← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Threat Actors Acquire Expired Domains to Redirect Traffic to Scams and Malware

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Threat actors acquire expired domains to redirect traffic to scams and malware.
  • 50,400 dropcatch domains are re-registered daily in gTLDs alone.
  • These domains inherit reputation, making them appear more legitimate.
  • .net and .xyz TLDs lead in dropcatch activity.

Exploiting Expired Domains

Threat actors are actively acquiring expired domains, referred to as "dropcatch domains" by DNS threat intelligence firm Infoblox. This strategy allows them to inherit existing website traffic and reputation, which they then use to redirect unsuspecting users to scam websites and malware distribution points on a large scale.

Scale of the Problem

During the first half of 2026, approximately 50,400 dropcatch domains were re-registered daily in generic top-level domains (gTLDs) such as ".com." When country code top-level domains (ccTLDs) are included, this figure rises to around 65,000 daily registrations. This means that nearly 20% of all new daily gTLD and ccTLD registrations are dropcatch domains.

Inherited Reputation and Risk

Infoblox highlights that these domains are particularly dangerous because they retain reputation and connections from their previous legitimate use. Security products and reputation-based algorithms may view them more favorably than genuinely new registrations, a fact that threat actors exploit to bypass detection. This inherited trust makes it easier for malicious actors to deceive users.

Leading TLDs and Registrars

Analysis shows that .net and .xyz are the top TLDs for dropcatch activity, surpassing .com. Other prominent TLDs include .org, .vip, .online, .store, .site, .app, and .shop. Major registrars like GoDaddy, Namecheap, and DropCatch.com facilitate these re-registrations, with each handling thousands of median daily dropcatch domains.

Domain Expiration and Re-registration Process

Domains expire for various reasons, but most gTLDs have a recovery policy allowing registrants to renew within a grace period. Once this period ends, the domain becomes available again. Custom drop catching services track domains nearing deletion and automatically attempt to register them for customers who place backorders, often leading to auctions if multiple parties are interested.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~15 min · 13 stories · Aug 17

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Threat actors are acquiring expired domains, termed "dropcatch domains," to exploit their inherited reputation and traffic for redirecting users to scams and malware. This practice accounts for nearly 20% of all daily new domain registrations, posing a significant security risk by leveraging previously legitimate web addresses.