Doppel Email Security is now generally available! | Register for the webinar to learn more
Research

Stage 2, Launch: The Moment the Attack Goes Live

Launch is the second stage of the social engineering attack chain: when staged domains, personas, and infrastructure go live. Learn why it's the midpoint, not the start.

Stage 2, Launch: The Moment the Attack Goes Live

Everything the attacker staged during Setup exists for one moment: the flip from Setup to Launch, from built to live. Launch is when the staged domain starts sending, the warmed persona starts reaching out, and the whole operation fans out across email, SMS, social, ads, and phone lines at once. This piece walks through Launch, the second stage of the social engineering attack chain: how the flip happens, why it is designed to blend into your legitimate traffic, and why the defenders who fare best treat it as the midpoint of the attack rather than the start.

There is a single moment in every social engineering operation when the attacker stops building and starts attacking. The domain that sat quietly aging for six weeks sends its first message. The persona that spent a month posting ordinary content sends its first connection request. The phone number that was warmed on other targets dials yours. That buildout may have taken months or a single afternoon. Nothing new was created in that moment. Everything that matters already existed. The only thing that changed is that it moved.

That flip, from built to live, is Launch, the second stage of the chain.

The first piece in this series (opens in new tab) argued that social engineering is a chain, not an event. The second (opens in new tab) followed the money. The third walked through Setup (opens in new tab), the buildout stage that happens off your infrastructure, weeks to months before contact. This piece picks up at the moment all of that staging is put into motion.

What launch actually is

In Doppel’s five-stage Social Engineering Attack Chain (SEAC) model, Launch is when the weaponized communication goes live and is set in motion across the attacker’s chosen channels. It is the shortest stage of the chain and the highest-volume one. Setup took weeks to months. Launch takes minutes. A campaign that took a month to build can land in thousands of inboxes before the first recipient finishes reading it.

The important structural fact about Launch is what it is not. It is not the beginning of the attack, even though it is usually the first stage that generates anything your tooling could possibly see. Every choice that decides whether the campaign works was already made: the domain, the persona, the pretext, the target list, the timing. Launch executes a finished plan. It is also the last stage the attacker fully controls. From Contact onward, the operation depends on a person responding. At Launch, the only participant is the adversary, moving staged assets into position at whatever speed and scale they choose.

How attackers run it

Strip out the mystique, the way we did for Setup, and Launch is distribution. It looks like this.

They send from infrastructure purpose-built to slip past security controls. The aged domain clears the security filters that would have flagged a fresh one. Display-name spoofing and lookalike addresses (opens in new tab) get the sender line to read right at a glance, which is the only inspection most recipients ever give it. Where the target’s defenses are stronger, the message routes through an adversary-in-the-middle proxy (opens in new tab) staged during Setup, so that even the login page waiting at the end of the link is a live relay of the real one.

They launder the delivery through services you already trust. Lures go out hosted on Google Sites and wrapped in legitimate OAuth flows (opens in new tab), staged inside Canva, DocHub, and the rest of your own SaaS stack (opens in new tab), or injected into file-upload forms on reputable sites (opens in new tab) so the malicious content arrives from a domain with years of clean reputation. The message does not have to defeat your filters if it arrives wearing the reputation of a service your filters were built to allow.

They launch wide, across channels at once. The same staged operation goes out as email in a dozen familiar disguises (opens in new tab), as SMS, as social outreach, as paid ads, and as calls. One staged asset, many doors. The channels are not redundant; they are a portfolio. Email is cheap and filtered. SMS is cheap and barely filtered. Voice is expensive per attempt and converts best. The economics from the second piece decide the mix, and the mix is tuned per target, not per campaign.

Why launch is hard to see

Launch is hard to catch for the opposite reason Setup is. Setup is invisible because it produces no traffic toward you. Launch produces plenty, and every piece of it is dressed to look like the traffic you already accept.

That is not an accident of craft. It is the whole design goal of the buildout. The domain was aged so this moment would clear reputation checks. The account was warmed so this message would not read as a first contact. The lure was staged on a trusted service so this delivery would ride an allowed sender. Setup existed to buy Launch a pass through every control that inspects things one at a time.

There is a second problem: speed and spread. A launch is one event for the attacker and thousands of events for everyone else, distributed across companies, channels, and time zones. Any single defender sees a thin slice of it, a few messages that may not even look related, while the campaign’s real shape (one asset, many targets, one window) is only visible across the whole spread. The message your gateway scores was never the unit of attack. The launch pattern was.

The pattern, not the message

That reframe is where the leverage sits at this stage. An individual message can be made nearly perfect. The launch pattern cannot, because scale leaves fingerprints. The same staged domain touches many targets in a narrow window. The same kit renders the same page behind a hundred different links. The same persona sends the same opener to fifty companies in one afternoon.

None of that is visible from inside one inbox. All of it is visible if you are watching the infrastructure. This is where the work described in the Setup piece pays its dividend: if the lookalike domain, the near-miss certificate, and the impersonating profile were already correlated into one campaign view during the buildout, then the moment any one of them goes live, you are not scoring a new message from an unknown sender. You are watching a known operation take its next step, and that is what correlation platforms like Doppel’s Threat Graph (opens in new tab) are built to surface. Detection at Launch is cheap for whoever did the watching at Setup, and nearly impossible for whoever starts at the inbox.

From launch to contact

Launch ends the moment a real person is on the other end of the communication. The message is opened. The call is answered. The connection request is accepted. That handoff, from an attack in motion to an attack with a human in it, is Contact, and it is the subject of the next piece. The boundary matters because it marks the point where the operation stops being entirely the attacker’s to control and starts depending on someone else’s judgment, which is exactly what the attacker spent Setup engineering around.

What defenders get wrong

The common mistake at this stage is the one this series opened with: treating Launch as the start of the attack. It is an easy mistake to make, because Launch is where the evidence starts. The first inbound message is the first thing the security stack can log, so it becomes the first line of the incident timeline, and the whole investigation inherits a frame in which the attack is hours old instead of weeks to months.

That frame has a cost. If the attack starts at the message, then the response is about the message: quarantine it, block the sender, close the ticket. The staged infrastructure behind it survives untouched, ready to launch again with a new address and the same domain, kit, and persona. Whoever treats Launch as the beginning ends up fighting each launch on its own, indefinitely. The attacker built once and launches many times; a defense that only answers launches is subsidizing the attacker’s best economics.

Why launch should never be your first signal

Launch is the moment the attack becomes visible and the worst moment to start looking. Everything about it was engineered during a stage you were not watching, precisely so that this stage would blend in. The defenders who fare best at Launch are the ones for whom it is not news: the campaign was already on their map during the buildout, so going live is not the first signal; it is the confirmation. Every other stage of the chain rewards early work. Launch is where that reward is paid.

What leaders should take away

  • Launch is the midpoint, not the start. If your incident timelines begin with the first inbound message, your program is dating every attack weeks to months late, and your response is scoped to the fragment instead of the operation.
  • The unit of attack is the launch pattern, not the message. One staged asset fans out across channels and targets at once. Programs that correlate at the campaign level see one operation moving; programs that score messages see thousands of unrelated events.
  • Answering launches is not the same as stopping them. Quarantining the message leaves the machinery intact and ready to fire again. Pairing message response with disruption of the staged infrastructure is what stops the next launch from being free.

The next piece in the series follows the attack across the perimeter: Contact, the stage where the communication reaches a person, and where the modern version increasingly arrives on channels your security stack has never seen.

Learn how Doppel can protect your business

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.