Blocklists are no longer effective against modern phishing attacks. The lifespan of phishing domains has significantly decreased, with 89% active for fewer than two days and only 6.5% lasting beyond 15 days. This rapid turnover means that by the time a domain is added to a blocklist, the associated campaign has already moved to new infrastructure.
AI has exacerbated the problem by enabling attackers to generate phishing pages from screenshots in minutes. This capability, combined with the ability to quickly spin up and tear down infrastructure, allows attackers to iterate on tooling at a pace that renders indicator-based detection functionally useless. The cost of creating these pages has also collapsed, making it easier for attackers to deploy convincing, unique phishing sites.
Modern phishing attacks are designed with disposable infrastructure from the outset. Attackers proactively tear down pages and launch new ones to evade detection, treating each piece of infrastructure as single-use. They also employ techniques like bot protection, screening checks, and complex redirect chains on trusted hosting platforms to filter out researchers and automated scanners. This ensures that the page a crawler sees is often different from what a victim encounters, and malicious payloads may no longer be active by the time a page is analyzed.
Security defenses that rely on matching known-bad indicators are consistently two steps behind. This includes protection against various in-browser attacks such as AiTM phishing, device code phishing, ClickFix, file downloads, and malvertising. The evolving tactics of attackers, driven by AI and disposable infrastructure, necessitate a re-evaluation of current security strategies.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Attackers are using AI to generate phishing pages and rapidly rotate infrastructure, making traditional blocklists and indicator-based detection methods obsolete. Phishing domains now have an average lifespan of less than two days, outpacing the ability of blocklists to track them. This shift necessitates new defense strategies against evolving phishing tactics.