Threat Intelligence

Cybercriminals Spend Millions Buying Expired Domains to Spread Scams and Malware

The Hacker News · 15 Aug 2026
Key Takeaway Regularly review and renew any domains your business owns, and be cautious of links to older or unfamiliar websites, as they may have been taken over by scammers.

Researchers at DNS threat intelligence firm Infoblox have identified a growing tactic among cybercriminals: buying up expired domains once they become available for re-registration. These domains, dubbed 'dropcatch domains,' often retain leftover web traffic and a degree of trust built up by their previous legitimate owners, making them valuable tools for malicious actors.

According to Infoblox, tens of thousands of these domains were acquired in a recent six-month period, representing a significant financial investment by threat actors — reportedly close to $7 million. Once in criminal hands, these domains are repurposed to redirect unsuspecting visitors to phishing pages, scam sites, or malware downloads, capitalising on the trust and search engine visibility the domains had previously earned.

This technique highlights how attackers are increasingly targeting overlooked corners of the internet's infrastructure rather than only building malicious sites from scratch. For small businesses, the risk lies in accidentally linking to, or being confused with, domains that have changed hands and now serve malicious content, as well as the broader danger of employees or customers landing on these repurposed sites.

domain security phishing malware DNS threats small business cybersecurity

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.