastructure layer usually reveals itself through repetition and operational convenience. Scam operators prefer assets that are easy to replace, difficult to attribute, and cheap to spin up in volume. A single domain may be disposable, but clusters of domains often share the same registrant data, privacy service, DNS provider, TLS certificate style, web templates, or analytics tags. Those overlaps are valuable because they create a correlation surface across otherwise unrelated reports. The same logic applies to email, chat gateways, and redirect chains: if a campaign keeps reusing the same delivery and landing infrastructure, it is usually optimised for scale rather than long-term legitimacy.
Investigators also look for behavioural mismatch. Legitimate businesses tend to have steadier asset lifecycles, clearer ownership trails, and less dependence on constantly changing endpoints. Scam infrastructure often shows faster replacement cycles, unusual concentration in a small number of hosting providers, and abrupt migration when blocks or takedowns occur. Wallets and payment rails can echo the same pattern when they are used as temporary pass-through points rather than end-user accounts. Where the infrastructure is being operated as a service layer for many victims, the same domains, IP ranges, or payment touchpoints may reappear across multiple campaigns even when the messaging, branding, or victim profile changes. That is the key analytical shift: the scam may look personalised at the front end, while the back end remains highly standardised.
- Cluster domain registrations, hosting, and certificate data to find reuse across separate complaints.
- Compare DNS and IP churn against the expected lifespan of the alleged business.
- Look for redirect chains, mirrored pages, and repeated templates that suggest a shared kit.
- Correlate wallet or payment infrastructure that behaves like a servicing layer rather than a normal customer flow.
Where this guidance breaks down is when operators deliberately compartmentalise infrastructure so aggressively that each scam instance appears unique unless multiple investigative sources are combined.
Common variations and edge cases
Tighter attribution analysis often improves confidence, but it also increases the time and data needed to distinguish a criminal service layer from ordinary shared internet infrastructure. That tradeoff matters because some signals, such as common cloud hosting or popular privacy services, are legitimate on their own. The question is whether the combination of signals is operationally coherent for a scam, not whether any single indicator is suspicious in isolation.
One common edge case is legitimate marketing or affiliate infrastructure that can resemble scam routing because it also uses redirects, short-lived pages, and frequent campaign turnover. Another is the use of rented infrastructure in regions or sectors where rapid provisioning is normal. In those cases, analysts should treat the repeated co-occurrence of domains, wallet activity, and hosting patterns as more important than any one artefact. There is also a consensus gap in how much weight to place on infrastructure similarity alone versus victim testimony, transaction evidence, or content analysis. NHI Management Group treats infrastructure as a strong lead, not a standalone conclusion, because criminals can copy surface patterns faster than they can copy the full operational context.
Risk and Threat Considerations
Scam infrastructure is risky because it creates scalable reuse: once the supporting domains, hosts, and payment routes are established, they can be repurposed across many victim-facing campaigns. That concentration increases the blast radius of a single compromise or takedown and can also hide a broader operation behind what looks like isolated fraud.
Failure mechanism: Operators exploit fast provisioning, disposable domains, layered redirects, and shared payment touchpoints to keep campaigns resilient and hard to attribute. The same infrastructure pattern can survive content changes, branding changes, or partial enforcement action because the underlying service layer remains intact.
Impact: Investigators may miss campaign linkage, victims may be routed through trusted-looking but transient assets, and defenders may underestimate the scale of the operation. The practical result is slower disruption, weaker attribution, and a longer operating window for the fraud network.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1583 — Acquire Infrastructure | Pig butchering relies on reusable scam hosting and domains. |
| T1584 — Compromise Infrastructure | Fraud infrastructure may be hijacked or repurposed to sustain campaigns. | |
| Recommendation — Map shared hosting and domain patterns to T1583 and hunt for staging reuse across campaigns. Track evidence of compromised websites or services used to route victims and fraud traffic. | ||
| CIS Controls v8 | 8 — Audit Log Management | Repeated infrastructure reuse is best exposed through logs and correlation. |
| 9 — Email and Web Browser Protections | Pig butchering commonly uses web delivery and redirect infrastructure. | |
| Recommendation — Centralise logs from DNS, hosting, email, and payment systems to correlate scam infrastructure reuse. Use web and email protections to block malicious redirects and rapidly changing scam endpoints. | ||
| NIST CSF 2.0 | DE.CM — Security Continuous Monitoring | Detecting scam infrastructure depends on continuous monitoring of external-facing assets. |
| Recommendation — Continuously monitor domain, hosting, and transaction signals for repeated fraud infrastructure patterns. | ||
Practitioner Guidance
What to prioritise: Prioritise infrastructure correlation before you focus on message content. The most useful investigations often begin by linking domains, certificates, hosting, DNS, and wallet behaviour across cases, then using those links to narrow the campaign family.
What to verify: Verify whether the same infrastructure appears to be serving multiple campaigns, whether endpoint churn is unusually fast, and whether the payment or redirection layer is stable even when the victim-facing branding changes. Those are stronger indicators than any single suspicious domain name.
Practitioner takeaway: Treat the infrastructure layer as the campaign’s operating system: if it is being reused, the apparent novelty of each scam is often cosmetic rather than operational.
Related resources from NHI Mgmt Group
- Who is accountable when illicit marketplaces support large-scale scam operations?
- What breaks when investigators focus only on victim wallets and ignore the infrastructure behind pig butchering schemes?
- What are the signs that AI infrastructure is being used for unauthorised model abuse?
- What are the signs that cloud infrastructure is failing to support strategic initiatives?