In Episode S8E10 of the Brilliance Security Magazine Podcast, host Steven Bowcut speaks with Abu Bakr Qureshi, Director of Cybercrime Disruption at Bfore, about predictive attack intelligence and the effort to stop malicious infrastructure before cybercriminals can weaponize it.
Summary
Traditional cyber threat intelligence relies heavily on indicators of compromise—evidence that malicious activity has already occurred. By the time defenders recognize those indicators, victims may have been targeted, and damage may already be underway.
Abu Bakr Qureshi argues that defenders can intervene earlier by identifying the behavioral patterns associated with attacker preparation. Drawing on his background working with domain registrars and registry operators, Abu explains how registration activity, DNS configuration, certificate issuance, infrastructure relationships, and reputational history can reveal malicious intent before an attack is launched.
Bfore’s PreCrime platform combines these signals to identify potentially malicious infrastructure. Abu explains that no single signal is sufficient; predictions are based on multiple indicators evaluated together, with researchers continually validating and refining the models to reduce false positives. Bfore reports that its detections provide an average lead time of 18 days compared with conventional threat intelligence sources.
That additional time can allow organizations and Bfore’s disruption partners to block infrastructure at the email, endpoint, firewall, and DNS levels. It can also create an opportunity for a preemptive takedown. The goal is to damage the reputation and usefulness of malicious infrastructure before it becomes operational, increasing the attacker’s costs and reducing the potential return on the campaign.
The discussion also examines how brand impersonation has expanded beyond traditional typosquatted domains. Criminals now combine domains with fraudulent mobile applications, social media profiles, advertisements, online storefronts, messaging platforms, and legitimate services that have been repurposed for abuse.
Abu shares an example of an investigation in which attackers used a multistage campaign involving SMS messages, fraudulent forms hosted through a legitimate service, phishing pages, and WhatsApp communications. By working with providers at multiple points in the attack chain, investigators reduced traffic to the fraudulent sites, removed the malicious forms, and shut down the associated WhatsApp accounts.
Abu also discusses artificial intelligence’s impact on cybercrime. Although AI has not fundamentally changed the underlying techniques used in phishing and impersonation attacks, it has dramatically increased their speed and scale. Criminals can now generate polished content, conduct reconnaissance, create convincing pretexts, and manage campaigns with far fewer people.
For organizations beginning the transition toward preemptive security, Abu recommends studying how they have been targeted in the past and identifying their most valuable externally facing assets. A company can begin with a single brand, website, login page, or mobile application and monitor for infrastructure that appears designed to imitate it. Understanding what criminals are likely to impersonate is an essential first step toward recognizing an attack while it is still being prepared.
Listen to the Podcast
Click the image below to listen to the podcast.
About Our Guest
Abu Bakr Qureshi is Director of Cybercrime Disruption at Bfore. He is a cyber threat intelligence professional specializing in brand protection, phishing detection, malicious-domain investigations, and cybercrime disruption.
Abu began his career in the DNS abuse space, working with domain registrars and registry operators responsible for managing top-level domains. That experience gave him firsthand insight into the role domain names and supporting infrastructure play in online fraud, phishing, impersonation, and other malicious activity.
His work focuses on identifying and dismantling the infrastructure and criminal networks used to impersonate trusted brands, distribute fraudulent content, and target customers across digital channels. At Bfore, he helps organizations detect behavioral indicators of attacker intent and disrupt threats before they become active campaigns.
Additional Resources
Video Overview
Infographic

About the Host
Steven Bowcut is the Editor-in-Chief of Brilliance Security Magazine and host of the BSM Podcast. He brings together security professionals, researchers, executives, and industry innovators for thoughtful conversations about the technologies, strategies, and emerging threats shaping the global security community.




