The images in this article were generated with artificial intelligence. How we publish
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatch domains- to take advantage of your traffic, history and reputation signals and redirect users to scams, illegal bets and malware distribution networks. According to the analysis, in the first half of 2026 they were re- recorded about 50,400 dropcatch daily only in gTLDs (.com, .net, .org, etc.) and about 65,000 if ccTLDs are included, which represents almost a fifth of the new daily inscriptions. These figures and the pattern of behaviour are confirmed by Infoblox; other statements in the report (such as the regional attribution of certain operations) are telemetry-based and therefore subject to review.
Technically, the mechanics is simple but effective: when a domain expires and passes its grace period, it returns to the "tail" of the record removal and can be captured by backorder services or auctions. Specialized platforms such as DropCatch.com use algorithms that try to register milliseconds after release; when there is more than one postulant the domain is adduced to the best bidder in a public bid. This allows malicious acquirers to obtain domains with a history of incoming links, indexed entries in search engines, DNS records and sometimes residual mail or certificates, elements that can make that domain more reliable by search engines and automated defenses.

The report identifies specific patterns: .net and .xyz lead the re-registration activity by TLD; .com is third, and registrators such as GoDaddy, Namecheap and DropCatch.com appear among the usual channels of acquisition. Infoblox also documents that a significant percentage of these domains are launched very quickly after purchase: 24% on the same day, 76% in one week and 94% in 15 days, which shows the intention to exploit them without delay.
An illustrative case and verified by the analysis is the operation called "Sable Squirrel," which according to Infoblox would have invested almost $7 million in expired domains and controls more than 10,000 names. The infrastructure linked to this actor serves as a network for the transmission of pirate sports events, promotion of betting sites and, simultaneously, as command and control backend (C2) for malware families such as Quasar RAT, AsyncrAT, DCRat, NanoCore, RAT Remcos and njRAT; the report notes that more than 31,000 malware samples have communicated with the infrastructure assigned to this operation. Infoblox also reports that some of these same web addresses present streaming content in public while operating as C2, which demonstrates the dual utility sought by the attackers.
These practices affect a wide range of actors. Users looking for free sports events or content can be redirected to platforms that install malicious applications or lead to fraud and betting. Companies and brands suffer reputational damage when their old domains - or similar imitations - are reused for illicit activities. For security teams, the existence of so many "wholesale" domains complicates prioritization, because many solutions continue to use the age and history of a domain as signs of trust.
The real consequences include increased malware campaigns and initial access to corporate networks, advertising fraud and monetization for illicit traffic, and difficulties in blocking malicious content without affecting legitimate traffic. In addition, the use of sealing techniques and traffic distribution systems that filter by geolocation or visitor behavior allows the malicious pages to remain hidden from scanners and most public investigations.
As for concrete measures, the steps differ according to the profile. For end-users: avoid downloading apps or following links that arrive from unofficial streaming sites, check the domain reputation (not only seniority), keep the system and antivirus up-to-date, and activate mail protections (SPF / DKIM / DMARC) in your business or personal accounts where possible. For security teams and administrators: incorporate expired domain intelligence and passive DNS into telemetry; do not rely exclusively on the domain's seniority as a confidence indicator; block or inspect domains that recently change the registry and monitor new TLS certificates linked to names with history. Use dynamic black lists combined with contextual categorization and evaluate implementing synkholding coordinated with authorities for clearly malicious domains.

Companies and brands should audit their domain portfolio and renewal policies, enable transfer and authentication block of two factors in the registry accounts, and consider recording critical variations or domains with potential confusion to prevent malicious actors from taking advantage of them. Registers and policy makers can mitigate risks by improving recovery windows and the transparency of auctions, and by facilitating liability for auction transactions; organizations such as ICANN document the life cycle of a domain and good practices to be reviewed ( ICANN: domain life cycle).
Among the limitations and areas of uncertainty it should be noted that the geographical attribution and exact calculation of the criminal benefit are often based on telemetry and evidence-healing correlations, not on public admissions, so these assessments can be updated with new information. It is also possible that part of the activity documented by Infoblox will include legitimate acquisitions of investors or brand advocates; the presence of residual traffic does not necessarily imply malicious intention until the domain is used in an abusive manner.
The practical conclusion is that the mass purchase of expired domains is no longer a theoretical risk: is an operating vector exploited for fraud, malware distribution and illicit monetization schemes. Defenders should stop considering the age of a domain as an immutable signal of confidence and deploy technical and process controls aimed at detecting rapid changes in registrant, redirection patterns and correlations with malware infrastructure. For more context on services that automate these catches, the DropCatch platform itself maintains public information on the dynamics of the "Daily Drop" ( DropCatch), and the Infoblox report provides the detailed analysis that supports these figures on its official channels ( Infoblox).
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...