The images in this article were generated with artificial intelligence. How we publish
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatch domains- to take advantage of your traffic, history and reputation signals and redirect users to scams, illegal bets and malware distribution networks. According to the analysis, in the first half of 2026 they were re- recorded about 50,400 dropcatch daily only in gTLDs (.com, .net, .org, etc.) and about 65,000 if ccTLDs are included, which represents almost a fifth of the new daily inscriptions. These figures and the pattern of behaviour are confirmed by Infoblox; other statements in the report (such as the regional attribution of certain operations) are telemetry-based and therefore subject to review.
Technically, the mechanics is simple but effective: when a domain expires and passes its grace period, it returns to the "tail" of the record removal and can be captured by backorder services or auctions. Specialized platforms such as DropCatch.com use algorithms that try to register milliseconds after release; when there is more than one postulant the domain is adduced to the best bidder in a public bid. This allows malicious acquirers to obtain domains with a history of incoming links, indexed entries in search engines, DNS records and sometimes residual mail or certificates, elements that can make that domain more reliable by search engines and automated defenses.

The report identifies specific patterns: .net and .xyz lead the re-registration activity by TLD; .com is third, and registrators such as GoDaddy, Namecheap and DropCatch.com appear among the usual channels of acquisition. Infoblox also documents that a significant percentage of these domains are launched very quickly after purchase: 24% on the same day, 76% in one week and 94% in 15 days, which shows the intention to exploit them without delay.
An illustrative case and verified by the analysis is the operation called "Sable Squirrel," which according to Infoblox would have invested almost $7 million in expired domains and controls more than 10,000 names. The infrastructure linked to this actor serves as a network for the transmission of pirate sports events, promotion of betting sites and, simultaneously, as command and control backend (C2) for malware families such as Quasar RAT, AsyncrAT, DCRat, NanoCore, RAT Remcos and njRAT; the report notes that more than 31,000 malware samples have communicated with the infrastructure assigned to this operation. Infoblox also reports that some of these same web addresses present streaming content in public while operating as C2, which demonstrates the dual utility sought by the attackers.
These practices affect a wide range of actors. Users looking for free sports events or content can be redirected to platforms that install malicious applications or lead to fraud and betting. Companies and brands suffer reputational damage when their old domains - or similar imitations - are reused for illicit activities. For security teams, the existence of so many "wholesale" domains complicates prioritization, because many solutions continue to use the age and history of a domain as signs of trust.
The real consequences include increased malware campaigns and initial access to corporate networks, advertising fraud and monetization for illicit traffic, and difficulties in blocking malicious content without affecting legitimate traffic. In addition, the use of sealing techniques and traffic distribution systems that filter by geolocation or visitor behavior allows the malicious pages to remain hidden from scanners and most public investigations.
As for concrete measures, the steps differ according to the profile. For end-users: avoid downloading apps or following links that arrive from unofficial streaming sites, check the domain reputation (not only seniority), keep the system and antivirus up-to-date, and activate mail protections (SPF / DKIM / DMARC) in your business or personal accounts where possible. For security teams and administrators: incorporate expired domain intelligence and passive DNS into telemetry; do not rely exclusively on the domain's seniority as a confidence indicator; block or inspect domains that recently change the registry and monitor new TLS certificates linked to names with history. Use dynamic black lists combined with contextual categorization and evaluate implementing synkholding coordinated with authorities for clearly malicious domains.

Companies and brands should audit their domain portfolio and renewal policies, enable transfer and authentication block of two factors in the registry accounts, and consider recording critical variations or domains with potential confusion to prevent malicious actors from taking advantage of them. Registers and policy makers can mitigate risks by improving recovery windows and the transparency of auctions, and by facilitating liability for auction transactions; organizations such as ICANN document the life cycle of a domain and good practices to be reviewed ( ICANN: domain life cycle).
Among the limitations and areas of uncertainty it should be noted that the geographical attribution and exact calculation of the criminal benefit are often based on telemetry and evidence-healing correlations, not on public admissions, so these assessments can be updated with new information. It is also possible that part of the activity documented by Infoblox will include legitimate acquisitions of investors or brand advocates; the presence of residual traffic does not necessarily imply malicious intention until the domain is used in an abusive manner.
The practical conclusion is that the mass purchase of expired domains is no longer a theoretical risk: is an operating vector exploited for fraud, malware distribution and illicit monetization schemes. Defenders should stop considering the age of a domain as an immutable signal of confidence and deploy technical and process controls aimed at detecting rapid changes in registrant, redirection patterns and correlations with malware infrastructure. For more context on services that automate these catches, the DropCatch platform itself maintains public information on the dynamics of the "Daily Drop" ( DropCatch), and the Infoblox report provides the detailed analysis that supports these figures on its official channels ( Infoblox).
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...

SharePoint in CVE alert 2026 55040 JWT failures allow for identity supplanting and data exfiltration
In recent weeks malicious activity has been detected taking advantage of a critical vulnerability in Microsoft SharePoint registered as CVE-2026-55040(CVSS 9.1), which Microsoft...