Phishing infrastructure is built to be thrown away. When a domain gets blocklisted, scrutinized, or too hot to handle, the attackers don't stop. They just move. To them, a domain extension is just a cheap tool. They go wherever it is easiest to strike. That pattern is visible in our own telemetry. In late 2024 and early 2025, KnowBe4 Threat Lab documented a 98% spike in phishing campaigns abusing.ru domains. 1,500 unique domains, over 13,000 malicious emails, with an average domain age of just 7.4 days.