
Cybercrime Has Become an Industrialized Economy
Cybercrime has evolved from isolated attacks into a sophisticated, industrialized economy powered by frontier AI, automation and specialized criminal services. Today’s attackers operate less like opportunistic hackers and more like businesses—renting infrastructure, purchasing phishing kits, outsourcing money laundering and using AI to generate convincing social engineering campaigns at unprecedented speed and scale.
The 2026 Infoblox Threat Landscape Report examines this transformation by analyzing trillions of DNS queries, billions of underground criminal transactions and extensive original threat intelligence research. The findings reveal a fundamental shift: cybercrime is becoming faster, more automated and dramatically more efficient. What has emerged is a cybercrime machine—an ecosystem designed to continuously scale attacks while staying ahead of traditional security defenses.
The Numbers Behind the Cybercrime Machine
Between June 2025 and June 2026, Infoblox observed significant changes in both cybercriminal activity and enterprise exposure.
Key findings include:
- More than 22 percent of newly observed domains exhibited malicious or suspicious characteristics.
- 88 percent of threat-related domains were observed in a maximum of one environment, while 44 percent remained active for just one day.
- 96 percent of organizations encountered exposure to traffic distribution systems (TDSs), which attackers use to profile victims before redirecting them to phishing sites, malware or scams.
- 65 percent of organizations queried residential proxy networks, highlighting how attackers increasingly conceal their network activity.
- Enterprise DNS queries to AI applications increased 159 percent, reflecting rapid adoption of more than 100 AI applications, including ChatGPT, Microsoft Copilot, Claude, Cursor, Replit and Hugging Face, and a corresponding expansion of the enterprise attack surface.
Collectively, these findings show that cybercrime is becoming more distributed, more resilient and more difficult to detect. Attackers rapidly create and abandon infrastructure faster than traditional security tools can identify it, while increasingly abusing trusted internet services to blend malicious activity into legitimate traffic.
Cybercrime Now Operates as a Service-Based Economy
Perhaps the report’s most significant findings illustrate how cybercrime now functions as a mature, service-based economy.
Rather than building every component of an operation themselves, attackers assemble campaigns from specialized services available across underground marketplaces. Infrastructure, phishing kits, malware, traffic-routing services, fraud platforms and money laundering can all be purchased or rented on demand.
This specialization has fundamentally changed the economics of cybercrime. Capabilities that once required advanced technical expertise are now accessible to almost anyone willing to pay. AI accelerates this trend by reducing the cost and effort required to generate convincing phishing emails, fake websites, multi-lingual content and personalized social engineering campaigns. As barriers to entry continue to fall, the number of capable attackers continues to grow.
The result is an ecosystem optimized for efficiency, resilience and continuous growth, much like a legitimate digital business.
Attackers Are Hiding in Plain Sight
While many security programs remain focused on malware and known indicators of compromise, attackers are increasingly succeeding by abusing trusted internet infrastructure. Infoblox researchers observed widespread abuse of DNS, advertising technology, cloud platforms, reverse DNS (.arpa) and other legitimate internet services. By operating within trusted infrastructure rather than obviously malicious domains, attackers make malicious activity significantly more difficult to distinguish from normal business traffic.
TDSs have become a foundational component of modern cybercrime. Originally developed for legitimate digital advertising and traffic optimization, TDS platforms are now widely abused by attackers to selectively route victims to phishing pages, malware downloads, scam websites or exploit kits. Rather than sending every visitor to the same destination, a TDS profiles users based on attributes such as IP address, geographic location, browser type, operating system, language, device and referral source. Visitors who match an attacker’s targeting criteria are redirected to malicious content, while everyone else, including security researchers, automated scanners and search engine crawlers, may see harmless websites or be redirected elsewhere. This selective filtering helps attackers evade detection and extend the lifespan of their campaigns.
The report also highlights increasingly resilient attack infrastructure. Router compromise campaigns redirected victims through attacker-controlled recursive DNS resolvers hosted by bulletproof hosting providers, allowing attackers to remain hidden while maintaining highly durable operations.
The pattern is clear: attackers are investing as heavily in resilient infrastructure as they are in malware.
Intelligent, Personalized Lures
Attackers are also changing how they deceive victims. Rather than relying on generic phishing campaigns, they now create highly personalized lures tailored to a victim’s language, location, device and browsing behavior. AI enables attackers to generate realistic content at scale while selectively delivering attacks only to intended targets.
Brand impersonation remains one of the most effective social engineering techniques, but the tactics have evolved. Analysis of customer phishing incidents found that 71 percent of phishing domains did not include the impersonated brand name. Instead, attackers relied on authentic branding, realistic websites, familiar logos and polished user experiences to establish trust. The deception has shifted away from domain names and toward the overall user experience.
Credential Theft Has Become Identity Theft
The report also demonstrates how credential theft has evolved beyond usernames and passwords.
Investigations into Android malware-as-a-service uncovered banking trojans capable of intercepting SMS one-time passwords, fingerprinting devices, harvesting contacts, performing overlay attacks and even capturing facial biometrics through fraudulent know-your-customer (KYC) verification workflows. Attackers increasingly exploit users’ trust by mimicking familiar security and identity verification processes, making fraudulent interactions appear legitimate.
Attackers are no longer stealing credentials. They’re stealing complete digital identities.
The Enterprise Attack Surface Continues to Expand
Organizations continue to adopt AI applications, software-as-a-service (SaaS) platforms, cloud services and connected devices at an unprecedented pace. While these technologies accelerate innovation, they also create new opportunities for attackers.
The report shows cybercriminals increasingly targeting overlooked areas, including AI platforms, browser push notifications, DNS infrastructure, software supply chains, residential proxy networks and abandoned cloud resources.
Employees may unknowingly install applications that transform corporate devices into residential proxy endpoints. Developers may inherit compromised open-source software through trusted supply chains. Forgotten DNS records create opportunities for subdomain hijacking. Public AI assistants can unknowingly become distribution channels for malicious instructions.
The challenge is no longer simply a larger attack surface. It’s the lack of visibility into emerging infrastructure before attackers exploit it.
Why Preemptive Security Matters
The report concludes that reactive security alone can no longer keep pace with industrialized cybercrime. Disposable infrastructure gives defenders only a brief window to investigate before attackers abandon it and move to new infrastructure. Organizations must identify and disrupt malicious infrastructure before users ever interact with it.
DNS provides a unique advantage because nearly every internet transaction begins with a DNS lookup. By analyzing DNS activity at global scale, organizations can identify malicious infrastructure before phishing emails are opened, malware is downloaded or credentials are stolen.
Rather than responding after compromise, security teams can prevent many attacks before they begin.
Predictive Intelligence
The 2026 Infoblox Threat Landscape Report is more than an annual review of cyberthreats. It explains the structural changes reshaping cybercrime and why traditional security models are struggling to keep pace.
The report makes one point unmistakably clear: modern cybercrime is increasingly defined by infrastructure, automation and scale—not simply by malware.
Organizations that continue to rely solely on reactive security will find it increasingly difficult to defend against attackers operating as highly efficient digital enterprises. Those that adopt a predictive intelligence exploring the actors’ infrastructure will be better positioned to reduce risk before attacks reach users.
As cybercrime continues to industrialize, the effectiveness of cybersecurity solutions will be defined less by responding to incidents and more by disrupting the infrastructure that makes them possible.
Download the Infoblox 2026 Threat Landscape Report to explore the complete research, key findings and practical recommendations. For ongoing analysis of emerging threats, visit the Infoblox Threat Intel page.