Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
Overview
Hackers are increasingly buying expired domains to take advantage of their existing traffic and credibility to misdirect users toward scams and malware. According to Infoblox, a firm that specializes in DNS threat intelligence, these domains—known as dropcatch domains—can be quickly registered after they expire. In the first half of 2026 alone, cybercriminals purchased over 50,400 of these domains, allowing them to exploit unsuspecting users. This practice poses significant risks as it can lead to increased phishing attacks and the spread of malicious software. Users and businesses need to be aware of these tactics to protect themselves from falling victim to these scams.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Expired domains, website traffic, internet users
- Action Required: Users should be cautious when clicking on links from unknown sources and businesses should monitor their expired domains closely.
- Timeline: Ongoing since 2026
Original Article Summary
Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given the name dropcatch domains to those that get a second chance, where an expired domain becomes available for registration and is then snapped up by another party. During the first half of 2026, 50,400
Impact
Expired domains, website traffic, internet users
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since 2026
Remediation
Users should be cautious when clicking on links from unknown sources and businesses should monitor their expired domains closely.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Phishing, Exploit, Malware.