Phishing trends and threat research you can act on
The Dralvia Research blog turns real suspicious-URL analysis into readable intelligence. Each digest covers the impersonated brands, common lures, attack paths, and infrastructure reuse we see across freshly analysed phishing campaigns, with evidence behind every claim.
What you will find here
- Daily and weekly phishing digests with the top impersonated brands and lures.
- Infrastructure-reuse and redirect-chain patterns across campaigns.
- Practical takeaways for SOC analysts, IT teams, and crypto users.
Browse Dralvia Labs by topic
Dralvia Labs is our research: experiments, threat models, and what we measured. Each topic is a hub that gathers the lab notes on that area. To see lab notes mixed into the archive above, pick Lab notes in the report type filter.
How AI agents get steered by prompt injection, tool calls, and MCP connections, and what stops a risky action before it runs.
Phishing pages, fake-update and paste lures, credential drops, and the hosting and redirect reuse that ties campaigns together.
Risky execution in repositories and AI-generated code: install hooks, hidden payloads, and what a scan catches before you run it.
Wallet signatures, token approvals, and smart-contract traps, plus the checks that show the real intent behind a request.
Making the safe choice the easy choice, so a non-expert can act on a verdict without reading a manual.