ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Blocking threats is no longer enough

The standard response to a malicious domain has not changed much in twenty years. You block it for your customers, log it, and move on. The domain stays live. The attacker finds new targets. Nobody outside your customer base is any better off.

 

This is not a criticism of the security industry. For a long time, it was the best available option. It is no longer.

 

Modern cyber-criminal infrastructure does not work the way it used to. Attacks are not improvised. The economy behind them is industrialised, commoditised in ways that are still not fully appreciated outside the research community. A relatively small number of malware-as-a-service families, infostealers, phishing kits, loaders and remote access trojans account for a disproportionate share of real attacks. The implication is not obvious, but it matters enormously: if a small cluster of threats drives the majority of damage, disrupting that cluster delivers outsized returns. You are not protecting against one campaign. You are degrading the operational capacity of infrastructure that is simultaneously targeting hundreds of organisations.

 

That logic holds most strongly when you act early. Ransomware does not materialise from nowhere. It arrives via a loader, delivered by a phishing kit, hosted on infrastructure registered days before anyone clicked anything. Each of those stages is a point where the attack ends before the final payload deploys. Security teams have long understood this conceptually. The problem has been speed.

 

Identifying attacker infrastructure before it is used in live attacks requires processing volume and velocity that manual analyst workflows cannot match. We are registering and classifying hundreds of malicious domains every day, many of them within minutes of creation. That is an AI problem, and we treat it as one, as in some cases, the defenders are faster than the attack itself.

 

Closing that gap is a collaboration problem, and it requires partners who operate inside the DNS ecosystem rather than alongside it. One example is our partner CleanDNS. This is not a reporting service. Instead, it is operationally integrated with registrars and registry operators through contractual relationships, which means it can initiate suspension, sinkholing, or removal actions directly rather than flagging abuse and waiting. That distinction is everything. The reporting layer is not where the friction is. The friction is in what happens after a report lands, which is where most takedown efforts stall.

 

The workflow is this: a high-confidence malicious domain is identified, and a structured evidence package goes to CleanDNS immediately. CleanDNS processes the case and engages the relevant registrar or registry through existing channels. Where policy thresholds are met, the domain comes down. 

 

A domain we can name: jugbphm[.]click, a confirmed Lumma Stealer command-and-control domain. TrendAI automation flagged it after observing malicious C2 behaviour. It was blocked for the client’s customers seven minutes later. Six hours after that, with human review complete, it was passed to CleanDNS. Twenty-five hours from initial observation, the domain was gone from the internet entirely.

 

That timeline has since shortened. The verification rate on every domain shared through the programme has been 100%, which has removed the need for human-in-the-loop review. Escalation from observation to CleanDNS action now takes minutes.

 

The broader point is this: the cyber-crime economy is built on infrastructure being cheap and replaceable. Takedown efforts have historically not threatened that model because they were too slow and too fragmented to create real operational cost. That is what changes when detection speed and removal capability work together. Attackers are not deterred by the abstract possibility of takedown. They are deterred when the economics shift, when the infrastructure they paid for disappears before it earns anything back.

 

Detection without disruption leaves the underlying problem intact. The industry has spent decades refining the former. The latter is where the ceiling actually is.

 


 

Robert McArdle is Director of Cybercrime Research at Trend AI

 

Main image courtesy of iStockPhoto.com and stuartmiles99


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543