I worked on spam classification for litigation targeting in the early days of CANSPAM [0] enforcement.

We had a similar problem where you can literally millions of email that we were pretty sure came from only a limited set of bad actors.

We first started classifying emails into buckets by From, mailserver relay chains etc as that's all we had to to go on.

Over time, those buckets got linked to spammer signatures and then we narrowed down from there.

Fascinating to see this happening nowadays with LLMs.