Ethical Hacking News
A new trend in cyber threats is the exploitation of expired domains to deliver malware. Attackers are buying expired domains to exploit their reputation, traffic, and DNS history, using them for malware delivery, scams, and C2 infrastructure. The threat of exploited expired domains is a growing concern, and defenders should be vigilant in monitoring their domain's reputation and security.
Expired domains are being exploited for malware delivery, scams, and C2 infrastructure. Attackers buy expired domains to leverage their reputation, traffic, and DNS history. Every day, around 65,000 domain names are re-registered by new owners, many of whom are attackers. Infoblox tracked a threat actor, Sable Squirrel, who spent $7 million on expired domains for malicious activities. Domain age and reputation can be valuable inputs for threat actors, making it important for defenders to be cautious with expired domains. Exploited expired domains are a growing concern, and defenders should monitor their domain's reputation and security.
The dark web is a breeding ground for cyber threats, and a new and emerging trend is the exploitation of expired domains to deliver malware. According to a recent report by Infoblox Threat Intel, attackers are buying expired domains to exploit their reputation, traffic, and DNS history, using them for malware delivery, scams, and C2 infrastructure.
Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. These dropcatch domains are often acquired by attackers who have figured out that a domain with history is worth more than a blank slate. The report states that these domains can be particularly interesting, even dangerous, because they inherit reputation and sometimes connections from their previous life.
Infoblox tracked one threat actor, Sable Squirrel, which has spent nearly $7 million acquiring expired domains to build a criminal operation spanning illegal sports streaming, gambling promotion, and malware infrastructure. Sable Squirrel controls more than 10,000 domains and runs streaming platforms under brands like Xoilac, Cakhia, and 90phut that direct Vietnamese, Korean, Japanese, and Australian users toward betting sites, while a subset of those same streaming domains double as command-and-control servers for malware including Quasar RAT, AsyncRAT, DCRat, and Remcos RAT.
The report also highlights the importance of domain age and reputation, which can be valuable inputs for threat actors. However, this also means that defenders should question, not trust, old domains in new hands. The practical lesson for defenders is to be cautious when dealing with expired domains, as they may be used for malicious purposes.
Infoblox tracked three other scavenger actors, Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel, that operate differently. These actors acquire expired domains that were previously compromised by other attackers and simply inherit the existing infection traffic. Shady Squirrel, assessed to be Russian-speaking and active since at least July 2023, feeds that traffic to SocGholish and tech support scam networks.
The threat of exploited expired domains is a growing concern, and defenders should be vigilant in monitoring their domain's reputation and security. The fact that a domain with history can be worth more than a blank slate highlights the importance of keeping an eye on domain registrations and monitoring for suspicious activity.
Related Information:
https://www.ethicalhackingnews.com/articles/Crooks-Are-Exploiting-Expired-Domains-to-Deliver-Malware-A-Growing-Threat-ehn.shtml
https://securityaffairs.com/197251/uncategorized/crooks-are-buying-your-expired-domains-and-using-them-to-deliver-malware.html
Published: Sat Aug 15 21:22:04 2026 by llama3.2 3B Q4_K_M