Listen to this Post
A Quiet Internet Economy With a Dangerous Second Life
Every day, tens of thousands of internet domains that once belonged to businesses, organizations, developers, campaigns, and individuals are registered again by completely different owners. On the surface, this looks like an ordinary part of the domain-name economy. Websites disappear, companies rebrand, projects shut down, and their domains eventually expire.
But beneath that routine process, a much darker market is growing.
According to research from Infoblox Threat Intel, approximately 65,000 previously registered domains are re-registered every day. These so-called dropcatch domains represented nearly 20% of all new domain registrations during the first half of 2026.
That means roughly one out of every five domains that appears to be “new” on the internet may actually have a history.
And that history can be valuable.
For legitimate buyers, an expired domain may offer an established name, backlinks, search visibility, or brand recognition. For cybercriminals, however, the same history can provide something far more useful: inherited trust, traffic, technical relationships, and reputation signals that security systems may not immediately recognize as dangerous.
This creates a subtle cybersecurity problem. The domain may be newly controlled, but it is not necessarily a new digital identity.
The Domain Is New, But Its Reputation May Not Be
A freshly registered domain normally begins with very little history.
Security companies can examine its registration date, DNS records, hosting provider, certificate history, reputation, previous activity, and other indicators. A domain registered yesterday and immediately used to distribute malware can therefore trigger suspicion.
An expired domain can be different.
Imagine a domain that existed for ten years, accumulated thousands of backlinks, appeared in legitimate articles, received search-engine indexing, hosted business content, and communicated with users for years before its owner abandoned it.
Then somebody else buys it.
Technically, the registration has changed. But many of the historical signals surrounding the domain may remain.
Infoblox describes this inherited reputation as one of the reasons expired domains can become attractive to threat actors. Security products and reputation algorithms may treat an established domain differently from a completely unknown domain.
Cybercriminals understand that distinction.
Why Attackers Want Digital History
The value of an expired domain goes far beyond its name.
A domain may retain links from websites that still exist. Search engines may continue to know about it. Users may still type the address into their browsers. Applications may still reference it. Email may continue arriving at addresses associated with the old domain.
Even forgotten DNS configurations can create opportunities.
In other words, an expired domain can function like a digital property whose previous owner left behind furniture, keys, mail, visitors, and connections.
The new owner may simply walk in.
Nearly One in Five New Domains Has a Past
Infoblox found that approximately 65,000 domains per day are re-registered after being dropped.
Among generic top-level domains, the average is around 50,400 per day, with just 15 TLDs accounting for approximately 92% of dropcatch activity.
The numbers become even more interesting when individual TLDs are examined.
Domains under .net and .xyz showed some of the highest proportions of previously registered names, with close to 30% of new registrations having a previous owner.
For .com, the figure reached approximately 24.5%.
That does not mean every expired domain is malicious. Far from it.
The overwhelming majority may be purchased for legitimate reasons. The cybersecurity problem is that defenders often have difficulty distinguishing benign reuse from malicious repurposing.
The Identity Problem
Determining who actually acquired an expired domain is not always straightforward.
WHOIS privacy services can hide registration information. Domains can be transferred between registrars. Names can be bought through auctions or brokers. Some are parked temporarily before being developed.
This creates an uncomfortable visibility gap.
A domain may have ten years of legitimate history followed by a sudden change in ownership that is difficult for outside observers to identify.
The
Its new owner may not be.
Old Backlinks Can Become New Attack Paths
One of the most interesting aspects of expired domains is their residual web traffic.
A company may have spent years building links to a domain. News publications may still reference it. Industry blogs may still contain URLs pointing toward it. Search engines may still have indexed pages from the old website.
When the domain expires, those references do not automatically disappear.
If an attacker acquires the domain, some of that historical traffic can potentially be redirected toward malicious destinations.
This creates an unusual form of cyber abuse.
The attacker does not necessarily need to build an audience from scratch.
The audience may already exist.
The Email Problem Is Even More Disturbing
Expired domains can also create email-related risks.
Suppose a company once operated under example.com and later abandoned the domain. Employees, suppliers, customers, automated systems, and third-party services may still send messages to addresses associated with that domain.
If an attacker later obtains the domain, those messages could potentially reach infrastructure controlled by the new owner.
This is why domain retirement is not simply a matter of stopping website hosting.
Organizations need to think about the entire ecosystem surrounding a domain, including email, DNS, certificates, SaaS integrations, APIs, redirects, authentication systems, and third-party dependencies.
A domain can disappear from the
The Sable Squirrel Operation
Infoblox highlighted a particularly striking example involving a threat actor it calls Sable Squirrel.
According to the research, this actor has spent nearly $7 million acquiring expired domains.
That is an enormous investment in something many organizations consider worthless once they stop using it.
The domains have reportedly been used to build an operation involving illegal sports streaming, gambling promotion, and malware infrastructure.
Sable Squirrel reportedly controls more than 10,000 domains.
This demonstrates that expired domains are not merely a minor technical trick.
They can become part of a large-scale criminal business model.
From Sports Streaming to Malware
Some of Sable
The platforms attract users from multiple countries, including Vietnam, South Korea, Japan, and Australia, and redirect or expose visitors to betting-related services.
But the infrastructure allegedly has another purpose.
Some of these domains are also associated with command-and-control infrastructure for malware families including Quasar RAT, AsyncRAT, DCRat, and Remcos RAT.
This is where the story becomes especially concerning.
A domain can look like a sports-streaming website to one observer while functioning as part of a malware ecosystem to another.
Buying the Reputation of a Defunct Company
Among the expired domains reportedly acquired by Sable Squirrel were healthymagination.com, associated with a former General Electric health initiative, and rezilion.com, previously associated with a cybersecurity company whose assets were sold to GitLab in 2024.
The second example is particularly striking because of the cybersecurity connection.
An expired domain associated with a security company can carry historical signals that make its later malicious use especially deceptive.
The irony is difficult to miss.
A digital identity once connected to cybersecurity can potentially become part of a malware infrastructure after its ownership changes.
Speed Is Part of the Attack
Sable Squirrel apparently does not wait around after acquiring domains.
Infoblox reported that approximately:
24% of acquired domains become active on the same day.
76% become active within seven days.
94% are active within two weeks.
That speed matters.
Security systems need time to collect telemetry, update reputation databases, observe DNS changes, identify hosting relationships, and classify newly emerging infrastructure.
Attackers can exploit that window.
The faster a criminal infrastructure becomes operational, the more likely it is to benefit from historical trust before defensive systems catch up.
The Scavengers Are Different
Sable Squirrel is not the only model identified by Infoblox.
Researchers also track actors referred to as Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel.
These groups reportedly operate more like digital scavengers.
Instead of acquiring expired domains primarily to build an operation from scratch, they look for domains that were previously compromised by other attackers.
The result is particularly troubling.
They can inherit traffic that already exists.
Recycling Someone
Imagine a legitimate website becoming compromised.
An attacker injects malicious code into it and begins receiving traffic from visitors.
Later, the malicious infrastructure is disrupted or the compromised site is abandoned.
The domain eventually expires.
A scavenger acquires the domain.
Instead of starting again, the new operator attempts to capitalize on the existing malicious ecosystem.
This is essentially criminal infrastructure recycling.
One attacker’s abandoned resource becomes another attacker’s revenue stream.
The Shady Squirrel Connection
Infoblox assesses Shady Squirrel as a Russian-speaking actor active since at least July 2023.
The group reportedly feeds inherited traffic into SocGholish and technical-support scam networks.
According to the research, SocGholish was able to regain access to thousands of compromised websites after partnering with Shady Squirrel shortly after its own infrastructure was disrupted by law enforcement.
The broader lesson is more important than any individual actor.
Disrupting malicious infrastructure does not necessarily eliminate the underlying ecosystem.
If the domain layer can be recycled, criminals can rebuild around existing traffic and reputation.
The Real Weakness Is Trust
The biggest lesson from this research is not that expired domains are inherently dangerous.
They are not.
The problem is blind trust in historical reputation.
A domain’s age does not tell you who controls it today.
A domain that has existed for 15 years can become malicious within hours.
A domain that belonged to a respected company can eventually become criminal infrastructure.
A domain with thousands of legitimate backlinks can suddenly redirect visitors somewhere dangerous.
Historical reputation is useful.
But it should never be treated as proof of current trustworthiness.
Deep Analysis
Understanding the Dropcatch Lifecycle
A typical dropcatch scenario begins when a domain owner fails to renew a registration.
The domain enters an expiration process.
Eventually, it becomes available again.
A new buyer acquires it.
From a technical perspective, the domain now has a new owner.
But the internet may still contain references to its previous life.
That gap between ownership history and technical history is exactly where attackers can operate.
DNS Is One of the First Places to Look
Security teams investigating suspicious domain reuse should examine historical and current DNS information.
Useful defensive commands include:
dig example.com
and:
dig example.com A dig example.com MX dig example.com NS dig example.com CNAME
These queries can reveal whether the domain points toward unexpected infrastructure.
For deeper inspection:
dig +trace example.com
can help analysts understand the delegation chain.
Check Registration Information
Defenders can also inspect domain-registration metadata through authorized services.
For example:
whois example.com
However, WHOIS information should never be treated as complete evidence.
Privacy services, registrar changes, transfers, and data limitations can make attribution difficult.
Examine DNS History
Historical DNS records are often more valuable than a single snapshot.
Security teams should compare:
Previous nameservers
Current nameservers
Previous hosting providers
Current hosting providers
Historical IP addresses
MX records
CNAME records
Certificate associations
A sudden change from a corporate hosting environment to infrastructure associated with unrelated domains should increase investigative attention.
Certificate Transparency Can Help
TLS certificates provide another useful source of historical information.
Defenders can investigate certificate relationships to determine whether a domain suddenly became associated with unfamiliar infrastructure.
For example, certificate transparency logs can help answer questions such as:
When did certificates first appear?
Which subdomains were covered?
Did ownership infrastructure change?
Are multiple suspicious domains using the same certificate?
Passive DNS Is Valuable
Passive DNS databases can reveal historical relationships that are invisible from current DNS records.
This is especially important because attackers may deliberately change DNS after establishing infrastructure.
The current record shows what exists today.
Historical DNS can show how the infrastructure evolved.
Security Teams Should Compare Ownership and Behavior
A useful detection principle is:
Domain Age ≠ Current Trust
Instead, defenders should correlate:
Domain age
+
Registration change
+
DNS change
+
Hosting change
+
Certificate change
+
Traffic behavior
+
URL behavior
+
Email behavior
The combination is far more meaningful than any individual signal.
Monitor Newly Reactivated Domains
Organizations can create detection rules for domains that have been inactive and suddenly become operational again.
A particularly interesting event is:
Long inactivity
↓
New registration
↓
DNS change
↓
New hosting provider
↓
Sudden traffic increase
That sequence deserves investigation.
Watch for Suspicious Redirects
Expired domains used for scams may rapidly change their content.
Defenders should inspect:
curl -I https://example.com
and, when appropriate:
curl -L -I https://example.com
The first command can reveal HTTP response behavior, while the second follows redirects.
Unexpected redirection chains should be investigated.
Examine HTTP Headers
Security researchers can also inspect response headers:
curl -sI https://example.com
Changes in server software, CDN configuration, caching behavior, or unusual headers can provide additional clues.
These commands should only be used against systems you are authorized to investigate.
Search for Dangling DNS Records
Organizations retiring domains should carefully review CNAME and other DNS records.
A record pointing to an abandoned third-party service can create a dangling DNS condition.
For example:
legacy.example.com CNAME old-service.provider.example
If the old service is no longer controlled by the organization but the DNS record remains, an attacker may potentially exploit the abandoned resource.
Domain Retirement Needs a Checklist
Companies should treat domain retirement almost like decommissioning a server.
Before abandoning a domain, teams should review:
DNS
Subdomains
TLS certificates
Cloud services
CDNs
SaaS integrations
API endpoints
SSO configurations
OAuth redirects
Mobile applications
Marketing links
Partner integrations
Monitoring systems
The goal is to remove dependencies before surrendering control.
Email Requires Special Attention
Email is one of the easiest aspects of domain retirement to overlook.
Organizations should verify that abandoned domains cannot receive sensitive correspondence after ownership changes.
Mail-routing records should be reviewed carefully.
Archived addresses should be handled according to organizational policy.
Critical services should not continue depending on addresses under a domain that the organization no longer owns.
Search Engines Can Become an Attack Surface
Old search results and cached references may continue sending visitors toward an expired domain.
This creates an unusual situation where the attacker inherits not only the domain but potentially part of the previous owner’s online visibility.
Defenders should therefore consider historical search presence when assessing domain risk.
Reputation Systems Need Better Context
Traditional reputation models often emphasize domain age, historical activity, and observed behavior.
Those indicators remain useful.
But this research demonstrates why ownership transitions deserve more weight.
A domain that was safe yesterday may be controlled by an entirely different entity today.
Security engines should therefore distinguish:
Historical reputation
from:
Current ownership and infrastructure reputation
Attackers Are Exploiting Defensive Assumptions
Cybersecurity defenses are often designed around patterns.
New domain?
Suspicious.
Old domain?
Potentially safer.
But attackers study those assumptions.
If criminals know that old domains receive more favorable treatment, purchasing old domains becomes a way to manipulate the defensive model.
That turns domain history into an attack surface.
The $7 Million Investment Matters
The reported spending by Sable Squirrel is perhaps the clearest indication that this is not merely theoretical.
Criminal operators generally do not spend millions of dollars on infrastructure without expecting financial returns.
The economics suggest that expired domains can generate enough value through advertising, gambling traffic, malware distribution, or other criminal activity to justify significant investment.
Criminal Infrastructure Is Becoming More Industrialized
The existence of thousands of domains under a single actor demonstrates a broader transformation in cybercrime.
Attackers increasingly operate like businesses.
They acquire assets.
They manage infrastructure.
They optimize traffic.
They recycle compromised resources.
They diversify revenue.
And they automate operations.
The domain name becomes one component in a larger criminal supply chain.
Infrastructure Disruption Is Not the Same as Ecosystem Disruption
Law enforcement can seize servers.
Security researchers can block domains.
Hosting companies can terminate accounts.
But if attackers can acquire replacement domains carrying existing reputation and traffic, the ecosystem can regenerate quickly.
This is why defenders need to think beyond individual indicators.
The goal should be to understand the infrastructure network behind the domains.
The Domain Itself May Not Be the Threat
This distinction is important.
An expired domain is not malicious simply because it has changed ownership.
The threat emerges when historical trust, residual traffic, abandoned infrastructure, or forgotten dependencies are combined with malicious intent.
That means aggressive blocking of every reused domain would create enormous collateral damage.
The better strategy is contextual analysis.
Organizations Should Track Their Own Former Domains
Companies should maintain an inventory of domains they have abandoned.
This allows security teams to monitor them after expiration.
If a former corporate domain suddenly begins hosting suspicious content, the company can investigate whether customers, employees, partners, or search engines could be confused.
Brand Protection Can Become Security Monitoring
Domain monitoring is often treated as a brand-protection function.
It should also be considered a cybersecurity function.
A domain previously associated with a company can be weaponized against customers after expiration.
Attackers can use old branding, familiar URLs, or historical search results to create convincing phishing campaigns.
Domain Age Should Become a Secondary Signal
A mature security model should not ask:
How old is this domain?
It should ask:
“Who controls this domain now, what changed, and what is it doing?”
That is a much harder question.
It is also a much better one.
The Internet Never Truly Forgets
One of the deepest lessons from expired-domain abuse is that online identities rarely disappear cleanly.
Links survive.
DNS records survive.
Certificates survive in logs.
Search results survive.
Email addresses remain in databases.
Applications retain old URLs.
People continue using bookmarks.
The domain may expire.
Its digital history does not.
What Undercode Say:
- Expired Domains Are Becoming Digital Recycled Infrastructure
The internet has always recycled IP addresses, servers, and domain names. What is changing is the scale at which criminals can exploit that recycling.
2. Historical Reputation Is Not Ownership Verification
A domain’s reputation tells us what happened before. It does not necessarily tell us who controls it today.
3. Security Products Need Ownership-Aware Intelligence
Reputation engines should place greater emphasis on registration changes, DNS transitions, hosting changes, and sudden behavioral shifts.
- The Biggest Risk May Be the Traffic
An attacker does not necessarily need to advertise a malicious domain.
If thousands of people already visit it because of historical backlinks, the attacker has inherited an audience.
- Forgotten Email Is a Major Organizational Risk
Companies should never assume that abandoning a domain simply means shutting down its website.
Email and third-party dependencies can survive long after the business stops using the domain.
- Sable Squirrel Shows the Economics of Domain Abuse
Spending millions of dollars on expired domains suggests that criminals view these assets as revenue-generating infrastructure rather than disposable tools.
7. Criminals Are Learning From Defensive Algorithms
If old domains receive more trust, attackers have a financial incentive to acquire them.
That creates a dangerous feedback loop between reputation systems and criminal behavior.
- Domain Age Can Become a False Sense of Security
An old domain may look respectable while its current owner may be completely unknown.
That makes domain age useful but insufficient.
9. Domain Monitoring Should Continue After Retirement
Organizations should monitor important abandoned domains instead of forgetting them immediately after expiration.
10. Security Teams Need Historical Visibility
Current DNS data is only a snapshot.
Historical DNS, certificates, hosting, WHOIS information, and passive DNS can reveal the transition from legitimate infrastructure to malicious infrastructure.
11. Scavenger Actors Are Especially Interesting
Actors that acquire already-compromised domains demonstrate that attackers can recycle the work of other criminals.
This creates a secondary market for malicious traffic.
12. Takedowns Can Produce Temporary Results
Removing malicious infrastructure is valuable, but it does not necessarily eliminate the underlying business model.
- Domain Abuse Is Also a Supply-Chain Problem
The domain can connect victims, advertising networks, malware operators, hosting companies, registrars, and compromised websites.
It is part of a broader infrastructure chain.
14. Organizations Need Domain Exit Strategies
A domain should have a retirement process just like a server, application, or database.
15. DNS Deserves More Security Attention
DNS is often treated as basic plumbing.
In reality, it can provide crucial evidence about infrastructure changes and ownership transitions.
16. Old Backlinks Are Potential Assets
Years of legitimate links can become valuable traffic sources for someone who acquires the domain later.
17. Search Visibility Can Be Weaponized
Search engines may continue associating a domain with its previous identity, allowing malicious operators to inherit visibility.
18. Brand Reputation Can Become a Weapon
A previously trusted name can make malicious content appear more credible.
19. Cybersecurity Companies Are Not Immune
The reported reuse of a former cybersecurity-related domain demonstrates how even security-associated identities can eventually be repurposed.
20. Domain Ownership Is a Security Boundary
Companies should treat control of a domain as an asset requiring lifecycle management.
- The Registration Date Is Only One Data Point
A domain registered years ago should not automatically receive a higher trust score.
22. Sudden Infrastructure Changes Matter More
A dramatic DNS, hosting, certificate, or content change can be more informative than domain age.
23. Automation Makes This Threat Scalable
Managing thousands of domains would be difficult manually, which strongly suggests that automation is central to large-scale domain operations.
- Attackers Can Move Faster Than Reputation Databases
The reported activation timelines show how quickly criminals can put newly acquired infrastructure to work.
25. Defenders Need Faster Detection
If attackers can activate domains in hours, security intelligence must be capable of detecting meaningful changes just as quickly.
26. Domain Auctions Deserve Greater Security Attention
The process through which expired domains are sold can become part of the infrastructure acquisition chain.
27. Privacy Services Complicate Attribution
WHOIS privacy is legitimate and widely used, but it also makes identifying new owners more difficult.
28. Reputation Needs Context
A domain should not be considered trustworthy simply because it has a long history of legitimate activity.
- The Past Can Become an Attack Vector
Historical information is normally treated as evidence.
In this case, history itself can become part of the weapon.
30. Infrastructure Recycling Is Likely to Grow
As attackers become more organized, recycling valuable digital assets will probably become increasingly attractive.
31. Domain Security Belongs in SOC Workflows
Security operations centers should consider domain lifecycle events when investigating suspicious infrastructure.
32. Organizations Should Inventory Abandoned Assets
Former domains, subdomains, DNS records, and certificates should be tracked even after they are no longer operational.
33. Customers Can Become the Victims
An abandoned company domain may later be used to impersonate the original organization.
That can turn a corporate asset-management mistake into a phishing problem.
34. Security Teams Should Correlate Multiple Signals
No single indicator is reliable enough.
Domain history, ownership changes, DNS, hosting, certificates, and behavior should be analyzed together.
35. The Threat Is Bigger Than Malware
Expired domains can support scams, gambling operations, phishing, advertising abuse, malware distribution, and traffic redirection.
36. Domain Reputation Is a Double-Edged Sword
The same reputation that helps legitimate businesses can eventually help attackers.
37. Cybercrime Is Increasingly Asset-Based
Criminal groups are not only writing malware.
They are acquiring infrastructure, traffic, brands, domains, and audiences.
38. Retirement Is Part of Cybersecurity
A company has not completely retired a digital asset until its dependencies and future ownership risks have been addressed.
39. The
Every backlink and historical association can become an asset.
But once ownership changes, those same associations can become liabilities.
- The Most Important Question Is Who Controls It Now
The central lesson is simple: trust the current behavior, not merely the historical reputation.
✅ The Scale of Dropcatching Is Significant
Infoblox’s research reports roughly 65,000 previously registered domains being registered again each day, with dropcatch domains accounting for close to one-fifth of new registrations during the first half of 2026.
✅ Expired Domains Can Retain Valuable Historical Signals
Old backlinks, search visibility, DNS relationships, email traffic, and other historical associations can survive after a domain changes ownership, creating opportunities for both legitimate reuse and malicious abuse.
✅ Sable Squirrel Represents a Large-Scale Abuse Model
The Infoblox research identifies Sable Squirrel as an actor that has reportedly invested nearly $7 million in expired domains and controls more than 10,000 domains associated with streaming, gambling promotion, and malware infrastructure.
⚠️ Domain Age Alone Does Not Prove Trustworthiness
An old domain is not automatically malicious or safe. The critical factor is what changed after ownership transferred and how the domain behaves under its current operator.
Prediction
(+1) Expired-Domain Monitoring Will Become a Bigger Part of Cybersecurity
As attackers increasingly recognize the economic value of historical domains, security vendors are likely to place more emphasis on ownership transitions, DNS history, domain reactivation, and infrastructure changes.
(+1) Organizations Will Treat Domain Retirement as a Formal Security Process
Companies will increasingly maintain inventories of abandoned domains and monitor them after expiration, particularly when those domains were historically associated with customer-facing services.
(+1) Reputation Engines Will Become More Context-Aware
Security systems will likely reduce their reliance on simplistic signals such as domain age and incorporate ownership changes, infrastructure transitions, historical DNS, and behavioral telemetry.
(-1) Criminals Will Continue Recycling Trusted Digital Identities
As long as old domains can inherit traffic and reputation, attackers will have a strong incentive to acquire them.
(-1) Abandoned Corporate Domains Could Become a Growing Phishing Problem
Organizations that forget about former domains may eventually discover that those addresses have been repurposed to imitate their old services, capture traffic, or deceive customers.
(+1) The Security Industry Will Pay More Attention to the Domain Lifecycle
The future of domain security will likely focus less on whether a domain is “old” or “new” and more on the complete lifecycle of the digital identity: who owned it, who owns it now, what changed, and what it is doing today.
▶️ Related Video (78% Match):
🕵️📝Let’s dive deep and fact‑check.
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
References:
Reported By: securityaffairs.com
Extra Source Hub (Possible Sources for article):
https://www.reddit.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube




