Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: Medium
Victim: General internet users and enterprises
Incident: Widespread acquisition of expired domains to redirect traffic to scams and malware.
Impact: Increased efficacy of phishing and malware campaigns through the bypass of reputation-based security filters.
Attacker: Unidentified scavenger threat actors
Analysis: Attackers are utilizing ‘dropcatch’ services to acquire domains with pre-existing traffic and positive reputation scores. By inheriting these attributes, malicious redirects and malware payloads are less likely to be flagged by reputation-based security algorithms. This technique allows threat actors to bypass traditional perimeter defenses by leveraging the ‘ghost’ of a legitimate site.
Recommendations: Implement DNS filtering that prioritizes recent registration date over historical reputation; Educate users to remain vigilant with links even from previously familiar domains; Deploy advanced web security gateways that analyze content behavior rather than just domain age
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source