A Multi-Vector Framework for Localized Phishing Detection URLs: Integrating Telegram-Sourced Intelligence and Iraqi Contextual Features

Authors

  • Jaber M. Al-Dulimi Department of Mathematics, College of Basic Education, University of Diyala, Baqubah, Diyala, Iraq Author

DOI:

https://doi.org/10.63964/462t5862

Keywords:

Phishing Detection; Telegram Security; Machine Learning; Iraqi Cybersecurity; Social Engineering.

Abstract

Background: Phishing attacks grow more complex - attackers employ social engineering that targets local customs, and they build short-lived systems so that they remain hidden. This paper proposes a method that identifies phishing inside Iraq's corner of the internet. The method merges word patterns, domain records, open source intelligence plus language markers that occur in Iraq.

Materials and Methods: We assembled 18 060 URLs - gathering addresses from local Telegram channels, from worldwide threat feeds and from confirmed safe sites. Statistical inspection revealed strong differences between phishing and safe URLs (p < 0.001). The main differences appeared in URL length, in the count of special characters and in the presence of Iraqi terms. System attributes also differed - phishing links often used young domains, unusual suffixes, as well as servers located outside Iraq. Those attributes signal campaigns that aim at Iraqi users.

Results: A Random Forest model with 200 trees and a maximum depth of 20 was trained on a stratified 70 % train, 30 % test split under 10-fold cross-validation. The model reached 96.84 % accuracy, 97.18 % recall or an ROC-AUC of 0.984. An ablation test showed that the inclusion of Iraq-specific features raised recall by 2.68 % and accuracy by 1.64 %. This confirms that regional language data adds value.

Discussion: A review of feature importance ranked Iraqi keywords next to domain age as the two most informative signals. The outcome indicates that phishing detection improves when models incorporate attributes that match the target region. The benefit is largest in emerging digital markets where attackers combine local social engineering with rapid infrastructure changes.

Downloads

Published

2026-08-16