The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch

Author: Published 5 min de lectura 142 reading

The images in this article were generated with artificial intelligence. How we publish

An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatch domains- to take advantage of your traffic, history and reputation signals and redirect users to scams, illegal bets and malware distribution networks. According to the analysis, in the first half of 2026 they were re- recorded about 50,400 dropcatch daily only in gTLDs (.com, .net, .org, etc.) and about 65,000 if ccTLDs are included, which represents almost a fifth of the new daily inscriptions. These figures and the pattern of behaviour are confirmed by Infoblox; other statements in the report (such as the regional attribution of certain operations) are telemetry-based and therefore subject to review.

Technically, the mechanics is simple but effective: when a domain expires and passes its grace period, it returns to the "tail" of the record removal and can be captured by backorder services or auctions. Specialized platforms such as DropCatch.com use algorithms that try to register milliseconds after release; when there is more than one postulant the domain is adduced to the best bidder in a public bid. This allows malicious acquirers to obtain domains with a history of incoming links, indexed entries in search engines, DNS records and sometimes residual mail or certificates, elements that can make that domain more reliable by search engines and automated defenses.

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
Image generated with IA.

The report identifies specific patterns: .net and .xyz lead the re-registration activity by TLD; .com is third, and registrators such as GoDaddy, Namecheap and DropCatch.com appear among the usual channels of acquisition. Infoblox also documents that a significant percentage of these domains are launched very quickly after purchase: 24% on the same day, 76% in one week and 94% in 15 days, which shows the intention to exploit them without delay.

An illustrative case and verified by the analysis is the operation called "Sable Squirrel," which according to Infoblox would have invested almost $7 million in expired domains and controls more than 10,000 names. The infrastructure linked to this actor serves as a network for the transmission of pirate sports events, promotion of betting sites and, simultaneously, as command and control backend (C2) for malware families such as Quasar RAT, AsyncrAT, DCRat, NanoCore, RAT Remcos and njRAT; the report notes that more than 31,000 malware samples have communicated with the infrastructure assigned to this operation. Infoblox also reports that some of these same web addresses present streaming content in public while operating as C2, which demonstrates the dual utility sought by the attackers.

These practices affect a wide range of actors. Users looking for free sports events or content can be redirected to platforms that install malicious applications or lead to fraud and betting. Companies and brands suffer reputational damage when their old domains - or similar imitations - are reused for illicit activities. For security teams, the existence of so many "wholesale" domains complicates prioritization, because many solutions continue to use the age and history of a domain as signs of trust.

The real consequences include increased malware campaigns and initial access to corporate networks, advertising fraud and monetization for illicit traffic, and difficulties in blocking malicious content without affecting legitimate traffic. In addition, the use of sealing techniques and traffic distribution systems that filter by geolocation or visitor behavior allows the malicious pages to remain hidden from scanners and most public investigations.

As for concrete measures, the steps differ according to the profile. For end-users: avoid downloading apps or following links that arrive from unofficial streaming sites, check the domain reputation (not only seniority), keep the system and antivirus up-to-date, and activate mail protections (SPF / DKIM / DMARC) in your business or personal accounts where possible. For security teams and administrators: incorporate expired domain intelligence and passive DNS into telemetry; do not rely exclusively on the domain's seniority as a confidence indicator; block or inspect domains that recently change the registry and monitor new TLS certificates linked to names with history. Use dynamic black lists combined with contextual categorization and evaluate implementing synkholding coordinated with authorities for clearly malicious domains.

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
Image generated with IA.

Companies and brands should audit their domain portfolio and renewal policies, enable transfer and authentication block of two factors in the registry accounts, and consider recording critical variations or domains with potential confusion to prevent malicious actors from taking advantage of them. Registers and policy makers can mitigate risks by improving recovery windows and the transparency of auctions, and by facilitating liability for auction transactions; organizations such as ICANN document the life cycle of a domain and good practices to be reviewed ( ICANN: domain life cycle).

Among the limitations and areas of uncertainty it should be noted that the geographical attribution and exact calculation of the criminal benefit are often based on telemetry and evidence-healing correlations, not on public admissions, so these assessments can be updated with new information. It is also possible that part of the activity documented by Infoblox will include legitimate acquisitions of investors or brand advocates; the presence of residual traffic does not necessarily imply malicious intention until the domain is used in an abusive manner.

The practical conclusion is that the mass purchase of expired domains is no longer a theoretical risk: is an operating vector exploited for fraud, malware distribution and illicit monetization schemes. Defenders should stop considering the age of a domain as an immutable signal of confidence and deploy technical and process controls aimed at detecting rapid changes in registrant, redirection patterns and correlations with malware infrastructure. For more context on services that automate these catches, the DropCatch platform itself maintains public information on the dynamics of the "Daily Drop" ( DropCatch), and the Infoblox report provides the detailed analysis that supports these figures on its official channels ( Infoblox).

Coverage

Related

More news on the same subject.