The security industry still tends to describe scam infrastructure through the most visible artefact: the malicious website. That framing is convenient because websites are easy to scan, classify, block and remove. It is also operationally incomplete.
Source: [Dev.to](https://dev.to/bruce1267/why-scam-infrastructure-is-more-than-a-website-19gb)