Expired domains: the quiet gateway for malware delivery

Attackers are quietly snapping up expired domains to weaponize their lingering reputation, traffic, and DNS history, turning them into Trojan horses for malware delivery and scams. Every day, roughly 65,000 previously owned domains are re-registered, and Infoblox Threat Intel estimates that nearly one in five “new” domains has a prior life. While some end up in legitimate hands, a growing share is landing in the inboxes of cybercriminals who know that an old domain is worth more than a blank slate.
Why history is a double-edged sword
A domain that once hosted a Fortune 500 site or a cybersecurity firm carries signals that security tools and reputation engines still recognize. These signals can include cached search results, residual web traffic from backlinks, lingering DNS records, and even email still routed to the old owner. Threat actors exploit this inertia: they acquire the domain and repurpose it for malware distribution, illegal streaming platforms, or command-and-control infrastructure. In one tracked campaign, an actor dubbed Sable Squirrel spent nearly $7 million to amass over 10,000 expired domains, repurposing some as illegal sports-streaming hubs while using others as C2 servers for Quasar RAT, AsyncRAT, DCRat, and Remcos RAT.
The mechanics behind the abuse
The scale is not uniform. Among generic top-level domains, the average daily dropcatch volume is about 50,400, with 15 TLDs accounting for roughly 92% of all activity. The .net and .xyz zones see the highest reuse rates—nearly 30% of new registrations had prior owners—while .com sits at 24.5%. Determining who buys these domains and how they’re used remains difficult because of WHOIS privacy, transfers, auctions, and parking services. Yet the inherited value is not just a better reputation score; it is a ready-made platform for code injection on already compromised sites, an email stream still arriving at the old owner’s inbox, and even cached pages that point curious users straight into malware traps.
Why it matters
This abuse underscores a fundamental asymmetry in domain security: history is permanent, but ownership is fleeting. Organizations that let domains lapse risk handing attackers a shortcut past reputation filters, while defenders must now scrutinize not only new domains but also their shadow selves. The rise of dropcatch-driven attacks suggests that defensive strategies will need to evolve beyond simple domain age checks and include continuous monitoring of DNS and email routing, even for assets that no longer belong to the company.
Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

