Cybercriminals improve the resilience of their infrastructure to evade detection and law enforcement take down by utilizing fast flux/double flux infrastructures and/or infrastructures with low reputation. In essence, they frequently rotate hosting IPs, often compromised, and domains utilized to carry out their attacks. For example, we have observed that APTs such as Trident Ursa (Gamaredon, Primitive Bear) and Stately Taurus (Mustang Panda), and malware families such as QakBot and SmokeLoader rotate hundreds of IPs and domains in a short period of time, allowing them to persist for years. By the time current technologies detect these IOCs, attackers have already moved on to a different infrastructure, making such detections less effective. Thus, we need an approach that can proactively discover where the attackers are heading to in order to block them effectively. Based on the observation that cybercriminals tend to reuse similar hosting infrastructure over time, pivoting on known IOCs (domains, IPs, SHAs, certificates, emails) as seed, we first build the network infrastructure using a smart crawling technique which assists in constructing manageable graphs with high toxicity. Then, we build a graph AI model over the discovered network infrastructure to identify patient-zero malicious domains, SHA256s and IPs belonging to different campaigns. Using our discovery and detection techniques, we have been tracking hundreds of campaigns/APTs and discovering many new campaigns (e.g. ApateWeb, QuantumAI). Our analysis showed that many newly detected network artifacts (domains, IPs, SHA256s) are not identified by popular domain lookup services such as VirusTotal at the time of detection. They usually appear in VirusTotal after days to weeks from our detection time, showing the proactiveness of our approach. In this talk, we first show how we leverage smart crawling and Graph AI to detect stealthy malicious domains, malicious files and compromised/low reputation IPs used by various attack campaigns. In particular, we provide in-depth case studies of discovered malicious infrastructure of Gamaredon, FIN7 APTs and a postal campaign, including how they evolved over time.