Blocklists were already losing ground before AI entered the picture. Phishing domains have been getting shorter-lived for years, campaigns have been burning infrastructure faster, and the gap between blocklists and attacker campaigns keeps getting wider. AI just finished the job.
Attackers are using AI to generate phishing pages from screenshots in minutes, spin up and tear down infrastructure faster than any blocklist can track, and iterate on tooling at a cadence that makes indicator-based detection functionally useless.
89% of phishing domains are now active for fewer than two days, with just 6.5% surviving past 15 days. By the time a domain makes it onto a blocklist, the campaign has moved on and the infrastructure has been replaced.
If your primary defense against attacks delivered via malicious webpages like AiTM phishing, device code phishing, ClickFix, file downloads, malvertising and more relies on matching known-bad indicators, you’re always two steps behind.
Disposable by design








