Bleepingcomputer
AI-Powered Phishing Campaigns Render Blocklists Ineffective
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
AI has significantly enhanced phishing tactics, making traditional blocklists obsolete. Attackers utilize AI to generate phishing pages from screenshots in mere minutes, leading to a rapid turnover of phishing domains. Currently, 89% of phishing domains are active for less than two days, with only 6.5% lasting beyond 15 days. This fast-paced infrastructure rotation means that by the time a domain is blacklisted, the attackers have already moved on. Modern phishing attacks are designed to be disposable, with attackers proactively dismantling their infrastructure to evade detection. Legitimate hosting platforms are increasingly abused to mask malicious activities, complicating detection efforts. The use of bot protection and complex redirect chains further obscures the malicious content from automated scanners. As a result, relying on blocklists is akin to playing whac-a-mole in a rigged game.
Key Points: • 89% of phishing domains are active for less than two days, complicating detection. • AI enables rapid creation of phishing pages, making traditional defenses ineffective. • Attackers leverage legitimate services to enhance the credibility of phishing attacks.