Skip to content

DNS Exploits and Weaponized Domains on the Rise, According to Infoblox Report

A common attack involves exploiting dangling CNAMEs.

Blue padlock on red and blue grid
Image by jaydeep on Pixabay

Nearly every internet transaction begins with a DNS lookup, which creates a broad and rapidly expanding landscape for malicious attacks. During the period from June 2025 to June 2026, in fact, Infoblox researchers observed more than 120 million newly registered domains, 22% of which were weaponized or exhibited threat characteristics, according to the company’s 2026 Threat Landscape Report.

The report also highlights these key findings:

  • 88% of threat-related domains were observed in a maximum of one environment, while 44% remained active for just one day.
  • 96% of organizations encountered exposure to traffic distribution systems (TDSs), which attackers use to profile victims before redirecting them to phishing sites, malware or scams.
  • Enterprise DNS queries to AI applications increased 159%, reflecting rapid adoption of AI services, with a corresponding expansion of the enterprise attack surface.
  • 65% of organizations queried residential proxy networks, highlighting how attackers increasingly conceal their network activity.

Infoblox researchers additionally observed “widespread abuse of DNS, advertising technology, cloud platforms, reverse DNS (.arpa) and other legitimate internet services,” says Bart Lenaerts-Bergmans in a related blog post.

A common approach involves exploiting dangling CNAMEs, which point to cloud services or hostnames that no longer exist. “Attackers can claim these abandoned cloud resources — for example, by recreating an Azure Web App or GitHub Pages site with the same hostname — and gain control of a trusted subdomain,” the report explains.

“By operating within trusted infrastructure rather than obviously malicious domains, attackers make malicious activity significantly more difficult to distinguish from normal business traffic,” Lenaerts-Bergmans notes.

The report also examines the changing nature of cybercrime, stating that “today’s attackers operate less like opportunistic hackers and more like businesses — renting infrastructure, purchasing phishing kits, outsourcing money laundering, and using AI to generate convincing social engineering campaigns at unprecedented speed and scale.”

Get more details in the free Threat Landscape Report from Infoblox.

Add ADMIN IT Infrastructure & Operations on Google