Infoblox report details growth of automated cybercrime infrastructure

0

Infoblox has released its 2026 Threat Landscape Report, arguing that cybercrime is increasingly organised as an industrialised economy that helps attackers operate and scale faster while evading traditional security controls.

The report analyses cybercrime across four areas: services used to run attacks at scale, infrastructure used to evade detection, the lures used to reach victims, and expanding attack surfaces within enterprises.

Infoblox said the findings draw on “trillions of DNS queries”, underground criminal transaction data and its own threat research. It reported that nearly 25 percent of 120 million newly observed domains were rated high or critical risk. The company also said 88 percent of threat-related domains were seen in only one customer environment, while 44 percent were active for a single day.

According to the report, the most prevalent threat affecting more than 95 percent of networks was traffic distribution systems (TDSs), which it described as infrastructure used to route victims to malware, phishing and scam campaigns. It also said 65 percent of its Threat Defense customers queried domains linked to residential proxy networks, which it said can be used to mask malicious activity as normal consumer internet traffic.

Infoblox also reported a 62 percent year-on-year increase in scam-related domains, driven by brand impersonation, identity theft and financial fraud.

“This year’s report documents the cybercrime machine, a globally connected criminal economy where frontier AI, specialised criminal services and hidden infrastructure have transformed how attacks are created, purchased and deployed,” said Dr. Renée Burton, vice president, Infoblox Threat Intel. “The most important shift is not that attackers have become more sophisticated. It’s that sophisticated capabilities have become widely accessible, changing the pace of cybercrime and challenging security strategies built primarily around detection and response.”

The company said the report depicts a shift from isolated attacks to an interconnected ecosystem supported by specialisation, automation and shared infrastructure, which it said reduces defenders’ time to respond and exposes limits in detect-and-respond strategies.

You can read the full report here.

Share.