← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

AI-powered phishing renders traditional blocklists ineffective due to rapid infrastructure rotation

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • 89% of phishing domains are active for less than two days.
  • Attackers use AI to generate phishing pages from screenshots quickly.
  • Infrastructure is designed to be disposable, rotating proactively.
  • Bot protection and redirect chains hide malicious pages from scanners.

The Obsolescence of Blocklists

Blocklists are no longer effective against modern phishing attacks. The lifespan of phishing domains has significantly decreased, with 89% active for fewer than two days and only 6.5% lasting beyond 15 days. This rapid turnover means that by the time a domain is added to a blocklist, the associated campaign has already moved to new infrastructure.

AI's Role in Accelerating Phishing

AI has exacerbated the problem by enabling attackers to generate phishing pages from screenshots in minutes. This capability, combined with the ability to quickly spin up and tear down infrastructure, allows attackers to iterate on tooling at a pace that renders indicator-based detection functionally useless. The cost of creating these pages has also collapsed, making it easier for attackers to deploy convincing, unique phishing sites.

Disposable Infrastructure and Evasion Techniques

Modern phishing attacks are designed with disposable infrastructure from the outset. Attackers proactively tear down pages and launch new ones to evade detection, treating each piece of infrastructure as single-use. They also employ techniques like bot protection, screening checks, and complex redirect chains on trusted hosting platforms to filter out researchers and automated scanners. This ensures that the page a crawler sees is often different from what a victim encounters, and malicious payloads may no longer be active by the time a page is analyzed.

Impact on Security Defenses

Security defenses that rely on matching known-bad indicators are consistently two steps behind. This includes protection against various in-browser attacks such as AiTM phishing, device code phishing, ClickFix, file downloads, and malvertising. The evolving tactics of attackers, driven by AI and disposable infrastructure, necessitate a re-evaluation of current security strategies.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Attackers are using AI to generate phishing pages and rapidly rotate infrastructure, making traditional blocklists and indicator-based detection methods obsolete. Phishing domains now have an average lifespan of less than two days, outpacing the ability of blocklists to track them. This shift necessitates new defense strategies against evolving phishing tactics.