How AI-powered phishing killed blocklists for good
AI-powered phishing has made blocklists functionally useless by generating phishing pages from screenshots in minutes, spinning up and tearing down infrastructure faster than any blocklist can track, and iterating on tooling at a cadence that makes indicator-based detecti…
Intelligence analysis by Llama

AI-powered phishing has made blocklists obsolete by generating phishing pages from screenshots in minutes, spinning up and tearing down infrastructure faster than any blocklist can track, and iterating on tooling at a cadence that makes indicator-based detection useless.
Imagine you're trying to catch a thief who keeps changing their disguise and moving to a new location. That's what's happening with AI-powered phishing, where attackers use AI to quickly change their tactics and make it hard to catch them.
Analysis
Disposable by Design
The problem isn't just that phishing infrastructure rotates quickly. Modern attacks are designed to be disposable from the outset. Attackers aren't waiting to get caught and then pivoting. They're proactively tearing down pages and spinning up new ones to stay ahead of detection, treating each piece of infrastructure as single-use by default.
The Tools Layer is Crumbling
For years, the middle of David Bianco's Pyramid of Pain offered a more durable detection surface. Instead of blocking individual domains, you could fingerprint phishing kits — their JavaScript structure, HTML patterns, code signatures — and write detections that survived across dozens or hundreds of campaigns even as infrastructure rotated. That layer is eroding. The phishing kit ecosystem now fragments through forking, AI-assisted development, and open-source-style code sharing faster than anyone can track.
Techniques that Survive
Genuinely new attack techniques still require human creativity to discover — an attacker has to identify a gap in how a legitimate protocol or feature can be subverted and operationalize it. That kind of innovation hasn't been automated, and detections built around how those techniques work can survive infrastructure rotation, tool proliferation, and kit fragmentation.
Key points
- AI-powered phishing has made blocklists functionally useless by generating phishing pages from screenshots in minutes, spinning up and tearing down infrastructure faster than any blocklist can track, and iterating on tooling at a cadence that makes indicator-based detection us…
- The rise of AI-powered phishing has made traditional blocklist-based defenses ineffective, leaving organizations vulnerable to attacks.
- Genuinely new attack techniques still require human creativity to discover, and detections built around how those techniques work can survive infrastructure rotation, tool proliferation, and kit fragmentation.
If organizations can adapt to the new reality of AI-powered phishing, they may be able to develop more effective defenses that can keep up with the attackers.
The rise of AI-powered phishing may lead to a situation where traditional blocklist-based defenses are no longer effective, leaving organizations vulnerable to attacks.



