← Back to Feed

The Infrastructure Relay: Inside Multi-Stage Phishing Redirection Chains

August 12, 2026 · LevelBlue SpiderLabs · Severity: MEDIUM

LevelBlue SpiderLabs details how their machine-learning URL scanner identifies emerging phishing campaigns by tracking instances where their engine is the sole detector on VirusTotal. The blog examines several notable campaigns that employ multi-stage redirection chains, where victims are relayed through multiple infrastructure layers to evade detection. This approach enables early identification and disruption of sophisticated phishing operations.

To stay ahead of evolving threats, LevelBlue utilizes a machine-learning-based URL scanner that constantly evaluates the digital landscape. We closely monitor VirusTotal for instances where LevelBlue acts as the sole detection layer — a crucial tactic for spotting new phishing campaigns early. In this blog, we will unpack several notable phishing campaigns discovered through this method.

Key Takeaways

  • LevelBlue's ML-based URL scanner detects phishing campaigns by monitoring VirusTotal for sole detections.
  • Multi-stage phishing chains use infrastructure relays to redirect victims through multiple malicious URLs.
  • Early detection of these redirection chains helps security teams disrupt phishing campaigns before they spread.
☕ Buy a Coffee