Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware
Overview
Attackers are increasingly purchasing expired domain names to take advantage of their established online reputation and traffic. These domains, referred to as dropcatch domains, can be exploited for malicious purposes, including distributing malware, conducting scams, and setting up command-and-control (C2) infrastructure. Each day, around 65,000 domain names that have lapsed are re-registered by new owners, which presents a significant risk. This trend poses dangers to users and organizations as they may unwittingly interact with these compromised domains, leading to potential security breaches. Awareness of this tactic is crucial for internet users and companies to mitigate risks associated with these expired domains.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Expired domains used for malware delivery, scams, and C2 infrastructure.
- Action Required: Users and organizations should monitor domain registrations and be cautious when interacting with unfamiliar websites, especially those that might have previously been associated with legitimate businesses.
- Timeline: Ongoing since 2026
Original Article Summary
Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. Infoblox Threat Intel calls these dropcatch domains, and in the first half of 2026 they […]
Impact
Expired domains used for malware delivery, scams, and C2 infrastructure.
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since 2026
Remediation
Users and organizations should monitor domain registrations and be cautious when interacting with unfamiliar websites, especially those that might have previously been associated with legitimate businesses.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Exploit, Malware, Intel.