LIVE · cybersecurity feed
Live wire
malware

Cybercrime goes subscription: AI, malware and infrastructure on demand

Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These services provide anonymity, plausible deniability, and access to short-lived infrastructure that is difficult to detect, attribute, and disrupt, enabling low-skilled actors to operate at scale, according to the Infoblox 2026 Threat Landscape Report.

zeroday.news · 2d ago

Cybercrime has evolved into a sophisticated, commercialized ecosystem where nearly every component needed to launch advanced attacks is available for purchase or rent. This model provides anonymity and plausible deniability to threat actors, granting them access to ephemeral infrastructure that is challenging to detect, attribute, and disrupt. This enables even less skilled individuals to operate at scale, according to the Infoblox 2026 Threat Landscape Report.

The report highlights that cybercrime is becoming increasingly efficient, automated, and difficult to counter, driven by economic factors and the emergence of frontier AI. The distinction between financially motivated and state-sponsored actors has blurred within this complex economy, allowing criminals to evade disruption through segmentation and the adoption of commodity services. The cybercrime ecosystem continues to expand and specialize, with profits attracting more participants, enabling attackers to evolve more rapidly than defenders.

AI is playing a significant role in automating reconnaissance, generating highly convincing lures, and accelerating the speed and scale of attacks. High-profile individuals, including executives, are particularly vulnerable as threat actors exploit their identities for impersonation fraud, business email compromise (BEC), and social engineering schemes. Service providers and telecommunications companies are also at risk, as their platforms and infrastructure are frequently abused to facilitate these attacks.

Cybercrime services encompass marketplaces for various illicit activities, including "pig-butchering" scam operators, AI-generated lures, Android banking trojans, and infrastructure supporting illegal gambling operations. One observed Android banking trojan attack chain demonstrated the ability to capture one-time passwords, device fingerprints, contacts, and facial biometrics, allowing criminals to steal complete digital identities and sustain account compromise and fraud.

Scam campaigns leveraging DCloud-based infrastructure include fake cryptocurrency exchanges, pig-butchering schemes, phishing sites, wallet drainers, gambling portals, and fraudulent investment platforms. These campaigns primarily target consumers but can expose enterprise networks when employees encounter malicious links during personal browsing on corporate or personal devices.

To evade detection, attackers rely on infrastructure that appears legitimate or is concealed. They profile visitors based on device, location, and behavior, delivering scams or malware only to intended targets while showing harmless content to security researchers and automated scanners. Cloaking and traffic distribution systems further hide malicious activity behind trusted advertising domains and redirect chains, reducing visibility into campaigns. Bulletproof hosting providers support these operations by prioritizing anonymity, ignoring abuse reports, and enabling rapid infrastructure migration, allowing phishing, fraud, malware, and other illicit activities to persist.

Threat actors frequently abuse trusted infrastructure because it increases success rates, reduces costs, conceals activity, improves resilience, and can provide access to users or networks that would otherwise be difficult to reach. Fake CAPTCHA scams, for instance, trick mobile users into sending expensive international text messages through fraudulent human-verification pages. One observed instance generated approximately 60 messages, costing the victim around $30, by combining social engineering with automated infrastructure to generate revenue at scale.

Brand impersonation and fraud pose significant risks to organizations through their customers. Once customer credentials and personally identifiable information are leaked into the criminal ecosystem, attackers may reuse the data to extort organizations, develop new lures, and stage further attacks. Criminals create phishing pages that closely resemble legitimate websites, replicating branding, logos, and user experiences rather than solely relying on domains containing the impersonated company's name. Selective targeting leaves fewer traces, making campaigns more challenging for security teams, email providers, and researchers to identify.

The widespread use of smartphones for both work and personal activities is exploited by threat actors who develop personalized lures that appear relevant and trustworthy. Short-lived campaigns help attackers evade blocklists and detection by rotating domains, hosting providers, and URLs; some phishing pages remain active for less than 24 hours, significantly reducing the window for investigation.

New technologies and expanding attack surfaces create security gaps before organizations can establish adequate monitoring and protection. Security teams must identify ownership, collect data, build detections, update policies, and train staff, providing attackers with time to exploit these vulnerabilities. Residential proxy services route internet traffic through everyday devices such as phones, laptops, and smart TVs, making malicious activity appear to originate from legitimate residential IP addresses, which complicates blocking and attribution. These proxies are often embedded in mobile applications and software development kits, and organizations may not realize that employee devices have become proxy endpoints, with the resulting traffic appearing as legitimate application activity.

Browser push-notification schemes trick users into granting permissions through fake CAPTCHAs, cookie banners, and verification prompts. Once permission is granted, attackers gain a persistent communication channel to the victim's device. Some victims have reported receiving over 140 notifications per day promoting investment scams, gambling sites, fake antivirus alerts, government impersonation scams, and other fraudulent content.

Organizations also face risks from dangling CNAME records. As cloud infrastructure changes, some CNAME records may persist after cloud services or hostnames are removed. Attackers can claim abandoned cloud resources, including Azure Web Apps and GitHub Pages sites using the same hostname, and take over trusted subdomains. During the Infoblox EASM early access program, one-third of identified dangling CNAMEs were found to be easy or trivial to take over. Attackers can then use these subdomains for phishing, malware delivery, or other malicious activities.

Threat actors are also targeting software supply chains to reach a large number of victims through trusted software, libraries, and development tools. In 2026, TeamPCP reportedly compromised Trivy, KICS, LiteLLM, and the Telnyx Python SDK. Access to software used by developers and security teams creates opportunities to steal credentials and spread malicious code through downstream environments.

malwareai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

SabPaisa Partners with AccuKnox for Zero Trust AI-Powered Cloud Security to Secure Its Payments Platform

CALIFORNIA, USA, 2nd August 2026, CyberNewswire

cloud

Welcome to Agents Week

Agents Week explores how cloud infrastructure must evolve to serve autonomous agents rather than human browsers. Join us as we unpack the storage, execution, and security primitives needed for an agent-native web.

security

Google Chrome may soon block New Tab hijacker extensions by default

Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]

breach

Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Nono: Open-source sandbox for AI agents AI coding agents run with the same permissions as their users, meaning they can access sensitive files, credentials, and production systems. A prompt injection, hallucinated command, or simple mistake can quickly turn that access into a security incident. To red

breach

CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks

After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water utilities across the state, according to Minnesota IT Services (MNIT). “A coordinated cyberattack targeted operational technology [

security

Atomic MacOS (AMOS) stealer infection, (Sun, Aug 2nd)

Introduction