Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

August 17, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: Medium
Victim: General internet users and enterprises
Incident: Widespread acquisition of expired domains to redirect traffic to scams and malware.
Impact: Increased efficacy of phishing and malware campaigns through the bypass of reputation-based security filters.
Attacker: Unidentified scavenger threat actors
Analysis: Attackers are utilizing ‘dropcatch’ services to acquire domains with pre-existing traffic and positive reputation scores. By inheriting these attributes, malicious redirects and malware payloads are less likely to be flagged by reputation-based security algorithms. This technique allows threat actors to bypass traditional perimeter defenses by leveraging the ‘ghost’ of a legitimate site.
Recommendations: Implement DNS filtering that prioritizes recent registration date over historical reputation; Educate users to remain vigilant with links even from previously familiar domains; Deploy advanced web security gateways that analyze content behavior rather than just domain age
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *