How website cloning works
The attacker’s goal is a convincing duplicate: your branding, your login form, your layout, hosted on a domain they control. When a victim lands on it and enters their details, the attacker captures them. It is devastating for the targeted organisation and for the users who trust the brand.
How Active Trace catches it
Active Trace plants hidden traps in your web pages — traps that stay dormant for normal visitors and only activate when the site is cloned and accessed by an attacker. The trap is a tiny piece of JavaScript or an SVG file embedded in your pages. When attackers clone your site, they copy your imagery and code wholesale to preserve its look and feel — so the trap comes along for the ride. The moment that cloned page loads somewhere it shouldn’t, the file quietly calls back to River Security infrastructure, telling us the site is running in an unauthorized setting. Active Trace identifies the clone and alerts your security team, giving you the chance to act while the fraudulent site is still being prepared.
Stopping phishing before it launches
The real value is timing. By surfacing a cloned site early — often before the phishing campaign goes out — Active Trace lets you respond while it still matters: block it, get it taken down, and cut the campaign off before it reaches your users. For organisations using Active Focus, it is one more way to stay a step ahead of the attackers, on the surface you can’t normally see.
Is it foolproof? No — nothing in this space is, and a determined attacker can strip the traps. But it doesn’t have to be foolproof. Raising the bar enough to catch and disrupt the majority of phishing infrastructure early is what changes the outcome.
