Q3 2026 VB phishing campaign redirect/cloaking infrastructure IOCs

This rule monitors network, DNS, and email activity to identify communication or references to a set of known malicious domains associated with threat activity. It consolidates logs from device network events, DNS queries, and email telemetry (URLs and sender domains) to detect potential compromise or phishing attempts.