The most common form is domains: an operator bulk-registers names through registrars like Namecheap or NameSilo, pays with a stolen or prepaid card, hides the owner behind WHOIS privacy, and often registers a cluster of related names on the same day so one campaign can rotate through several before defenders block the first. A DNS server acquired alongside the domain lets the attacker control resolution directly, useful for fast-flux setups where the IP behind a domain changes every few minutes to dodge blocklists.
Servers, virtual private servers and botnets cover the compute side. Bulletproof hosting providers rent space with no abuse response, but plenty of operators instead abuse mainstream cloud accounts on AWS, Azure or DigitalOcean using stolen credit cards or compromised customer accounts, because traffic to a major cloud ASN blends in far better than traffic to a known-bad hosting block. Botnets are simply rented by the hour or day on criminal marketplaces, giving an attacker thousands of residential IPs to route credential-stuffing or C2 traffic through.
Web services, serverless platforms and malvertising are the newest and hardest to catch, because the infrastructure is legitimate and free. Adversaries stage phishing chains on services like webhook.site and image-hosting platforms, both real services defenders rarely block wholesale. Cloudflare Workers, Firebase Hosting and Discord's CDN get the same treatment for the same reason: the domain itself carries no reputation risk. Malvertising buys ad placements on real ad exchanges to redirect victims through a chain that ends on attacker-acquired infrastructure, all without registering a single suspicious domain up front.