AI is helping attackers create disposable phishing infrastructure that blocklists can't track fast enough. Here's why browser-level, technique-based detection offers a more durable defense.
You know that sinking feeling when you realize a phishing email almost got you? The one that looked so legit, so perfectly on-brand, that you hovered over the link for a second too long? That feeling is about to get a whole lot more common.
Here's the uncomfortable truth: the old ways of spotting phishing are dying. Blocklists, signature-based filters, domain reputation checks—they're all struggling to keep pace with what AI is doing to cybercrime. And if you're still relying on them to protect your team, you're playing a game where the rules changed without you noticing.
### The Disposable Phishing Problem
Think about how phishing campaigns used to work. Attackers would register a domain, set up a convincing fake login page, and blast out thousands of emails. It was crude, but it worked. The problem? Security teams would catch those domains within hours, add them to blocklists, and the campaign would die.
AI changed that math completely. Now, attackers can spin up phishing infrastructure in minutes—domains, hosting, SSL certificates, the whole package—use it for a single wave of attacks, then abandon it. By the time your blocklist gets updated, the domain is already dead and replaced with a fresh one. It's like trying to swat flies with a calendar.
Push Security has been documenting this shift, and the picture is stark. Attackers aren't just using AI to write better phishing emails anymore. They're using it to build entire automated pipelines that generate and rotate infrastructure faster than any human-run defense can track.
### Why Blocklists Are Fighting Yesterday's War
Let me be clear: blocklists aren't useless. They catch the lazy attackers, the ones still using known malware domains or reusing old infrastructure. But the problem is that they're fundamentally reactive. They only work against things we've already seen and cataloged.
- Blocklists rely on known-bad indicators
- AI generates novel phishing kits at machine speed
- Each campaign can use unique, never-before-seen infrastructure
- By the time a domain is flagged, the damage is already done
It's a classic asymmetric warfare problem. Defenders have to be right every time. Attackers only have to be right once. And with AI, attackers get to be wrong a thousand times without any real cost.
### The Shift to Technique-Based Detection
So what's the alternative? Push Security argues—and I think they're onto something—that we need to stop focusing on what's bad and start focusing on how attacks actually work. Instead of asking "is this domain known to be malicious?", we should be asking "is this behavior consistent with phishing?"
This is called technique-based detection, and it happens at the browser level. It doesn't care about specific domains or malware signatures. Instead, it watches for the behavioral patterns that all phishing attacks share, regardless of the infrastructure behind them.
Think of it like this: a burglar might change their clothes, dye their hair, and use a different car each time. But they still have to break a window, jimmy a lock, or pick a door. Technique-based detection watches for the breaking-in, not the disguise.
### What This Means for Your Security Posture
If you're a security professional, this shift should change how you think about your defenses. The question isn't whether your blocklist is good enough anymore. It's whether you have visibility into what's actually happening in your users' browsers.
> "The most durable defenses aren't the ones that know every attack. They're the ones that recognize the patterns that no attack can avoid."
Browser-level detection gives you that visibility. It sees the moment a user interacts with a suspicious page, the moment credentials are entered into a lookalike form, the moment a session is being hijacked. It doesn't need to know the attacker's domain to know something's wrong.
### The Bottom Line
AI-powered phishing isn't coming. It's here. And it's already rendering blocklist-based defenses obsolete. The attackers who are still using static domains and predictable infrastructure are the ones falling behind. The smart ones—the dangerous ones—have already moved on.
If you're still betting your security program on known-bad indicators, it's time to ask yourself some hard questions. Can your current tools detect a phishing campaign that has never been seen before? Can they catch an attack that uses infrastructure created five minutes ago? If the answer is no, you're not defending against the threat that actually exists.
The future of phishing defense isn't about knowing more bad things. It's about understanding the techniques that no attacker can give up, no matter how much AI they throw at the problem. That's the shift that matters.