Threat Intelligence

Cybercriminals invest millions in expired domains for illicit activities

Domain names - internet and web telecommunication concept. 3d rendering

Cybercriminals are investing millions of dollars to acquire expired domain names and repurpose them for various malicious activities, including malware distribution, scams, illegal streaming, and online gambling, according to a recent report by Infoblox Threat Intel, as covered by IT Pro.

These "dropcatch" domains are attractive to threat actors because they retain trust, backlinks, and web traffic from their previous legitimate use, making them appear more favorable to security systems than new registrations. Analysis shows approximately 65,000 such domains are registered daily, accounting for nearly one in five new domains. One investigation identified an actor, Sable Squirrel, who spent over $7 million on more than 10,000 expired domains used for illegal streaming and malware command and control. These domains often host seemingly legitimate streaming sites while simultaneously serving as C2 channels for malware like Quasar RAT and HiddenTear ransomware.

Another group, Shady Squirrel, has partnered with the notorious "fake update" infrastructure SocGholish, delivering malware through scareware and call centers. The significant volume and inherent trust associated with these repurposed domains pose a substantial risk, arguably greater than that of newly registered domains.

Source: IT Pro

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds