Attackers are exploiting a loophole in the domain registration process by purchasing expired domains, which are then used to deliver malware, conduct scams, and establish command and control infrastructure. Approximately 65,000 previously owned domain names are re-registered daily, with nearly 20% of new domain registrations in the first half of 2026 being "dropcatch domains" that have a prior history1. These domains are attractive to attackers due to their existing reputation, traffic, and DNS history, making them ideal for malicious activities. As a result, one in five newly registered domains has a prior life, posing a significant threat to online security. This tactic allows attackers to leverage the trust associated with established domains, making it more challenging for security systems to detect and prevent malicious activities. The reuse of expired domains for malicious purposes highlights the importance of monitoring domain registrations and tracking changes in domain ownership to prevent such threats.
Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware
⚡ High Priority
Why This Matters
Infoblox Threat Intel calls these dropcatch domains, and in the first half of 2026 they accounted for nearly 20% of all new domain registrations, meaning one in five.
References
- SecurityAffairs. (2026, August 15). Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware. SecurityAffairs. https://securityaffairs.com/197251/cyber-crime/crooks-are-buying-your-expired-domains-and-using-them-to-deliver-malware.html
Original Source
SecurityAffairs
Read original →