In-region logging on Enterprise.Details
Secure Domains
AI & emerging threats

Quishing, Deepfake Lures and LLM-Written Phishing: Why 2026's Scams All Still Need DNS

QR codes that dodge email filters, deepfake voices that impersonate your CFO, and phishing emails written by LLMs with flawless grammar — the lure has never been more convincing. But every one of these attacks still ends the same way: a victim's device resolving a malicious domain. That constant is your defensive advantage.

By
Threat Research Team · Secure Domains
Published
July 16, 2026
3 min read
3 min read

Phishing used to announce itself: broken English, generic greetings, suspicious attachments. Generative AI erased those signals. Large language models now write fluent, personalised lures in any language — including Arabic tuned to regional business etiquette — while voice-cloning tools impersonate executives well enough to authorise wire transfers, and QR codes move the malicious link off the filtered channel entirely, onto the victim's personal phone.

Security-awareness training built on 'spot the typo' is losing to attackers whose typos are gone. Yet underneath the shape-shifting surface, the anatomy of the attack has not changed at all: the victim must eventually visit attacker-controlled infrastructure, and that visit begins with a DNS query.

The 2026 Lure Kit: QR, Voice, and Perfect Prose

Quishing — phishing via QR code — exploded because it hops the security boundary: the email gateway sees only an image, while the resolution happens on a phone that is often outside corporate controls. Deepfake vishing adds a human authority layer, with cloned voices directing victims to 'verification portals'. And LLM-generated campaigns now A/B-test their own lures, iterating faster than takedown services can respond.

What all three deliver is a URL. Behind every QR code is a domain. Behind every fake portal the deepfake voice recommends is a domain. Behind every flawless email's link is a domain — typically a newly registered look-alike, minted hours before the campaign and abandoned days after.

  • Quishing: QR codes routing victims to phishing domains via unmanaged mobile devices
  • Deepfake vishing: cloned executive voices directing staff to credential-harvesting portals
  • LLM-written spear phishing: fluent, personalised, multilingual — no typos to spot
  • Combosquatting and homoglyph domains impersonating trusted brands
  • Disposable infrastructure: domains registered hours before use, rotated daily

The Constant the Attacker Cannot Remove

An attacker can change the channel (email, SMS, QR, voice), the language, the sender and the story. What they cannot change is the mechanics of the internet: for a victim to reach the fake portal, a device must resolve the portal's domain. That single chokepoint is channel-agnostic — it does not matter whether the lure arrived by email gateway, personal WhatsApp or a poster in a car park.

This is why protective DNS has become the highest-leverage anti-phishing control of the AI era. It does not need to read the email, hear the voice or scan the QR code. It needs only to answer one question at resolution time: should anyone in this organization be visiting this domain right now?

How DNS Armor Breaks the Lure-to-Harvest Chain

DNS Armor attacks the disposable-infrastructure economics directly. Newly registered and low-reputation domains are treated with suspicion by default; AI models score domain strings for brand impersonation, homoglyphs and DGA patterns; and reactive domain discovery pivots from one confirmed phishing domain to the registration and hosting cluster around it — blocking the campaign's next hundred domains before they are ever used.

Because enforcement happens at the resolver, coverage extends wherever resolution is steered through DNS Armor: corporate networks, branch sites, roaming laptops and managed mobile devices alike. The QR code scanned in the car park meets the same wall as the link clicked at a desk.

  • Default suspicion for newly registered and never-seen domains
  • AI scoring of look-alike, homoglyph and brand-impersonation domains
  • Reactive discovery that blocks a campaign's related domains pre-emptively
  • Uniform enforcement for office, branch, roaming and managed mobile users
  • Resolution logs that show exactly who was targeted, for incident response

Conclusion

The AI arms race is transforming the lure, not the attack. However convincing the email, the voice or the QR code becomes, the campaign still lives or dies on whether the victim's device can resolve a malicious domain.

Fight the constant, not the shapeshifter. With AI-driven protective resolution from DNS Armor, the perfect phishing lure delivers its victim to a domain that no longer resolves — and the campaign fails at the only step it could never skip.

Learn how DNS Armor™ delivers DNS threat protection and sovereign authoritative DNS.

Stop threats at the first DNS query.

See how DNS Armor Protect™ blocks malware, phishing and tunnelling before a connection is made.