Infoblox has published the 2026 Threat Landscape Report, which highlights how cybercrime has evolved into a globally industrialized activity that enables attackers to operate more quickly, scale more efficiently, and evade traditional defenses. The latest technological advances, such as state-of-the-art artificial intelligence, specialized services geared toward malicious activities, and hidden infrastructures, are accelerating this transformation, shortening organizations’ response times and underscoring the shortcomings of traditional detection-and-response security strategies.
The report analyzes malicious cyber activities across four dimensions: the industrialization of services, which allows large-scale attacks; hidden infrastructures that hinder or prevent detection; evolving lures that act as vectors against victims; and the expansion of the attack surface, which opens new access points to an organization’s IT infrastructure. Taken together, these four elements reveal how modern cybercrime operates and what organizations must do to stay ahead.
Key criminal trends
Infoblox Threat Intel, Infoblox’s security intelligence unit, has identified the major trends behind today’s evolution of cybercriminal activity. The key takeaways from this study are:
- Nearly 25% of the 120 million domains recently observed carried a high or critical risk, reflecting the enormous scale of disposable infrastructure that is providing resources for malicious activity.
- The most prevalent threat, affecting more than 95% of networks, was Traffic Distribution Systems (TDS), an ubiquitous and hard-to-detect infrastructure that directs victims toward malware, phishing, and fraud attacks.
- Ephemeral infrastructures: 88% of threat-related domains were observed in a single customer environment, while 44% were active for only one day, illustrating the scale of domain weaponization and the growing reliance on ephemeral infrastructures designed to evade defenders.
- 65% of Infoblox Threat Defense customers accessed domains associated with residential proxy networks, which attackers use to mask malicious activity as legitimate Internet user traffic, causing malicious traffic to blend with everyday network activity and go undetected.
- Fraud-related domains increased by 62% year over year, with targets such as identity impersonation, identity theft, and financial fraud.