The Hidden Danger of Expired Domains: How Cybercriminals Are Buying Digital Reputation and Turning Old Websites Into Malware Infrastructure + Video

Listen to this Post

Featured Image

Introduction: The Internet Never Truly Forgets

A domain name may disappear from the internet, but its history does not necessarily disappear with it.

Every day, tens of thousands of domain names that once belonged to businesses, organizations, developers, researchers, or ordinary individuals are registered again by completely different owners. To an unsuspecting visitor, these domains can look legitimate. They may be years old, have backlinks from reputable websites, appear in search indexes, and carry a digital history that a newly created domain could never have.

That history has become a commodity.

According to research from Infoblox Threat Intel, roughly 65,000 previously registered domains are re-registered every day. During the first half of 2026, these so-called dropcatch domains represented almost 20% of all new domain registrations. In other words, approximately one out of every five domains entering the registration ecosystem is not truly new.

For cybersecurity teams, that statistic should be uncomfortable.

A brand-new malicious domain is often easy to identify. It has no history, no meaningful backlinks, little reputation, and frequently appears alongside other suspicious infrastructure. An expired domain can be completely different. It may arrive with years of accumulated trust signals, residual traffic, old DNS relationships, cached content, and email intended for its previous owner.

The attacker is not starting from zero.

They are buying the past.

What Is a Dropcatch Domain?

A dropcatch domain is generally a previously registered domain that expired and became available for someone else to register. The new owner may legitimately purchase it because of its name, traffic, backlinks, or investment potential.

But cybercriminals have discovered another advantage: the domain can retain characteristics associated with its former life.

A domain registered ten years ago can appear very different from a domain created yesterday. Reputation systems, search engines, security products, advertisers, and automated scanners may all consider historical signals when evaluating websites.

That creates an opportunity for abuse.

Why an Old Domain Can Look More Trustworthy

Security systems frequently rely on multiple signals when deciding whether a domain deserves attention.

Domain age can be one of those signals.

It is not supposed to be a guarantee of safety. An old domain can obviously become malicious. But in large-scale automated environments, reputation is often calculated using many imperfect indicators.

An attacker understands this difference.

Instead of creating completely-new-malicious-domain.example, an attacker can acquire an established domain that has existed for years and potentially inherit some of the credibility associated with its history.

The domain itself has changed hands, but automated systems may not immediately understand that distinction.

The Real Value Is Bigger Than Reputation

The most important part of the threat is that expired domains can inherit more than a reputation score.

They can inherit connections.

Old backlinks can continue sending visitors. Search engines may still have cached information. Users may still type the address into their browsers. Advertising networks may retain historical associations. Email may continue arriving at addresses connected to the domain.

And DNS configurations can create another dangerous layer.

A forgotten DNS record may point toward infrastructure that no longer belongs to the original organization. If nobody removes or updates that relationship, a new domain owner may potentially exploit the abandoned configuration.

The result is a digital property that comes with remnants of someone else’s infrastructure.

The Scale of the Dropcatch Economy

Infoblox estimates that among generic top-level domains, approximately 50,400 domains per day fall into the dropcatch category.

The activity is heavily concentrated among a relatively small group of TLDs.

Approximately 15 TLDs account for around 92% of observed dropcatch activity. The rates are particularly significant for .net and .xyz, where nearly 30% of new registrations reportedly had a previous registration history.

Even .com, traditionally associated with established businesses and organizations, shows a substantial rate, reaching approximately 24.5% in the research.

The numbers demonstrate that this is not a niche phenomenon.

It is part of the normal lifecycle of the modern internet.

Why Attribution Is So Difficult

Finding out who owns an expired domain is not always straightforward.

WHOIS privacy services can conceal registration information. Domains can move between registrars. Ownership can change through transfers. Some domains are purchased through auctions, while others may be parked before being developed.

A malicious actor can therefore assemble infrastructure without immediately presenting an obvious identity.

This creates an uncomfortable problem for defenders.

A domain can be old, technically valid, and apparently respectable while the organization currently controlling it has absolutely no relationship with the organization that originally registered it.

The Sable Squirrel Operation

One of the most striking examples described by Infoblox involves a threat actor tracked as Sable Squirrel.

According to the research, the actor has spent nearly $7 million acquiring expired domains and controls more than 10,000 domains.

This is not an ordinary phishing campaign.

It resembles a large-scale digital real-estate operation in which abandoned internet properties are systematically collected and repurposed.

The domains reportedly support illegal sports streaming, gambling promotion, traffic redirection, and malware infrastructure.

The scale shows why defenders cannot assume that domain abuse is limited to a handful of throwaway websites.

From Sports Streaming to Malware

Sable Squirrel reportedly operates streaming platforms associated with brands such as Xoilac, Cakhia, and 90phut.

These services have reportedly targeted audiences in several countries, including Vietnam, South Korea, Japan, and Australia, while directing users toward betting-related destinations.

But the infrastructure apparently has another purpose.

Some of the same domains have been associated with command-and-control activity involving malware such as Quasar RAT, AsyncRAT, DCRat, and Remcos RAT.

This is where the story becomes particularly concerning.

A website that looks like a sports streaming platform to an ordinary visitor can simultaneously function as part of a malware ecosystem behind the scenes.

Buying the Reputation of a Defunct Security Company

Among the expired domains reportedly acquired by Sable Squirrel are healthymagination.com, associated with a former General Electric healthcare initiative, and rezilion.com, previously associated with a cybersecurity company whose assets were sold to GitLab in 2024.

The second example is especially revealing.

A domain associated with a cybersecurity company can carry precisely the kind of historical characteristics that automated systems may interpret as legitimate.

When an attacker acquires such a domain, the attacker is not merely purchasing a web address.

They may be purchasing years of accumulated digital history.

The Email Problem Nobody Wants to Talk About

Expired domains can create another dangerous problem: misdirected email.

Imagine a company operated on oldcompany.example for a decade.

The company later abandons the domain.

Years later, another party registers it.

If customers, suppliers, employees, automated systems, or forgotten applications continue sending messages to old addresses, the new owner could potentially receive communications intended for the previous organization.

This does not automatically mean every expired domain exposes sensitive email. Properly configured mail systems, domain controls, and security procedures can reduce the risk.

But the possibility demonstrates why domain retirement must be treated as a security process rather than simply a billing decision.

The Forgotten DNS Trap

DNS records can survive long after people stop thinking about them.

A company may create a CNAME record pointing a subdomain toward a cloud service. Later, the service is discontinued, but the DNS record remains.

If the external resource becomes available for someone else to claim, an attacker may potentially exploit the dangling relationship.

This class of problem is often called dangling DNS or subdomain takeover, depending on the exact circumstances.

Expired domains make the situation even more complicated because the entire domain itself may eventually fall into someone else’s hands.

The Speed of Sable Squirrel

The attackers described in the research do not appear to leave their newly acquired domains sitting unused for months.

Infoblox reports that approximately 24% of Sable

Around 76% become active within seven days.

And approximately 94% are active within two weeks.

That speed matters.

Security reputation systems need time to observe behavioral changes. Threat intelligence feeds need time to identify infrastructure. Analysts need time to investigate.

Attackers can exploit the gap between acquisition and detection.

The Scavenger Model

Sable Squirrel is only one part of the picture.

Infoblox also tracks actors called Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel.

Their strategy is different.

Instead of purchasing expired domains simply to establish new infrastructure, these actors reportedly seek domains that had previously been compromised.

They are effectively scavenging abandoned malicious infrastructure.

The attacker who originally compromised a website may disappear, lose access, or have its infrastructure disrupted.

Another criminal actor can then acquire the expired domain and potentially benefit from the traffic and relationships created during the previous attack.

The malicious ecosystem therefore becomes strangely recyclable.

Shady Squirrel and the SocGholish Connection

Infoblox describes Shady Squirrel as a Russian-speaking actor believed to have been active since at least July 2023.

The actor has reportedly redirected inherited traffic toward SocGholish and technical-support scam networks.

The significance is larger than one malware campaign.

It demonstrates how cybercriminal infrastructure can survive its original operator.

A domain can outlive an attack.

Then another criminal group can purchase it and attempt to monetize the traffic again.

The Dangerous Illusion of Domain Age

For years, people have instinctively associated an old domain with legitimacy.

That assumption is becoming increasingly dangerous.

Domain age can tell us when a domain was first registered.

It does not necessarily tell us who controls it today.

A domain registered in 2005 could have changed ownership several times since then. Its current content may have nothing to do with its original purpose.

Therefore, old does not mean safe.

And new does not automatically mean malicious.

Security decisions must consider ownership changes, DNS history, content changes, infrastructure relationships, certificate history, hosting information, and current behavior.

Why Security Products Need Better Context

The fundamental weakness exposed by dropcatch abuse is that many automated security systems work with incomplete context.

A domain reputation score may be useful.

A domain-age signal may be useful.

Historical backlinks may be useful.

But none of these signals should be treated as permanent proof of trust.

The internet is constantly changing ownership.

Security systems must therefore become increasingly sensitive to identity transitions.

The important question is no longer simply:

How old is this domain?

The better question is:

Who controls this domain now, and what changed when ownership changed?

The Corporate Risk of Abandoned Domains

This issue is not limited to cybercrime researchers.

Businesses are also exposed.

Companies routinely abandon domains after mergers, rebranding, product shutdowns, marketing campaigns, acquisitions, or discontinued projects.

Some organizations own hundreds or thousands of domains.

Over time, nobody remembers why every domain was registered.

Eventually, the registration expires.

That forgotten domain can become someone

Old Backlinks Can Become a Weapon

Search engines and websites constantly create links.

A domain associated with an old business can accumulate thousands of backlinks over the years.

Some links may come from universities, news organizations, industry publications, partner websites, documentation, or government resources.

When the domain expires, those links do not necessarily disappear immediately.

An attacker can therefore acquire the domain and potentially redirect existing traffic toward completely different content.

The historical reputation becomes a delivery mechanism.

Cached Search Results Add Another Layer

Search engines retain historical information about websites.

Even after a domain changes hands, traces of its former identity can remain visible.

Search results may continue to associate the domain with its former purpose.

This can create a dangerous mismatch between what a domain used to be and what it is now.

Users searching for the original organization may therefore encounter a domain that appears familiar while actually being controlled by an unrelated party.

Deep Analysis

Why Defenders Should Monitor Domain Ownership

Security teams should treat important domains as assets that require lifecycle management.

Domain registration is not merely an administrative task.

It is part of the

Companies should maintain an inventory of active domains, expired domains, subdomains, DNS records, certificates, cloud services, and external dependencies.

Basic DNS Investigation

Defenders can start investigating suspicious domains with standard DNS utilities:

dig example.com
dig example.com A
dig example.com MX
dig example.com NS
dig example.com CNAME

These commands can reveal important DNS relationships.

Unexpected mail servers, nameservers, or CNAME records can justify further investigation.

Inspecting DNS Resolution

A simple lookup can also be performed with:

nslookup example.com

Or:

host example.com

The goal is not to declare a domain malicious based on one result.

The goal is to identify infrastructure that deserves additional investigation.

Checking HTTP Behavior

Security analysts can inspect HTTP response headers with:

curl -I https://example.com

For more detailed defensive analysis:

curl -v https://example.com

This can reveal redirects, server responses, certificate-related behavior, and other clues.

Do not automatically trust a website simply because it uses HTTPS.

Encryption protects the connection.

It does not prove the identity or intentions of the website operator.

Tracking Redirect Chains

Malicious domains often rely heavily on redirection.

A defender can investigate redirects using:

curl -I -L https://example.com

The -L option follows redirects.

A domain that unexpectedly redirects through several unrelated domains may deserve closer examination.

Inspecting TLS Certificates

Certificate information can provide additional context:

openssl s_client -connect example.com:443 -servername example.com

Analysts can compare certificate information with historical infrastructure and known organizational assets.

Again, a valid certificate is not equivalent to legitimacy.

Checking WHOIS Information

Where registration data is publicly available, defenders can inspect it through appropriate WHOIS services:

whois example.com

Privacy protection may conceal important information, but registration dates and registrar information can still provide useful clues.

Ownership changes should be treated as an important investigative signal.

Monitoring Corporate Domains

Organizations should continuously monitor their own domain portfolio.

A useful internal process is:

Inventory domains

Identify business owner

Record expiration dates

Review DNS dependencies

Remove abandoned records

Renew critical domains

Monitor ownership changes

This process can prevent a surprisingly large number of future problems.

Finding Dangling DNS Dependencies

Organizations should periodically search for DNS records pointing toward services that are no longer used.

Examples include:

CNAME → abandoned cloud service

CNAME → retired SaaS platform

A record → decommissioned server

MX → discontinued mail provider

TXT → obsolete verification service

Every abandoned dependency increases the

Domain Monitoring Should Include Change Detection

A strong monitoring system should alert when:

Registrar changes

Nameserver changes

DNS records change

Hosting provider changes

TLS certificate changes

IP address changes

Content changes

Redirect behavior changes

Ownership information changes

A domain that remains online for ten years can become malicious in a single afternoon.

Monitoring therefore needs to detect behavioral transitions, not merely newly registered domains.

Security Teams Should Question Reputation Scores

Reputation engines are valuable because nobody can manually investigate every domain on the internet.

But automated reputation should be treated as evidence, not truth.

A domain with a strong reputation should still receive scrutiny when other indicators suddenly change.

For example:

Old domain

+

New IP address

+

New nameservers

+

New TLS certificate

+

Sudden content change

+

Large redirect chain

=

High-priority investigation

The combination of signals is often more meaningful than domain age alone.

The Bigger Lesson for Threat Intelligence

The dropcatch phenomenon highlights a major evolution in cybercrime.

Attackers are becoming increasingly interested in digital assets with history.

Instead of building infrastructure from scratch, criminals can acquire infrastructure that already possesses useful characteristics.

This is similar to buying an established business instead of opening a new store.

The infrastructure already has customers.

In this case, those “customers” may be search engines, backlinks, forgotten email senders, cached results, or users who still recognize the domain.

What Undercode Say:

The Internet Has Become a Marketplace of Reputation

The most important lesson from this research is that reputation itself has become an asset.

Attackers are not necessarily interested in a domain because its name is valuable.

They may be interested because its history is valuable.

Domain Age Is an Increasingly Weak Security Signal

A ten-year-old domain can become malicious immediately after changing ownership.

Security products need to recognize that age measures history, not trust.

Ownership Changes Deserve More Attention

One of the strongest signals should be a major change in ownership or infrastructure.

If a domain suddenly moves to a new registrar, new nameservers, new hosting provider, and new certificate, that transition should matter.

Abandoned Infrastructure Is Still Infrastructure

Organizations often think of abandoned systems as irrelevant.

Attackers think differently.

An abandoned domain, forgotten DNS record, or obsolete cloud service can represent an opportunity.

The Sable Squirrel Example Changes the Conversation

Spending millions of dollars on expired domains demonstrates that this is not a theoretical technique.

There is an economic model behind it.

If criminals can monetize inherited traffic and reputation at scale, expired domains become a form of cybercrime infrastructure investment.

The Malware Connection Is Particularly Serious

When streaming infrastructure also becomes command-and-control infrastructure, defenders can no longer judge a website purely by what appears in the browser.

The visible website may be only one layer of the operation.

Cybercriminals Are Reusing the

The internet remembers.

Old links remain.

Old DNS records remain.

Old search results remain.

Old email addresses remain.

Attackers can exploit those leftovers.

Domain Retirement Needs a Security Checklist

Companies should not simply allow domains to expire.

Before retirement, they should review DNS, email, certificates, cloud services, backlinks, authentication systems, API integrations, and third-party dependencies.

Email Is an Especially Sensitive Dependency

The possibility of receiving messages intended for a former owner makes domain expiration a serious business-security concern.

Employees should know which domains are critical and which have been formally retired.

Dangling DNS Should Be Treated as an Exposure

A forgotten CNAME can be more dangerous than it looks.

Security teams should routinely audit records that point to external infrastructure.

Search Engines Can Become Part of the Attack Surface

Historical indexing can preserve the identity of a previous owner long after the domain has changed hands.

That creates opportunities for impersonation and deception.

Trust Should Follow Ownership, Not History

A domain’s history should inform security decisions.

It should not determine them.

The current operator matters more than the original registration date.

Threat Intelligence Needs Temporal Context

Security platforms should ask what changed and when.

A domain that was harmless for 15 years and became suspicious yesterday should not be treated identically to one that has behaved maliciously for 15 years.

Attackers Understand Reputation Systems

Cybercriminals increasingly understand how automated defenses work.

When a system rewards age, reputation, backlinks, or historical legitimacy, attackers will eventually attempt to manufacture or purchase those characteristics.

The Economics Are Changing

Cybercrime is becoming increasingly industrialized.

The reported $7 million investment by Sable Squirrel illustrates how infrastructure can be acquired as a business asset.

Domain Auctions Could Become Intelligence Sources

Security teams should pay attention not only to malicious domains after activation but also to suspicious acquisition patterns.

Large-scale purchases of domains connected to sensitive organizations could provide early warning signals.

Security Vendors Need Better Ownership Intelligence

Reputation systems should ideally combine registration history with ownership transitions, DNS changes, hosting changes, certificates, content changes, and behavioral indicators.

One signal is rarely enough.

Companies Should Defend Their Digital History

A brand’s security perimeter does not end with the domains it currently uses.

Former domains can still affect brand identity, customer trust, email security, and search visibility.

Former Vendors Can Create Hidden Risk

An abandoned domain may still be referenced by old vendors or partners.

That means domain retirement should include communication with third parties.

Security Teams Should Think Like Attackers

The attacker asks:

What can I inherit?

Defenders should ask the same question.

What traffic, trust, DNS relationships, email, certificates, or search visibility could someone else inherit?

The Problem Will Probably Grow

As the domain ecosystem expands and companies accumulate more digital properties, more domains will eventually expire.

That creates a larger pool for scavengers.

Automated Detection Will Become Essential

Nobody can manually inspect tens of thousands of domains every day.

Machine-assisted monitoring will be necessary.

But those systems need better historical and ownership context.

Old Should Never Equal Safe

This may be the simplest lesson from the entire report.

Age is evidence.

It is not authentication.

HTTPS Should Never Equal Trusted

An encrypted connection only tells us that the connection is encrypted.

It does not tell us who controls the website.

Domain Security Is Becoming Identity Security

The deeper issue is identity.

Who owns the domain?

Who operates the infrastructure?

Who controls the DNS?

Who receives the email?

Who publishes the content?

Those questions are becoming increasingly important.

The Internet Has a Memory Problem

The same historical data that makes the internet useful can also make it dangerous.

Backlinks, archives, caches, certificates, and DNS records can all outlive their owners.

Defenders Must Learn to Detect Transitions

The most suspicious event may not be domain creation.

It may be a sudden change to an old domain.

The Real Threat Is the Trust Gap

There is often a period between when ownership changes and when reputation systems recognize the change.

That gap is exactly where attackers can operate.

Expired Domains Should Be Considered Security Assets

Organizations should track them just as seriously as servers, cloud accounts, certificates, and IP addresses.

Criminal Infrastructure Is Becoming More Persistent

The scavenger model demonstrates that malicious infrastructure does not necessarily disappear when an attacker leaves.

Someone else may inherit it.

The Next Generation of Security Tools Must Understand History

But they must understand the right history.

Knowing that a domain is ten years old is useful.

Knowing that it changed owners three days ago may be far more useful.

The Bottom Line

The dropcatch phenomenon exposes a quiet transformation in cybersecurity.

Attackers are no longer interested only in creating malicious infrastructure.

They are increasingly interested in acquiring infrastructure that already looks legitimate.

That makes abandoned domains an important part of the modern attack surface.

The safest assumption is simple:

Never trust a domain because of its age. Trust it only after examining its current ownership, infrastructure, behavior, and context.

✅ Dropcatch Domains Are a Significant Part of New Registrations

The supplied research states that roughly 65,000 previously registered domains are re-registered each day and that they represented nearly 20% of new registrations during the first half of 2026. The figures are attributed to Infoblox Threat Intel.

✅ Expired Domains Can Retain Useful Historical Connections

Old domains can retain backlinks, cached search information, historical DNS relationships, and email dependencies. These remnants can create security and abuse opportunities after ownership changes.

✅ Threat Actors Can Use Expired Domains for Malicious Infrastructure

The

⚠️ Domain Age Does Not Guarantee Trust

An old domain may receive favorable reputation signals, but domain age alone does not prove that the current owner is legitimate. Ownership, DNS, hosting, content, and behavioral changes must also be evaluated.

⚠️ A Valid HTTPS Certificate Does Not Prove Legitimacy

HTTPS protects communications between a browser and a server. It does not establish that the website is trustworthy or operated by the organization historically associated with the domain.

Prediction

(+1) Domain Ownership Monitoring Will Become Standard Security Practice

As organizations recognize that abandoned domains can become attack infrastructure, domain lifecycle monitoring is likely to become a normal part of enterprise security programs.

(+1) Reputation Systems Will Add More Ownership Context

Security vendors will increasingly correlate domain age with registration changes, DNS modifications, hosting transitions, certificate history, and behavioral changes rather than treating age as a standalone trust signal.

(+1) Threat Intelligence Will Focus More on Digital Asset Reuse

Researchers are likely to discover more criminal groups purchasing expired domains, abandoned infrastructure, and previously compromised web properties because these assets can provide immediate traffic and historical credibility.

(-1) Abandoned Corporate Domains Will Remain a Persistent Security Problem

Many organizations still treat domain expiration as an administrative issue. Without formal retirement procedures, forgotten domains will continue creating opportunities for impersonation, phishing, traffic hijacking, and infrastructure abuse.

(-1) Scavenger Actors Could Make Old Malicious Infrastructure Harder to Eliminate

Even when law enforcement or security researchers disrupt a malicious campaign, expired domains and associated infrastructure can potentially be acquired by another criminal group and reused.

(+1) The Best Defense Will Be Continuous Verification

The future of domain security will depend less on asking whether a domain is old and more on continuously verifying who controls it, where it points, what it serves, and how its behavior has changed.

▶️ Related Video (70% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: securityaffairs.com
Extra Source Hub (Possible Sources for article):
https://www.twitter.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube