Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
An expired domain is a web address whose registration was not renewed. After its registration period ends and any grace period passes, it can become available to a new owner. That change matters because the address may still have visitors, links, and public trust. Infoblox uses “dropcatch domain” for an expired domain that receives a second chance. A different party registers it after the original owner lets it go. The new owner can then control the site’s content and technical settings, even though people may recognize the old name. The article says threat actors are acquiring these domains at large scale. They use inherited traffic and reputation to redirect people toward scams or malware. The supplied excerpt identifies the term and reports activity during the first half of 2026, but it ends before giving the full surrounding statistics.
What are expired domains, and what does “dropcatch domain” mean?
An expired domain is a web address whose registration was not renewed. After its registration period ends and any grace period passes, it can become available to a new owner. That change matters because the address may still have visitors, links, and public trust.
Infoblox uses “dropcatch domain” for an expired domain that receives a second chance. A different party registers it after the original owner lets it go. The new owner can then control the site’s content and technical settings, even though people may recognize the old name.
The article says threat actors are acquiring these domains at large scale. They use inherited traffic and reputation to redirect people toward scams or malware. The supplied excerpt identifies the term and reports activity during the first half of 2026, but it ends before giving the full surrounding statistics.
How many expired domains were acquired, and how much money did hackers spend on them?
The supplied article fragment reports that 50,400 expired domains were acquired during the first half of 2026. That figure shows the activity was not limited to isolated cases. It describes a broad operation involving many previously registered web addresses.
The excerpt does not complete the sentence after “50,400.” As a result, it does not provide the requested spending figure for hackers. No reliable amount can be calculated from the text because the purchase prices, average costs, and total investment are missing.
The scale still matters. Buying many domains lets attackers reuse established names and attract visitors without building every site from scratch. It can also make malicious redirects harder to spot. A complete article or source would be needed to state the money spent. Based only on the supplied material, the supported answer is 50,400 domains and an undisclosed spending total.
Why would an attacker want to take over a domain that previously belonged to someone else?
Attackers want expired domains because an address does not necessarily lose all its value when its owner stops renewing it. Visitors may still type the address, follow old links, or discover it through search results. Other websites may also continue linking to it.
The domain can retain a familiar name and a history that makes it appear trustworthy. For example, a previously useful site might still receive visits from bookmarks or external links. After registration, the attacker can replace the old content, change the site’s settings, or send visitors elsewhere.
This approach saves effort. The attacker does not need to attract every visitor from zero or create an entirely new reputation. The article says threat actors acquire expired domains to inherit website traffic and reputation, then redirect victims to scams and malware. Its focus is the reuse of existing online trust for harmful purposes.
How can an acquired domain redirect visitors to scams or malware?
A domain works as an entry point for visitors. Once an attacker registers an expired address, the attacker can control the domain’s web configuration. That control can turn a previously ordinary destination into a gateway for fraud or malicious software.
For example, someone might follow an old link to a familiar domain and be sent to a fake login page. The page could request passwords or payment details. Another setup could deliver malware or redirect the visitor through several sites before reaching the harmful content. The visible address may initially seem legitimate.
The article describes this as a large-scale abuse of inherited traffic and reputation. The risk is not simply that an old website disappears. Its established audience can be redirected without realizing ownership changed. Visitors should treat unexpected requests, downloads, and redirects cautiously, especially when a once-familiar site behaves differently.
What kinds of legitimate traffic and reputation can a domain retain after its original owner lets it expire?
When a domain expires, its online history does not instantly vanish. People may still visit through saved bookmarks, old messages, or links on other websites. Search engines may also retain signals from the site’s previous content. The name itself can carry recognition or trust.
For example, a domain once used by a community, business, or information site may continue receiving direct visits. External pages might still link to it, and users may assume the familiar address remains safe. A new owner can place different content there or redirect those visitors elsewhere.
The article specifically says attackers seek inherited website traffic and reputation. Those assets can make scams more convincing and reduce the need for fresh advertising. The supplied excerpt does not list every type of retained traffic or reputation signal, but established links, returning visitors, and familiarity are well-known consequences of a domain’s prior use.
How do domain registrars and automated drop-catching services make it possible to register an expired domain quickly?
A domain registrar is the service through which a person or organization registers a web address. When an address becomes available again, registrars can process a new registration. This creates the basic channel through which an expired domain changes hands.
Automated drop-catching services add speed and scale. They monitor domains approaching deletion and send registration requests as soon as the names become available. If several parties want one address, automated systems can compete faster than a person working manually. The successful request gets the new registration, subject to registry rules.
The article gives the term “dropcatch domain” to an expired domain snapped up by another party. It does not provide operational details about particular registrars or services. Still, the central mechanism is clear: expiration opens an opportunity, and automated registration helps an interested buyer seize it quickly. Threat actors can repeat that process across many names.
What role do DNS records play in deciding where a website visitor is sent?
DNS, or the Domain Name System, translates a human-readable domain into technical destination information. A visitor enters a web address, and DNS records help direct the request to the relevant server or service. Without that mapping, the name would not reliably lead to a website.
For example, an attacker who controls an expired domain can update its DNS records or related settings. The domain can then point to a server hosting a scam page, malware, or another redirect. The visitor may begin with the old, familiar address even though the underlying destination has changed.
This is why domain ownership and DNS control matter together. The article says threat actors acquire expired domains to redirect victims at large scale. DNS changes are one technical way that control can be used. The excerpt does not identify specific record types, so it supports the general role of DNS rather than a particular configuration.
This brief was written by AI from the original reporting and checked by other models. Names, figures and quotes come from the source; read it for full context.
Read more in the JupiteX app
Pulse is free. New stories every 4 hours, each one broken into the questions that explain it.
Or read more news on the web