Domini scaduti riutilizzati per malware e truffe: l’attacco sfrutta la fiducia ereditata
Malware

Illustrative image generated with AI

Expired Domains Reused for Malware and Scams: Attacks Exploit Inherited Trust

Learn how criminals reuse expired domains for malware and scams, exploiting inherited trust and traffic.

Text generated by artificial intelligence, published without human review. AI transparency

How an “old” domain can become criminal infrastructure

An expired domain does not necessarily start from scratch. When it is registered by a new party, it may retain residual traffic, backlinks, search engine rankings, DNS configurations, and a reputation built by its previous owner.

This is the mechanism analyzed by Infoblox Threat Intel in research identified on August 15, 2026. Criminals acquire abandoned domains, also known as dropcatch domains, to distribute malware, promote fraud, or operate command-and-control servers.

The scale of the activity is significant. Around 65,000 domains previously owned by other parties are re-registered every day. During the first half of 2026, these registrations accounted for nearly 20% of the total—meaning roughly one in five “new” domains already had a history.

A domain’s age can influence reputation systems, search engines, and analysis tools. A domain originally registered ten years ago may appear less suspicious than one created recently, even if it has since been acquired by a malicious actor.

The most affected TLDs and the ownership problem

Looking only at generic top-level domains, the average reaches approximately 50,400 dropcatch domains per day. Fifteen TLDs account for about 92% of the activity.

The highest figures involve:

  • .net, where nearly 30% of new registrations had been used previously;
  • .xyz, also close to 30%;
  • .com, where 24.5% of registrations had a prior history.

Determining who actually controls these domains is not straightforward. WHOIS data may be protected by privacy services, while transfers, auctions, and parking periods make it difficult to trace the ownership chain.

The handover may also leave behind assets that benefit attackers, including emails still addressed to the old domain, legacy links published on third-party websites, indexed pages, and DNS records that remain active.

A specific risk involves dangling CNAMEs. In this scenario, a record continues to point to an external resource no longer controlled by the original owner. Anyone able to register or claim that resource may gain indirect control over the associated service.

Sable Squirrel acquired more than 10,000 domains

The most structured example involves the actor known as Sable Squirrel, which reportedly invested nearly $7 million in acquiring more than 10,000 expired domains.

These domains support a multi-purpose ecosystem involving illegal sports streaming, gambling promotion, and malware distribution or control. Sable Squirrel operates platforms associated with the Xoilac, Cakhia, and 90phut brands, targeting users in Vietnam, South Korea, Japan, and Australia.

Visitors to these sites are redirected to betting platforms. The same domains can also serve a more technical and dangerous purpose by acting as C2 servers for several remote access trojans:

  • Quasar RAT;
  • AsyncRAT;
  • DCRat;
  • Remcos RAT.

As a result, a domain that appears to be related to entertainment can become part of the infrastructure used to issue commands to infected systems.

Domains attributed to the operation include healthymagination.com, previously associated with a healthcare initiative by General Electric, and rezilion.com, formerly owned by a cybersecurity company whose assets were sold to GitLab in 2024.

The value is therefore not merely technical. Attackers may also appropriate some of the trust associated with the previous owner—whether a healthcare organization, technology company, or cybersecurity firm.

Activation often occurs within days

Speed is central to this model. After registering a domain, Sable Squirrel tends to activate it before reputation systems can update their assessment.

According to the analysis:

  • 24% of domains are activated on the same day;
  • 76% become active within seven days;
  • 94% are operational within two weeks.

This window allows attackers to quickly exploit existing traffic, backlinks, and search results. A domain that suddenly begins hosting redirects, betting pages, or malicious code may continue benefiting for some time from the reputation it built previously.

The issue also affects email. Messages intended for the former owner may continue reaching systems or mailboxes associated with the domain. If the organization has not properly revoked configurations, permissions, and DNS references, the new owner may intercept some of this traffic or use it in impersonation campaigns.

“Scavengers” reuse previously compromised websites

Not all actors follow the large-scale acquisition model. Infoblox also tracks Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel, which it classifies as scavenger groups.

These operators look for expired domains that had already been compromised by other criminals. Their goal is to inherit infection-driven traffic rather than build a distribution network from scratch.

Shady Squirrel, believed to be Russian-speaking and active since at least July 2023, redirects this traffic to SocGholish and to scam networks based on fake technical support.

According to the analysis, SocGholish regained access to thousands of compromised websites by working with Shady Squirrel, just days after law enforcement disrupted its infrastructure. The case shows how a criminal operation can resume activity by exploiting already exposed sites and domains, without having to repeat the entire initial compromise phase.

What organizations should monitor

A domain’s age is not proof of trustworthiness. Organizations should verify current ownership and recent behavior, especially when a domain changes registrars, nameservers, hosting providers, or DNS configuration.

Priority checks include:

  • monitoring ownership and provider changes;
  • periodically reviewing CNAMEs, DNS records, and references to abandoned resources;
  • analyzing redirects, content, and sudden traffic changes;
  • checking for the reuse of legacy backlinks and still-indexed pages;
  • monitoring email addressed to domains or mailboxes no longer managed;
  • correlating indicators with Quasar RAT, AsyncRAT, DCRat, Remcos RAT, and SocGholish;
  • immediately reassessing reactivated domains, as they may become operational on the same day.

There is no single patch for this risk. Effective defense requires a combination of ownership verification, DNS monitoring, and traffic analysis. Reputation systems must also avoid assigning trust based solely on a domain’s age or previous history.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsexpired domainsmalwarescamsdropcatch domainsSable Squirreltrust exploitationcyber threatsC2 servers
Back to home