Post

Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware

Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware

Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware

🚨 Attackers are exploiting expired domains! They are purchasing these domains to take advantage of their reputation, traffic, and DNS history, using them for malware delivery, scams, and command-and-control (C2) infrastructure. Every day, around 65,000 domain names that once belonged to someone else are re-registered by new owners. Infoblox Threat Intel refers to these as dropcatch domains, which accounted for nearly 20% of all new domain registrations in the first half of 2026. This means that one in five “new” domains has a prior life.

🔍 These domains can be particularly interesting, even dangerous, as they inherit reputation and sometimes connections from their previous life. Researchers, security products, and reputation-based algorithms may view them more favorably than genuinely brand-new registrations. Threat actors are well aware of this and take full advantage of it.

💰 The inherited value isn’t just a better reputation score. Expired domains also come with residual web traffic from old backlinks, emails still arriving for the previous owner, cached search results, and sometimes lingering DNS records that point to infrastructure no longer under the original owner’s control. Infoblox tracked one threat actor, dubbed Sable Squirrel, who has spent nearly $7 million acquiring expired domains to build a criminal operation spanning illegal sports streaming, gambling promotion, and malware infrastructure. This actor controls over 10,000 domains and runs streaming platforms under brands like Xoilac, Cakhia, and 90phut, directing users from Vietnam, Korea, Japan, and Australia toward betting sites. A subset of these streaming domains also serves as command-and-control servers for malware, including Quasar RAT, AsyncRAT, DCRat, and Remcos RAT.

📈 Among the expired domains acquired by Sable Squirrel are healthymagination.com, originally a General Electric health initiative, and rezilion.com, a cybersecurity company whose assets were sold to GitLab in 2024. Once Sable Squirrel re-registers a domain, it acts quickly: 24% go live the same day, 76% within seven days, and 94% within two weeks.

🦠 Infoblox is also tracking three scavenger actors: Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel. Unlike Sable Squirrel, these actors acquire expired domains previously compromised by other attackers, simply inheriting the existing infection traffic. For instance, Shady Squirrel, assessed to be Russian-speaking and active since at least July 2023, feeds that traffic to SocGholish and tech support scam networks. SocGholish reportedly regained access to thousands of compromised sites by teaming up with Shady Squirrel shortly after its infrastructure was disrupted by law enforcement.

⚠️ The practical lesson for defenders is uncomfortable: domain age and reputation are inputs worth questioning, not trusting. An old domain in new hands is only as trustworthy as whoever currently holds it. This illustrates just one story of how threat actors use dropcatch domains to further their schemes.

Read full article

This post is licensed under CC BY 4.0 by the author.