Expired domains are not just a marketing problem or a registrar cleanup issue. They can become ready-made cyber infrastructure.
Recent reporting from The Hacker News, based on Infoblox threat intelligence research, highlights a broader dropcatching problem: threat actors are buying expired domains with existing reputation, backlinks, residual traffic, and lingering technical relationships, then using that inherited trust for redirects, scams, malware delivery, and command-and-control infrastructure.
What happened
Infoblox describes “dropcatch” domains as expired domains that are re-registered by a new party after the prior owner lets them lapse. That by itself is not malicious. Domain investors, brand protectors, and defenders all use the practice. The risk comes when a threat actor buys a previously trusted or previously compromised domain and immediately turns its old reputation into attacker infrastructure.
The research calls out several financially motivated actors using this model. One operation, tracked as Sable Squirrel, reportedly spent millions of dollars acquiring expired domains to support a mix of illegal sports streaming, gambling promotion, and malware infrastructure. Infoblox also tracks scavenger-style actors that acquire domains previously used in malicious campaigns, then inherit traffic from compromised websites that still reference those domains.
That last point matters: when a compromised website still contains an old script reference, iframe, or redirect to a domain that later expires, whoever catches that domain may start receiving traffic from victims without needing to compromise the site again.
Why this matters for SMBs and government contractors
Many security programs still treat domain age and prior reputation as trust signals. That is understandable, but it is no longer enough. A domain can be old and still dangerous. It can have clean historical reputation and still be under new ownership. It can appear in legacy documentation, old email templates, third-party JavaScript, or abandoned vendor integrations and still become part of an active attack chain.
For small businesses and government contractors, this creates three practical risks:
- Reputation-based filtering gaps: DNS and web controls may allow domains because they are old, categorized, or previously benign.
- Residual trust abuse: Old links, backlinks, cached search results, and embedded scripts can keep sending users or systems toward a domain long after ownership changes.
- Third-party dependency drift: Forgotten vendor domains, marketing scripts, analytics code, and retired project domains can become attack paths if nobody owns the cleanup process.
Defensive takeaways
This is not a problem most organizations can solve by blocking all newly re-registered domains. That will create noise and business friction. The better approach is to reduce blind trust and improve visibility around domain ownership changes, abandoned dependencies, and suspicious redirect behavior.
- Audit external dependencies: Review websites, portals, documentation, email templates, and applications for third-party scripts, redirects, iframes, and hardcoded domains.
- Monitor expired and abandoned domains: Track domains your organization once owned, campaign domains used by marketing, retired project domains, and domains tied to former acquisitions or products.
- Treat domain age as a weak signal: Tune DNS and proxy controls to consider ownership changes, recent nameserver changes, suspicious redirect chains, and hosting movement.
- Inspect redirect chains: Alert when users are routed through multiple unfamiliar domains, traffic distribution systems, popunder behavior, fake update pages, or unusual geolocation-based redirects.
- Clean up old web compromise artifacts: If a site was ever infected with injected JavaScript, do not assume removing the active payload once is enough. Hunt for dormant references and abandoned loader URLs.
- Protect your own domains: Use registrar lock, renewal monitoring, strong registrar MFA, centralized domain inventory, and clear ownership for every business domain.
Bulwark Black assessment
The important lesson is simple: reputation is not identity, and age is not trust.
Dropcatch abuse works because many defenses and business processes still assume that old infrastructure is safer than new infrastructure. Attackers are turning that assumption into an advantage. They do not always need a zero-day or a fresh phishing domain when they can buy a domain that already has traffic, history, backlinks, and forgotten integrations pointing at it.
For SMBs and government contractors, the priority should be domain governance and DNS visibility. Know what you own, know what your systems call out to, and do not let retired infrastructure become someone else’s attack surface.
Original source: Infoblox — Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows. Additional reporting: The Hacker News.
