Skip to content

AI-powered phishing renders classic blocklists ineffective

In brief: AI-generated, short-lived phishing infrastructure is outpacing classic blocklists, which is why Push Security recommends browser-based, technique-focused detection instead of indicator-based defense.

Attackers are using AI to spin up new phishing infrastructure by the minute and continuously modify their toolkits. According to an analysis by Push Security, domain- and signature-based blocklists can no longer keep up with this pace.

Push Security describes how generative AI tools largely automate the creation of phishing pages, domains and kits. This allows attackers to stand up and tear down infrastructure in a short amount of time: a domain is registered for a single campaign or even for individual victims and then discarded before it can be added to blocklists and distributed. Phishing kits themselves are also constantly varied, so that signature-based detection, which relies on known bad indicators such as domains, file hashes or URL patterns, misses its target.

For security leaders, this means that a core building block of classic defense architectures — threat intelligence feeds containing known malicious indicators — is structurally losing response speed. Because new infrastructure is created faster than it can be detected and added to feeds, the window in which a phishing page is active but not yet blocked is systematically shifting in favor of attackers. Blocklists therefore remain reactive and tend to lag behind the threat, regardless of how quickly feeds are updated.

Instead, Push Security advocates for technique-based detection at the browser level that targets typical behavioral patterns and techniques of phishing attacks — rather than known bad indicators — such as the interception of credentials in forms, the imitation of login pages, or suspicious redirect chains. Such approaches are designed to work regardless of whether a specific domain or kit is already known, and thus also to be effective against newly generated, previously unseen phishing infrastructure.

For CISOs, this creates a need to review existing defenses that primarily rely on blocklists and signatures, and to additionally plan for controls at the browser or endpoint level that detect attack techniques rather than individual indicators. This is particularly relevant to protection mechanisms against credential phishing, which are playing an increasingly central role within identity and access management strategies.


Source: www.bleepingcomputer.com · Published August 5, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: