Join our Newsletter — 33% off our NHI Course

How should fraud teams investigate phishing-as-a-service networks that receive cryptocurrency payments and use infrastructure providers?

Fraud teams should trace the money, the tooling, and the service layer together. Payments to phishing-as-a-service operators can reveal wallets, cash-out points, and links to exchanges or mixers. That evidence helps connect phishing kits, hosting, email infrastructure, and downstream victims into one operational picture. The practical goal is to identify repeat infrastructure, disrupt monetisation, and support law enforcement action.

Tracing the operation from payment to infrastructure

Phishing-as-a-service investigations are most useful when they treat the operation as a supply chain, not a single scam page. The payment trail can expose where the service is monetised, while the hosting and delivery layer can reveal repeat infrastructure, reseller patterns, and the providers that make the campaign resilient. That combined view is what turns isolated incidents into a reusable investigative set.

Cryptocurrency payments rarely identify an operator on their own, but they do create structured leads: wallets, clusters, cash-out behaviour, and links to exchanges or conversion services. When those leads are correlated with domains, certificates, mail infrastructure, and hosting providers, analysts can separate disposable phishing pages from the longer-lived service layer that keeps the network running.

Because the infrastructure is often outsourced, teams should look beyond the immediate phishing kit and ask who is enabling it. A phishing platform may rotate domains quickly, but its payment rail, hosting pattern, registrar behaviour, and delivery tooling can stay stable enough to support attribution and takedown. That is where repeatable evidence usually emerges.

What the infrastructure provider layer tells investigators

Infrastructure providers matter because they can reveal operational continuity. The same attacker may move between hosts, but the same preferences for uplinks, DNS behaviour, reverse proxies, content delivery, or email delivery services often reappear. Those preferences can help connect campaigns that would otherwise look unrelated.

Useful investigation points include hosting accounts, abuse-report history, IP and ASN relationships, domain registration patterns, TLS certificate reuse, and any service-layer dependency that shows how the phishing operation is assembled. A provider may not be complicit, but it can still be a valuable pivot point for identifying related tenants, shared control, and the repeatable parts of the network.

For teams investigating the service layer, Service Account Security Guide is a useful reminder that stable operational access often survives even when visible assets are churned. The same principle applies here: the durable control plane is often more informative than the disposable front end.

How to turn leads into an actionable disruption plan

Effective investigations prioritise correlation over volume. A single wallet or host is rarely enough, but a pattern that ties payment, phishing kit reuse, and infrastructure repetition together can support escalation, law-enforcement referrals, and coordinated takedown requests. The best outcome is not just attribution, but disruption of the operator’s ability to collect and redeploy quickly.

Teams should preserve evidence in a form that supports chain-of-custody and partner action, including timestamps, wallet addresses, transaction hashes, domain and hosting records, and screenshots or captures of the phishing workflow. If the same service layer is repeatedly used across incidents, that evidence can justify broader containment, intelligence sharing, and provider engagement rather than one-off cleanup.

Fraud response also benefits from an identity and access perspective. If operators are using shared accounts, reseller panels, or recurring delivery tooling, those dependencies can expose common failure points. NHIMG’s MailChimp Breach shows how social engineering and account compromise can turn a service platform into a downstream fraud channel, which is often the same pattern investigators need to understand in phishing-service ecosystems.

Risk and Threat Considerations

These networks are resilient because they split risk across payment, hosting, delivery, and monetisation. If teams only chase the phishing page, the operator can replace it quickly; if they only follow the wallet, the service layer can remain untouched and continue scaling abuse. The real exposure is the combination of short-lived infrastructure and persistent service dependencies.

Failure mechanism: Operators use disposable front-end infrastructure while reusing wallets, delivery tooling, or hosting relationships that survive individual takedowns, which lets the service reconstitute after disruption.

Impact: Investigators who miss that repeatable layer may collect evidence without creating meaningful disruption, allowing the same fraud operation to keep monetising and re-targeting new victims.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and OWASP ASVS set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 RS.AN-03 — Analysis Supports analyzing phishing-service links and infrastructure patterns to understand the incident chain.
Recommendation — Analyze payment, hosting, and delivery pivots to identify repeated campaign infrastructure.
NIST SP 800-53 Rev 5 AU-6 — Audit Record Review, Analysis, and Reporting Fits the need to correlate logs and evidence across wallets, domains, hosting, and delivery services.
Recommendation — Review audit and transaction evidence together to build a single case timeline.
MITRE ATT&CK T1583 — Acquire Infrastructure Directly matches the use of hosting, domains, and service providers in phishing operations.
Recommendation — Map provider and domain acquisition patterns to attacker infrastructure staging.
CIS Controls v8 CIS-13 — Network Monitoring and Defense Applies to detecting repeat infrastructure, domains, and delivery channels used by phishing services.
Recommendation — Monitor infrastructure reuse and alert on recurring phishing delivery patterns.
OWASP ASVS V16 — Security Logging and Error Handling Supports retention of evidence and telemetry needed to investigate abuse paths and fraud workflows.
Recommendation — Retain logs and artifacts that preserve the full abuse chain for later correlation.

Practitioner Guidance

What to prioritise: Start with the strongest pivots that can survive churn, especially wallet tracing, hosting relationships, and any recurring infrastructure fingerprints. Those are usually more useful than trying to prove authorship from a single phishing site.

What to verify: Confirm whether the same payment destination, infrastructure provider, or delivery pattern appears across multiple incidents before you escalate. Repetition is what turns a suspicious artefact into an operational link.

Practitioner takeaway: The most valuable investigation is the one that connects monetisation to reusable infrastructure, because that is where disruption becomes durable rather than purely reactive.