News Security

Infoblox Report Reveals Rise of AI-Powered Cybercrime Economy

Renée

New threat intelligence findings show how automation, AI, and criminal service marketplaces are transforming cybercrime into a highly scalable global industry

Infoblox has released its 2026 Threat Landscape Report, warning that cybercrime has evolved into a sophisticated and highly industrialized economy powered by artificial intelligence, automation, specialized criminal services, and hidden internet infrastructure. The report paints a picture of a cybercriminal ecosystem that increasingly resembles a global business network, complete with supply chains, service providers, automation tools, and scalable attack platforms.

Drawing on analysis of trillions of DNS queries, billions of underground transactions, and extensive threat intelligence investigations, the report reveals how cybercriminals are leveraging advanced technologies to launch attacks faster, evade detection more effectively, and operate at unprecedented scale.

According to the findings, nearly 25 percent of 120 million newly observed domains were categorized as high or critical risk, highlighting the massive volume of malicious infrastructure being created and deployed by threat actors. The report suggests that cybercriminals are increasingly relying on disposable and short-lived digital assets that can be rapidly replaced whenever they are detected or blocked.

One of the most significant findings centers on the growing use of Traffic Distribution Systems (TDSs), which were identified as the most prevalent threat affecting more than 95 percent of monitored networks. These systems act as hidden routing mechanisms that direct victims toward phishing pages, malware downloads, scam websites, and other malicious content while remaining difficult for traditional security tools to detect.

“The most important shift is not that attackers have become more sophisticated. It’s that sophisticated capabilities have become widely accessible, changing the pace of cybercrime and challenging security strategies built primarily around detection and response.”

Dr. Renée Burton, Vice President, Infoblox Threat Intel

The report also highlights how attackers are increasingly using short-lived domains to outpace defenders. Nearly 88 percent of threat-related domains were observed in only a single customer environment, while 44 percent remained active for only one day. This rapid turnover makes it increasingly difficult for conventional security tools that rely on historical threat intelligence and reputation databases.

Another growing concern is the expanding use of residential proxy networks, which disguise malicious traffic as legitimate consumer internet activity. Infoblox found that 65 percent of its Threat Defense customers queried domains associated with these networks. By routing attacks through seemingly legitimate residential internet connections, cybercriminals can blend into normal online activity and evade traditional monitoring systems.

The report also identifies a dramatic rise in online fraud. Scam-related domains increased 62 percent year-over-year, driven largely by brand impersonation campaigns, identity theft schemes, financial fraud operations, and increasingly sophisticated social engineering attacks. These scams are often supported by AI-generated content and automated infrastructure that enables attackers to reach larger numbers of targets while reducing operational costs.

According to Dr. Renée Burton, Vice President of Infoblox Threat Intel, modern cybercrime has transformed into a globally connected ecosystem where specialized criminal services can be purchased on demand. Attackers no longer need deep technical expertise because sophisticated capabilities have become accessible through cybercrime marketplaces that provide infrastructure, malware, phishing kits, proxy services, and AI-powered tools.

The report argues that this shift represents a fundamental challenge to conventional cybersecurity strategies. Many security programs continue to focus primarily on detecting and responding to threats after they appear. However, the speed, scale, and automation of modern cybercrime are compressing response times and reducing the effectiveness of traditional defense models.

Instead, organizations are being encouraged to adopt more proactive security approaches that focus on disrupting malicious infrastructure before attacks occur. Greater visibility into DNS activity, threat intelligence, network behaviors, and infrastructure-level indicators is becoming increasingly important as attackers continue to exploit automation and AI to accelerate their operations.

The findings underscore a broader reality facing enterprises worldwide: cybercrime is no longer driven primarily by isolated hackers. It has evolved into a highly organized digital economy where criminal services, AI technologies, and automated attack infrastructure enable adversaries to launch large-scale operations with unprecedented efficiency.

As AI continues to reshape both legitimate business operations and criminal activity, the report suggests that organizations must rethink how they defend against threats in an era where cyberattacks are increasingly automated, scalable, and designed to outpace traditional security controls.

Related posts

Veeam Unveils Data Cloud Vault Archive for Secure, Cost-Effective Long-Term Backup Retention

Enterprise IT World MEA

Veeam Launches Data Platform v13.1 to Strengthen Cyber Recovery and Data Resilience

Enterprise IT World MEA

DXC and ElevenLabs Partner to Advance Enterprise Voice AI Innovation

Enterprise IT World MEA

Leave a Comment