Join Doppel at Black Hat USA 2026 to win The Bigger Carry-On suitcase from Away
Research

Stage 1, Setup: How Attackers Build the Conditions for Success Before You Ever See a Message

Learn how adversaries build lookalike domains, warm accounts, and clone brands in Stage 1 of the social engineering attack chain and how defenders can stop them.

Stage 1, Setup: How Attackers Build the Conditions for Success Before You Ever See a Message

The message that reaches your employee is the first thing you see and the last thing the attacker builds. Weeks to months earlier, on infrastructure you do not own and cannot log, they registered the domain, aged the accounts, cloned your brand, and studied how you communicate. This piece walks through Setup, the first stage of the social engineering attack chain: what the adversary assembles before contact, why it sits in your blind spot, and why it is the cheapest stage they run and the cheapest one you can break.

Every forensic reconstruction I have run tells the same story about time. Someone calls us in after the attack has already succeeded, and we work backward from the moment someone first noticed something was wrong. That moment is almost never close to the moment the attack began. The domain was registered six weeks earlier. The lookalike profile had been posting for a month. The phone number had already been warmed on other targets before it ever rang inside the company. By the time anyone saw the attack, the hard part was finished.

That gap between when an attack starts and when we notice it is not an accident. It is a stage. It is the first stage of the chain, and it is where these operations are won or lost long before anyone is asked to spot a bad message.

The first piece in this series argued that social engineering is a chain, not an event. The second explained why the chain pays. This piece starts the walk through it, at the stage that happens first and hides best: Setup.

What Setup Actually Is

In the five-stage Social Engineering Attack Chain model, Setup is the pre-attack buildout: everything the adversary assembles to make later contact believable. The infrastructure and the lookalike domains. The personas and the cloned brand assets. The phone numbers and the messaging accounts. The quiet research that decides who to approach, when, and on which channel they are most likely to be believed.

None of it touches your environment. All of it is aimed at your environment. That is the tension that defines the stage.

I think of Setup as the staging window: the weeks to months between the decision to run an operation and the first message that reaches a person. Everything in that window is preparation, and almost all of it is invisible from where a defender usually sits.

How Attackers Build It

Strip out the mystique, and Setup is procurement and assembly. It looks like this.

They buy the real estate. A lookalike domain costs about the price of a sandwich, and it is often registered well ahead of use and left to age, because a domain with history clears security filters that a domain registered yesterday does not. They warm the accounts. Email and social profiles get a slow trickle of ordinary activity so that, by launch, they read as established personas rather than fresh ones.

They clone the brand. Logos, letterhead, and login pages are lifted straight from your public footprint, and increasingly the staging happens inside trusted tools like Canva, DocHub, and editable official forms, so the finished lure is hosted on a service your own filters may already trust. They build the people. A persona no longer takes a skilled operator weeks or months; a custom GPT can stand up a consistent, on-brand identity with a backstory and a writing style in an afternoon. When they do not want to build at all, they rent. Malware and phishing kits sold as a service hand a buyer the whole staged package.

Lay all of these steps on a timeline and the shape of the problem becomes obvious. The domain is aged for weeks or months. The accounts are warmed and seeded in parallel. The brand assets and the personas are staged and deployed. The research picks the target and the moment. The first interaction with a target lands only at the very end, at the far right of a timeline the defender never saw the left side of.

The economics from our second blog piece explain why the buildout looks the way it does. Setup is where the operation spends what little money it costs, and every piece of it is built to be reused. Cheap and reusable is exactly the combination that produces volume.

Why Setup Sits in Your Blind Spot

Setup is hard to see for a simple structural reason: it does not happen on your infrastructure. It happens on registrars, in certificate logs, on social platforms, in app stores, on services you do not own, log, or instrument. Your email gateway, your endpoint tooling, and your SIEM are all pointed at your borders and inward, at traffic that has already arrived. Setup produces no inbound traffic. Nothing has arrived for them to catch.

What signal it does produce is distributed and quiet: one new domain, one fresh profile, one certificate, one app listing, each one landing in a different place and each one, on its own, looking like the ordinary background noise of the internet. A single lookalike domain is not an incident. Thousands are registered every day. The problem is never the one artifact. The problem is that no one is positioned to notice when several of them belong to the same operation aimed at you.

Where the Leverage Is

Setup is the cheapest stage the attacker runs, and that is exactly what makes it the cheapest stage for you to break.

Every later stage inherits Setup. The launch, the contact, the conversation, the compromise all stand on the domain, the persona, and the cloned brand that were staged first. Take those away before the first message goes out, and the operation does not advance to a cheaper fallback. It goes back to the beginning and pays the buildout cost again.

Our second piece made the general case that disruption beats detection because cost is the only number the adversary feels. Setup is where that principle has the most force, because it is the one stage where a small action on your side can erase a large amount of the attacker's work.

From Setup to Launch

Setup ends the moment that infrastructure is switched on. The aged domain starts sending. The warmed accounts start reaching out. The staged conversation goes live. That flip, from built to live, is Launch, and it is the subject of the next piece. By the time Launch is visible, everything that makes it effective was already decided here, before anyone was watching.

What Defenders Get Wrong

The common mistake is not missing Setup signals. It is seeing them and filing them as isolated, low-priority noise. A brand-monitoring alert flags a lookalike domain, and it is logged. A fresh executive profile is reported, and a takedown is queued. A certificate for a near-miss of your name appears, and no one is watching certificate logs at all. Each of these is treated as a housekeeping item, closed on its own desk, on its own clock.

This is the fragmentation from the first piece, pushed back one stage earlier. Five teams closing five tickets on one campaign was the problem at Contact. At Setup it is worse, because the signals are even weaker and even further from the security stack, so they are the easiest of all to dismiss. The adversary is assembling one operation. The defender is filing its parts as unrelated trivia.

What Setup Looks Like If You Watch For It

You cannot instrument the attacker’s infrastructure, but you can watch the public record it leaves while it is being built. The raw material is already out there:

  • Passive DNS and new-domain registration cadence, for lookalikes of your brand and your executives’ names.
  • Certificate transparency logs, where a certificate for a near-miss domain often appears before the domain is ever used.
  • Social-handle and profile creation, for personas impersonating your brand, your leaders, and your support channels.
  • App-store listings and changelogs, for fake or trojanized versions of your apps.

Watching any one of these feeds gives you more noise. The value is in correlation: connecting the domain, the certificate, the profile, and the app listing into a single view that says these belong to one operation aimed at us. That correlation is the work Doppel built the Threat Graph to do, and it is what turns a pile of low-priority alerts into one high-priority campaign.

There is also an active option, and it is the one I have spent the most time on throughout my career. You can put out infrastructure of your own that an adversary in the staging window is likely to probe, touch, or clone, and let their preparation reveal itself against something you control and are watching closely. Done well, deception turns the attacker’s quietest, most confident stage into a source of early warning. The point here is that Setup is not only observable in the public record; it can also be made to surface itself.

Why This Stage Matters Most

Setup is the stage that decides how the rest of the attack goes, and it is the one almost no one is watching. It happens off your network, weeks to months before contact, in signals weak enough to ignore one at a time. That is precisely why it is the highest-leverage place to act. Every other stage is the attacker executing a plan. Setup is the attacker building one, and a plan is cheaper to break while it is still being built than after it is in motion.

What leaders should take away

  • The attack is built before you can see it. By the time a message reaches an employee, the domain, the persona, and the cloned brand behind it have existed for weeks to months. A program whose earliest visibility is the inbound message is watching the last stage of the buildout, not the first.
  • Setup signals are precursors, not housekeeping. A lookalike domain, a fresh impersonating profile, and a near-miss certificate are not separate chores on separate desks. Correlated, they are the early outline of one campaign, and correlation is what turns them from noise into warning.
  • Earliest is cheapest. Disrupting an operation during Setup sends the adversary back to the start of the buildout and makes them pay for it again. It is the one point where a small move on your side costs them the most.

The next piece in this series follows the buildout into motion: Launch, the brief, high-volume moment when everything staged here goes live, and the last point in the chain that is still entirely the attacker’s to control.

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.