← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 15, 2026 · 17:48via Security Affairs

Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware

Brief

Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure.

Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. Infoblox Threat Intel calls these dropcatch domains, and in the first half of 2026 they accounted for nearly 20% of all new domain registrations, meaning one in five “new” domains has a prior life. Some end up with legitimate investors or researchers.

Others end up with attackers who have figured out that a domain with history is worth more than a blank slate.

“These domains can be particularly interesting, even dangerous, because they inherit reputation and sometimes connections from their previous life.

Read more on Security Affairs