CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4515

As cited

Copy frozen at (site build).

threat intel

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

Threat actors are purchasing expired domains that retain existing traffic and reputation to redirect victims toward scams and malware. Security firm Infoblox calls these acquisitions dropcatch domains and tracked approximately 50,400 such registrations during the first half of 2026, representing a significant investment in domain infrastructure for fraud.

Why it matters: Organizations and users relying on links or bookmarks to legitimate domains face redirect attacks; defenders should monitor for domain takeovers of expired assets and implement DMARC, SPF, and DKIM to prevent inherited domains from spoofing legitimate senders.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary