惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
B
Blog
T
The Blog of Author Tim Ferriss
J
Java Code Geeks
腾讯CDC
D
Docker
G
Google Developers Blog
D
DataBreaches.Net
雷峰网
雷峰网
Blog — PlanetScale
Blog — PlanetScale
S
SegmentFault 最新的问题
The Cloudflare Blog
有赞技术团队
有赞技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Stack Overflow Blog
Stack Overflow Blog
大猫的无限游戏
大猫的无限游戏
量子位
美团技术团队
aimingoo的专栏
aimingoo的专栏
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Engineering at Meta
Engineering at Meta
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Infoblox Blog

You Don’t Need a Locksmith: Preparing for the Root Zone Key Signing Key (KSK) Rollover in October 2026 AI Agent Security: DNS-AID and Protective DNS | Infoblox Illegal Gambling Sites Reveal Three Types of Cybercrime Infoblox vNIOS on AWS China | Unified DDI Across Global and China Cloud Environments DNS-AID: Securing AI Agents and the Future of Agentic Commerce Modernizing Federal Networks Without Compromise | Infoblox DNS at IETF 126 To Open Weight or Not to Open Weight - That Should NOT be the question AI Governance with DNS Security | Infoblox Infoblox Supports the Next Generation of Cybersecurity Talent at Cyber Battle Australia The Second Life of Expired Domains Illegal Streaming Fronts a $7M Dropcatch Domain Operation Expired Malicious Domains Bring New Threats to Life How Many AI Agents Are Running in Your Organization? Infoblox IQ for DDI Is Now Generally Available | AI for Network Operations Kentik Joins Infoblox: Network Observability & AI AI’s First Move Is a Name Lookup External Attack Surface Management: See What Attackers See | Infoblox FedRAMP DDI Management with Infoblox Government Cloud Inside a Global Procurement-Themed AiTM Phishing Campaign The Missing Link in the Anti-Scam Chain: Why DNS Belongs in the Room. (DNS, GASA, Global Anti-Scam Alliance, DNS Threat Intelligence) Oracle Cloud Discovery for Universal Asset Insights | Infoblox Why Asset Discovery Integrations Start with Network Intelligence Infoblox Kentik Acquisition: AI-Driven Network and Security Intelligence Proxyware actor behind fake 7-Zip is bigger than you think! Using Protective DNS to Dismantle Global Scam Networks | Infosecurity Europe 2026 Residential Proxies: Why DNS Is the Stronger Play NIST Maps DNS Security to the Cybersecurity Framework 2.0 Trusted Infrastructure Data for AI and AgenticOps | Infoblox Meet Your Security Analyst’s New AI Teammate | Infoblox IQ
Cybercrime Trends and Threat Intelligence | Infoblox
Bart Lenaerts-Bergmans · 2026-07-31 · via Infoblox Blog

Cybercrime Has Become an Industrialized Economy

Cybercrime has evolved from isolated attacks into a sophisticated, industrialized economy powered by frontier AI, automation and specialized criminal services. Today’s attackers operate less like opportunistic hackers and more like businesses—renting infrastructure, purchasing phishing kits, outsourcing money laundering and using AI to generate convincing social engineering campaigns at unprecedented speed and scale.

The 2026 Infoblox Threat Landscape Report examines this transformation by analyzing trillions of DNS queries, billions of underground criminal transactions and extensive original threat intelligence research. The findings reveal a fundamental shift: cybercrime is becoming faster, more automated and dramatically more efficient. What has emerged is a cybercrime machine—an ecosystem designed to continuously scale attacks while staying ahead of traditional security defenses.

The Numbers Behind the Cybercrime Machine

Between June 2025 and June 2026, Infoblox observed significant changes in both cybercriminal activity and enterprise exposure.

Key findings include:

  • More than 22 percent of newly observed domains exhibited malicious or suspicious characteristics.
  • 88 percent of threat-related domains were observed in a maximum of one environment, while 44 percent remained active for just one day.
  • 96 percent of organizations encountered exposure to traffic distribution systems (TDSs), which attackers use to profile victims before redirecting them to phishing sites, malware or scams.
  • 65 percent of organizations queried residential proxy networks, highlighting how attackers increasingly conceal their network activity.
  • Enterprise DNS queries to AI applications increased 159 percent, reflecting rapid adoption of more than 100 AI applications, including ChatGPT, Microsoft Copilot, Claude, Cursor, Replit and Hugging Face, and a corresponding expansion of the enterprise attack surface.

Collectively, these findings show that cybercrime is becoming more distributed, more resilient and more difficult to detect. Attackers rapidly create and abandon infrastructure faster than traditional security tools can identify it, while increasingly abusing trusted internet services to blend malicious activity into legitimate traffic.

Cybercrime Now Operates as a Service-Based Economy

Perhaps the report’s most significant findings illustrate how cybercrime now functions as a mature, service-based economy.

Rather than building every component of an operation themselves, attackers assemble campaigns from specialized services available across underground marketplaces. Infrastructure, phishing kits, malware, traffic-routing services, fraud platforms and money laundering can all be purchased or rented on demand.

This specialization has fundamentally changed the economics of cybercrime. Capabilities that once required advanced technical expertise are now accessible to almost anyone willing to pay. AI accelerates this trend by reducing the cost and effort required to generate convincing phishing emails, fake websites, multi-lingual content and personalized social engineering campaigns. As barriers to entry continue to fall, the number of capable attackers continues to grow.

The result is an ecosystem optimized for efficiency, resilience and continuous growth, much like a legitimate digital business.

Attackers Are Hiding in Plain Sight

While many security programs remain focused on malware and known indicators of compromise, attackers are increasingly succeeding by abusing trusted internet infrastructure. Infoblox researchers observed widespread abuse of DNS, advertising technology, cloud platforms, reverse DNS (.arpa) and other legitimate internet services. By operating within trusted infrastructure rather than obviously malicious domains, attackers make malicious activity significantly more difficult to distinguish from normal business traffic.

TDSs have become a foundational component of modern cybercrime. Originally developed for legitimate digital advertising and traffic optimization, TDS platforms are now widely abused by attackers to selectively route victims to phishing pages, malware downloads, scam websites or exploit kits. Rather than sending every visitor to the same destination, a TDS profiles users based on attributes such as IP address, geographic location, browser type, operating system, language, device and referral source. Visitors who match an attacker’s targeting criteria are redirected to malicious content, while everyone else, including security researchers, automated scanners and search engine crawlers, may see harmless websites or be redirected elsewhere. This selective filtering helps attackers evade detection and extend the lifespan of their campaigns.

The report also highlights increasingly resilient attack infrastructure. Router compromise campaigns redirected victims through attacker-controlled recursive DNS resolvers hosted by bulletproof hosting providers, allowing attackers to remain hidden while maintaining highly durable operations.

The pattern is clear: attackers are investing as heavily in resilient infrastructure as they are in malware.

Intelligent, Personalized Lures

Attackers are also changing how they deceive victims. Rather than relying on generic phishing campaigns, they now create highly personalized lures tailored to a victim’s language, location, device and browsing behavior. AI enables attackers to generate realistic content at scale while selectively delivering attacks only to intended targets.

Brand impersonation remains one of the most effective social engineering techniques, but the tactics have evolved. Analysis of customer phishing incidents found that 71 percent of phishing domains did not include the impersonated brand name. Instead, attackers relied on authentic branding, realistic websites, familiar logos and polished user experiences to establish trust. The deception has shifted away from domain names and toward the overall user experience.

Credential Theft Has Become Identity Theft

The report also demonstrates how credential theft has evolved beyond usernames and passwords.

Investigations into Android malware-as-a-service uncovered banking trojans capable of intercepting SMS one-time passwords, fingerprinting devices, harvesting contacts, performing overlay attacks and even capturing facial biometrics through fraudulent know-your-customer (KYC) verification workflows. Attackers increasingly exploit users’ trust by mimicking familiar security and identity verification processes, making fraudulent interactions appear legitimate.

Attackers are no longer stealing credentials. They’re stealing complete digital identities.

The Enterprise Attack Surface Continues to Expand

Organizations continue to adopt AI applications, software-as-a-service (SaaS) platforms, cloud services and connected devices at an unprecedented pace. While these technologies accelerate innovation, they also create new opportunities for attackers.

The report shows cybercriminals increasingly targeting overlooked areas, including AI platforms, browser push notifications, DNS infrastructure, software supply chains, residential proxy networks and abandoned cloud resources.

Employees may unknowingly install applications that transform corporate devices into residential proxy endpoints. Developers may inherit compromised open-source software through trusted supply chains. Forgotten DNS records create opportunities for subdomain hijacking. Public AI assistants can unknowingly become distribution channels for malicious instructions.

The challenge is no longer simply a larger attack surface. It’s the lack of visibility into emerging infrastructure before attackers exploit it.

Why Preemptive Security Matters

The report concludes that reactive security alone can no longer keep pace with industrialized cybercrime. Disposable infrastructure gives defenders only a brief window to investigate before attackers abandon it and move to new infrastructure. Organizations must identify and disrupt malicious infrastructure before users ever interact with it.

DNS provides a unique advantage because nearly every internet transaction begins with a DNS lookup. By analyzing DNS activity at global scale, organizations can identify malicious infrastructure before phishing emails are opened, malware is downloaded or credentials are stolen.

Rather than responding after compromise, security teams can prevent many attacks before they begin.

Predictive Intelligence

The 2026 Infoblox Threat Landscape Report is more than an annual review of cyberthreats. It explains the structural changes reshaping cybercrime and why traditional security models are struggling to keep pace.

The report makes one point unmistakably clear: modern cybercrime is increasingly defined by infrastructure, automation and scale—not simply by malware.

Organizations that continue to rely solely on reactive security will find it increasingly difficult to defend against attackers operating as highly efficient digital enterprises. Those that adopt a predictive intelligence exploring the actors’ infrastructure will be better positioned to reduce risk before attacks reach users.

As cybercrime continues to industrialize, the effectiveness of cybersecurity solutions will be defined less by responding to incidents and more by disrupting the infrastructure that makes them possible.

Download the Infoblox 2026 Threat Landscape Report to explore the complete research, key findings and practical recommendations. For ongoing analysis of emerging threats, visit the Infoblox Threat Intel page.