How AI-powered phishing killed blocklists for good

How AI-powered phishing killed blocklists for good
AI has made blocklist-based defense obsolete by enabling attackers to rapidly create, rotate, and disguise phishing infrastructure faster than indicators can be tracked. The article argues that lasting protection comes from technique-level behavioral detection, with examples including AiTM phishing, ClickFix, device code phishing, and novel attacks like InstallFix, ConsentFix, and LLMShare. #AiTM #ClickFix #DeviceCodePhishing #InstallFix #ConsentFix #LLMShare #PushSecurity

Keypoints

  • Phishing domains now disappear so quickly that blocklists often miss them.
  • Attackers use AI to build phishing pages and rotate infrastructure at high speed.
  • Trusted services like Cloudflare, Vercel, SharePoint, and Google Sites are widely abused.
  • Device code phishing, AiTM, and ClickFix are spreading through criminal toolkits.
  • Behavioral detections at the technique level are more durable than IOC-based defenses.

Read More: https://www.bleepingcomputer.com/news/security/how-ai-powered-phishing-killed-blocklists-for-good/