Attackers are exploiting expired domains by purchasing them and leveraging their existing reputation, traffic, and DNS history to deliver malware, conduct scams, and establish command and control infrastructure. Approximately 65,000 previously owned domain names are re-registered daily, with nearly 20% of new domain registrations in the first half of 2026 being "dropcatch" domains, which have a prior history1. These domains can end up in the hands of legitimate investors or researchers, but many are acquired by malicious actors who recognize the value of exploiting a domain's existing credibility. This tactic allows attackers to bypass traditional security measures and increase the likelihood of successful malware delivery. The reuse of expired domains poses a significant threat to online security, as it enables attackers to blend in with legitimate traffic and exploit trust in established domains, so practitioners must be vigilant in monitoring domain registrations and reputation to mitigate this risk.
Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware
⚡ High Priority
Why This Matters
Infoblox Threat Intel calls these dropcatch domains, and in the first half of 2026 they accounted for nearly 20% of all new domain registrations, meaning one in five.
References
- SecurityAffairs. (2026, August 15). Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware. *SecurityAffairs*. https://securityaffairs.com/197251/uncategorized/crooks-are-buying-your-expired-domains-and-using-them-to-deliver-malware.html
Original Source
SecurityAffairs
Read original →