Cybercrime Goes Industrial

Analytics2026-08-10, 10:53
In Threat Landscape Report 2026, researchers at Infoblox describe cybercrime not as a collection of separate threat groups, but as a mature commercial ecosystem, where virtually every component of an attack can be bought or rented: from infrastructure, malware, and comprehensive toolkits to payment processing and money laundering services.
The industrialization of cybercrime is particularly evident in statistics related to network infrastructure:
• Over the course of a year, Infoblox recorded the emergence of more than 120 million new domains, more than 22% of which were weaponized or exhibited threat characteristics.
• 88% of malicious domains were recorded as IoCs at only one Infoblox customer organization, while 44% were active for just 1 day. This indicates that attackers' infrastructure is becoming increasingly short-lived and narrowly targeted.
• Domains generated using DGA/RDGA accounted for 21.5% of the malicious domains identified. The number of scam domains grew by 62%, phishing domains by 54%, and those associated with residential proxies (we previously reported about their proliferation) by as much as 847% year over year.
• Traffic distribution systems (TDS) affected 96% of Infoblox customers. These systems profile visitors and show malicious content only to suitable victims, concealing it from everyone else. In one of the Detour Dog schemes studied, 95% of visitors to the compromised site saw ordinary content — only selected targets were redirected to a resource containing malicious content. Examples of similar campaigns were previously examined in this post.
Phishing itself is changing. In 71% of incidents involving Infoblox customers, the domain did not contain the brand name at all, which the page was impersonating. Instead of obvious lookalike domains, attackers are betting on realistic design and user experience. At the same time, phishing pages are becoming increasingly short-lived: in a campaign targeting 18 U.S. universities, URLs typically existed for less than 24 hours.
Another distinct trend is the abuse of legitimate internet infrastructure. For example, attackers gained control of reverse DNS zones in the .arpa space and used them to make links in spam emails appear more legitimate, then redirected victims through TDSs to short-lived phishing pages. An attack surface study also found that approximately one-third of outdated CNAME records, pointing to resources that no longer existed, could be relatively easily hijacked.
The report's key takeaway: attackers increasingly have little need for long-lived infrastructure. Modern campaigns rely on mass domain creation, rented services, automation, and the targeted delivery of malicious content — so the same IoC is increasingly unlikely to appear at a large number of organizations at once.
Vendors
Infoblox
Products
Threat Landscape Report 2026