Your expired domain is someone else's malware C2
Infoblox tracked 65,000 expired domains re-registered daily in 2026 and one actor spending $7M on 10,000 of them. Here's why lapsed domains are a business risk.
Every business that has been running for more than five years has a graveyard of expired domains: the campaign microsite, the pre-rebrand name, the .net you bought defensively and stopped renewing. New research says that graveyard is being shopped, and the buyers are not sentimental. Infoblox Threat Intel tracked one actor that spent over $7 million acquiring more than 10,000 expired domains and wired them into malware command-and-control.
What actually happened
Per Infoblox Threat Intel, published August 13, roughly 65,000 expired domains are re-registered daily — close to one in five of all newly observed domains. The researchers call these dropcatch domains: names picked up by a new owner the moment the old registration lapses.
The named actor, Sable Squirrel, ran illegal Vietnamese sports streaming and online gambling promotion on the front end while the same infrastructure served as C2 for Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT and HiddenTear ransomware. Infoblox associated over 31,000 malware samples with the infrastructure.
The timing data is the part worth writing down. About 24% of tracked domains went live within one day of acquisition, and 94% were operational inside two weeks. Median activation was roughly five days. The Hacker News reported the same findings. There is no dormancy period you can rely on.
Why expired domains matter for your business
The reason a lapsed domain is worth money is the reason it is dangerous: it keeps your reputation. Backlinks, aged WHOIS, clean history with mail and web filters, and residual traffic from anyone who bookmarked it or printed it on a van. A brand-new domain has to earn all of that. Yours came pre-earned, and you paid for it.
Two concrete exposures. First, email. If an old domain of yours ever sent mail, or ever appeared in a customer's contact list, whoever holds it now can send from it — and land in the inbox because the domain looks familiar and the filters remember it fondly. Second, dangling DNS. CNAME records pointing at a SaaS subdomain you stopped paying for are the same failure mode one layer down: someone re-registers the target and inherits a hostname on your zone.
The fix is administrative, not technical, which is why it never gets done. Pull the full list of every domain your business has ever registered — including ones bought by an agency or a former employee on a personal card. Decide which ones you keep forever and put those on auto-renew with a card that does not expire and a registrar-lock. For the ones you genuinely release, audit your DNS for records that point anywhere you no longer control, and pull the domain out of every SPF include and email footer before it drops.
Renewal is roughly fifteen dollars a year. That is not a security budget. That is a rounding error against your brand appearing in someone's C2 telemetry.
Key takeaways
- Infoblox tracked ~65,000 expired domains re-registered daily in the first half of 2026 — nearly 20% of all newly observed domains
- One actor, Sable Squirrel, spent over $7M on 10,000+ domains used for illegal streaming, gambling promotion, and malware C2
- 24% of tracked dropcatch domains were weaponized within one day; 94% within two weeks. There is no safe waiting period
- Dropped domains keep your backlinks, aged registration history, and reputation with mail filters — that's the whole product
- Inventory every domain your business ever registered, including agency and ex-employee purchases, and auto-renew the ones tied to your identity
- Audit DNS for CNAMEs pointing at services you no longer pay for — same takeover, one layer down
Nobody owns your domain list, which is how it becomes a problem. We inventory the domains, DNS records, and third-party services a business has accumulated, then write down who renews what and when. Ask us what's in your zone file, or see how we build stacks you actually own.
Sources: Infoblox Threat Intel, August 13, 2026, The Hacker News.
- #expired-domains
- #dns
- #malware
- #domain-security
- #threat-intel
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
SpaceX closed the Cursor deal. Your IDE has a new owner.
SpaceX completed its $60B acquisition of Anysphere, maker of Cursor. What changes for teams whose developers live in that editor, and what to lock down now.
Read itRingCentral breach: 1.6M accounts are now a vishing kit
ShinyHunters leaked names, phone numbers and addresses for 1.6M RingCentral accounts after a social-engineering breach. Why your phone vendor's data is the risk.
Read it