Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What are the signs that a spear phishing…
Threats, Abuse & Incident Response

What are the signs that a spear phishing campaign is being prepared long before it is launched?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Threats, Abuse & Incident Response

Long lead times between domain registration and use, highly personalised email content, and messages that reference internal details all suggest advance preparation. These clues can indicate surveillance, compromise, or insider assistance. Security teams should correlate domain age, message targeting, and unusual knowledge of business processes to spot campaigns that have already moved beyond generic phishing.

What preparation looks like before a spear phishing campaign goes live

A spear phishing campaign usually leaves planning signals before the first malicious message is sent. The most useful indicators are not the lure itself, but the lead-up: domain registration activity, targeting research, message drafting, infrastructure staging, and the reuse of internal language that only works after someone has studied the organisation.

When these signs cluster together, the campaign is usually beyond generic spam. That shift matters because it suggests the attacker already knows who to target, what story will persuade them, and which business details will make the message feel legitimate.

Which early indicators matter most

One of the strongest indicators is a newly registered or recently repurposed domain that is not yet in active use but is clearly being prepared for a future lure. Attackers often pair that with email content that is unusually tailored to specific roles, projects, vendors, or internal workflows. Personalisation at that level typically requires reconnaissance, prior compromise, or outside assistance.

Another signal is language that mirrors internal naming conventions, approval steps, or current business activity. A message that refers to an internal process, recent meeting, or ongoing initiative may mean the sender has studied public material closely, obtained information through compromised accounts, or learned details from an insider source. Read in isolation, any one clue may be weak; together, they become much more meaningful.

A further warning sign is operational staging that appears before delivery, such as lookalike domains, mailbox setup, sender reputation warming, or test messages to small targets. These are preparation behaviours, not just technical setup. They show intent to make the campaign durable enough to evade routine user suspicion and basic filtering.

How teams should interpret the pattern

The practical test is whether the signs point to informed targeting rather than opportunistic spam. If the attacker appears to know internal structure, business timing, or trusted relationships, the campaign may already involve surveillance or a compromised foothold. That is a stronger security signal than simply noticing a suspicious domain or a badly written email.

Correlation is critical. Domain age alone does not prove malice, and a personalised email could still be harmless. But when short domain history, specific organisational references, and role-based targeting appear together, the probability of deliberate preparation rises sharply. Teams should treat that combination as an early warning of a campaign that is being assembled with intent, not improvised on the fly.

Risk and Threat Considerations

Spear phishing preparation is risky because the attacker can refine the lure before delivery, increasing the chance of credential theft, business email compromise, or follow-on access. The longer the preparation window, the more opportunity the adversary has to validate targets, harvest context, and tune the message to bypass both human suspicion and email controls.

Failure mechanism: Reconnaissance, compromised accounts, or insider knowledge supply the attacker with just enough internal context to make the message credible, while infrastructure staging gives the campaign a cleaner delivery path.

Impact: Once the lure looks familiar, a single successful reply or click can expose credentials, approve fraudulent activity, or open the door to broader account compromise and lateral movement.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1598 — Phishing for InformationPreparation signals often reflect recon for targeted phishing.
T1583 — Acquire InfrastructureNew domains and staging infrastructure are common pre-launch phishing setup.
Recommendation — Map domain and content reconnaissance to T1598 and hunt for pretext-building activity. Track newly acquired infrastructure and block lookalike domains before delivery.
NIST CSF 2.0DE.CM-02 — Monitor personnel and system behavior for signs of malicious activityCorrelated prep indicators are detectable through continuous monitoring.
Recommendation — Correlate domain age, targeting, and message anomalies in your monitoring pipeline.
NIST SP 800-53 Rev 5AU-6 — Audit Review, Analysis, and ReportingInvestigating spear-phishing prep depends on correlating logs and message telemetry.
Recommendation — Analyze email, DNS, and authentication logs together to confirm coordinated preparation.
CIS Controls v8CIS-9 — Email and Web Browser ProtectionsEmail protections are central to detecting and reducing spear phishing exposure.
Recommendation — Harden email filtering and block suspicious sender infrastructure as early as possible.

Practitioner Guidance

What to verify: Check domain age, registration patterns, DNS changes, and mailbox infrastructure alongside the message content. A short-lived domain is most useful as evidence when it aligns with a targeted lure and references that only an informed sender would know.

What to prioritise: Focus first on messages that combine personalisation with unusual knowledge of business processes or recent events. Those are the cases most likely to indicate preparation rather than generic phishing.

Decision rule: If the lure contains internal details that should not be visible to an external sender, treat the incident as a potential surveillance or compromise issue, not just a user-awareness problem.

Practitioner takeaway: The most reliable early warning is a cluster of preparation signals, not a single suspicious artifact, so defenders should assess domain lifecycle, targeting precision, and insider-style context together.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org