AI Phishing Ends Blocklists: The New Era of Cybersecurity
Blocklists have become ineffective against AI-powered phishing attacks that evolve faster than static defenses can track.
The Decline of Blocklists
Blocklists have been losing relevance for years as phishing operations evolve to outpace static detection methods. The rapid lifecycle of phishing domains, the accelerated deployment of malicious infrastructure, and the widening gap between threat activity and defensive measures have all contributed to this decline.
AI’s Role in Accelerating Attacks
The integration of artificial intelligence has accelerated this shift, enabling attackers to create, deploy, and discard phishing assets at unprecedented speeds. Modern phishing campaigns now operate with a lifecycle measured in hours rather than days. Data reveals that 89% of phishing domains are active for less than 48 hours, with only 6.5% persisting beyond 15 days. By the time these domains are added to blocklists, the associated campaigns have already transitioned to new infrastructure.
Disposable Infrastructure
This dynamic renders traditional indicator-based defenses ineffective, particularly against sophisticated techniques such as AiTM phishing, device code phishing, and ClickFix attacks. The core challenge lies in the disposable nature of contemporary phishing infrastructure. Attackers no longer rely on static assets; instead, they design campaigns to be single-use by default. This approach minimizes the risk of detection and analysis.
Challenges in Modern Phishing
Malicious pages are frequently hosted on trusted platforms such as Cloudflare Workers, Vercel, Microsoft Dynamics, Google Firebase, and others, which are leveraged to obscure their presence. These platforms often incorporate bot protection mechanisms, referrer checks, and browser fingerprinting to differentiate between automated scanners and real users. As a result, the content visible to security tools differs significantly from what end users encounter.
AI-Generated Phishing Pages
AI has further disrupted traditional defenses by reducing the cost and complexity of creating phishing pages. Attackers can now generate fully functional phishing sites from screenshots of legitimate login pages, producing unique frontends that evade static analysis. These pages are often indistinguishable from their authentic counterparts, making detection through conventional methods nearly impossible.
Exploitation of Legitimate Services
Phishing campaigns increasingly exploit legitimate services such as AI chatbot sharing features, search ad placements, and in-app messaging to leverage the reputations of trusted platforms. This tactic ensures that malicious domains are not flagged by standard blocklists.
Behavioral Detection as a Solution
The erosion of the Pyramid of Pain layer has compounded these challenges. Historically, phishing kits provided a stable surface for detection through their JavaScript structures, HTML patterns, and code signatures. However, the proliferation of AI-assisted development and open-source-style code sharing has fragmented this layer. Phishing kits now evolve rapidly, with new variants emerging faster than defenders can track.
Resilient Attack Techniques
Device code phishing exemplifies this trend, having transitioned from niche use in 2024 to widespread adoption by 2026. Over 25 distinct kits, including EvilTokens, Kali365, and ARToken, now offer device code phishing capabilities, often integrated with admin panels that allow attackers to control payload delivery dynamically.
Behavioral Signatures
Despite these challenges, certain attack techniques remain resilient to infrastructure changes. Adversary-in-the-middle (AiTM) phishing, ClickFix, and device code phishing all rely on consistent behavioral patterns. For example, AiTM kits such as Tycoon 2FA and Evilginx employ similar interception mechanisms, regardless of their frontend design or hosting infrastructure. Similarly, ClickFix attacks consistently manipulate user clipboards to execute payloads, even as lure techniques evolve.
A recent example highlights the effectiveness of behavioral detection. Microsoft identified a novel phishing technique that exploited OAuth error-handling redirects to bypass domain reputation checks. Push Security’s agentic threat hunting pipeline, which uses AI to analyze browser telemetry, detected this method by focusing on the underlying behavioral pattern rather than specific indicators. Months later, the same detection identified a different campaign using the same technique, despite variations in lures, domains, and phishing kits. This case underscores the limitations of blocklists and tool-based signatures, which would have failed to recognize the attack.
The Future of Cybersecurity
Push Security’s approach demonstrates the potential of technique-level detection. By prioritizing behavioral analysis over static indicators, the company has protected over 60 customers from novel phishing techniques, intercepting approximately 225 threats before they could compromise accounts or deliver malware. This strategy relies on continuous monitoring of browser activity and rapid deployment of detections that adapt to evolving attack patterns.
Conclusion
The shift from blocklists to behavioral detection represents a fundamental change in cybersecurity strategy. As AI continues to empower attackers, traditional defenses will struggle to keep pace. Organizations must adopt solutions that prioritize understanding how attacks operate, rather than relying on outdated indicators. This transition requires investment in advanced monitoring tools and agile research capabilities to address the accelerating threat landscape.
