Cybercrime is no longer a collection of isolated attacks. It has evolved into a sophisticated, service-based economy powered by frontier AI, automation and specialized underground services. Attackers now operate like businesses, renting infrastructure, purchasing phishing kits and using AI to generate convincing campaigns at unprecedented speed and scale.
The Infoblox 2026 Threat Landscape Report examines this transformation by analyzing trillions of DNS queries, billions of underground criminal transactions and extensive original threat intelligence research. The findings reveal a fundamental shift in how cybercrime operates and what it means for defenders.
What the Research Found
Between June 2025 and June 2026, Infoblox Threat Intel observed significant changes in both cybercriminal activity and enterprise exposure:
- More than 22 percent of newly observed domains exhibited malicious or suspicious characteristics.
- 88 percent of threat-related domains were observed in a single customer environment, while 44 percent remained active for just one day.
- 96 percent of organizations encountered exposure to traffic distribution systems (TDSs), which attackers use to profile and redirect victims to phishing, malware or scams.
- 65 percent of organizations queried residential proxy networks, highlighting how attackers conceal their activity within legitimate traffic.
- Enterprise DNS queries to AI applications increased by 159 percent, reflecting rapid adoption and a corresponding expansion of the attack surface.
Why It Matters
Attackers are no longer relying on obviously malicious infrastructure. They are hiding within trusted internet services, abusing DNS, advertising technology, cloud platforms and legitimate hosting to make malicious activity nearly indistinguishable from normal business traffic. The report also shows how personalized lures have evolved: 71 percent of phishing domains no longer include the impersonated brand name, relying instead on authentic branding and polished user experiences to build trust.
The pattern is clear. Disposable infrastructure gives defenders only a brief window to respond before attackers abandon it and move on. Organizations that can identify and disrupt malicious infrastructure before users interact with it hold a significant advantage.
Get the Full Report
Download the Infoblox 2026 Threat Landscape Report to explore the complete research, key findings and practical recommendations, and read our blog to learn more.
👇️Let us know your thoughts and questions below.