AI-Powered Phishing Renders Traditional Blocklists Obsolete

Blocklists are losing the battle against phishing, and AI accelerates their decline into irrelevance. Attackers now use AI to generate convincing phishing pages from screenshots in minutes, spinning up and tearing down infrastructure faster than any blocklist tracks. According to Push Security, 89% of phishing domains remain active for fewer than two days, and a mere 6.5% survive past fifteen days. By the time a domain lands on a blocklist, the campaign has already moved on, leaving defenders matching stale indicators while real attacks target fresh infrastructure.

The core problem is that modern phishing operations are disposable by design. Attackers do not wait to get caught before pivoting—they proactively treat each piece of infrastructure as single-use, replacing pages before detection tools even register a threat. They also hide behind legitimate hosting platforms like Cloudflare Workers, Vercel, Azure, and Google Firebase, layering bot protection, referrer checks, and browser fingerprinting on top. Push Security finds that 95% of in-browser attacks employ some form of bot protection, meaning automated scanners and human researchers see entirely different pages than actual victims encounter.

AI dramatically lowers the cost and effort of launching these attacks as well. Where attackers previously clone legitimate pages through manual effort, they now generate entire phishing sites from a single screenshot using AI coding tools. This allows campaigns to iterate at unprecedented speed, testing variations and evading detection in real time. For organizations relying on known-bad indicators as their primary defense against phishing, the message is clear: indicator-based approaches no longer work, and proactive, behavior-driven detection is essential to staying ahead of threats that evolve by the minute.

Read More at the original source →