- What does the 2026 adversary infrastructure brief cover?
- How C2, phishing, and staging infrastructure is bought, burned, and reused across clusters, including bulletproof hosting, residential proxies, and certificate reuse. It is a year of workbench data, written for detection and CTI, not a press cycle. Attack Nemesis Research published it to inform blocking-versus-hunting decisions.
- What do I get besides the narrative?
- Which infrastructure neighborhoods to treat as durable, which to treat as noise, and the action derived from each, plus indicator tables in an appendix. Attack Nemesis pairs every infrastructure finding with an action.
- Why do the brief’s indicators expire after 14 days?
- Because infrastructure turns over faster than a PDF ages, and stale indicators become noisy watchlists. The expiry is deliberate. Attack Nemesis publishes indicators with a date they die.
- Who is the brief for, and how long is it?
- Detection engineers and CTI leads deciding what to block and what to hunt. It is a 42-page PDF brief. Attack Nemesis wrote it for the people who have to act on infrastructure, not report on it.