What happened
Infoblox's researchers set out to size a market that everyone in DNS knows exists and nobody had measured well: the automated re-registration of expired domains. Their finding for the first half of 2026 is that dropcatch registrations run at about 50,400 per day in gTLDs and about 65,000 per day once ccTLDs are included, which makes them roughly one in five of all newly observed domains.
The reason buyers pay for a dead domain rather than registering a fresh one is that a dead domain is not dead. It keeps its backlinks, its residual traffic, its email reputation, and its history in every allowlist and reputation feed that scored it while it was legitimate. Infoblox describes these as "the kind of reputation signals many defenses still treat as indications of trustworthiness."
The centerpiece is an actor Infoblox names Sable Squirrel: more than 10,000 domains, an extrapolated spend of close to $7 million, tied to a Vietnamese-language sports piracy network and to over 31,000 malware samples that connect to its domains, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos and njRAT. The examples named include healthymagination.com (a former General Electric health initiative), maxfactor-international.com (a Procter & Gamble cosmetics brand) and snsystems.com (a former Sony developer-tools subsidiary). The same domain can be redirected to different destinations depending on who visits, so a security analyst and a consumer see different things.
Why it matters if you run public infrastructure
Most coverage of this research is about victims who visit these domains. The more useful reading for anyone who owns domains is the other direction: every domain you let lapse becomes someone else's asset, and it walks out the door carrying your name.
- Campaign and product domains. The GE and P&G examples were exactly this: a brand initiative ended, the renewal stopped, and the domain, still linked from press coverage and partner sites, now redirects to gambling or serves malware under a familiar name.
- Dangling references in your own DNS. A CNAME on your main domain that points
at a hostname on a domain you no longer own is a subdomain takeover with extra steps. An SPF
include:that references a lapsed vendor domain lets the new owner send mail that passes as you. The dropcatcher does not even need to target you; the automation buys the domain and the pointer does the rest. - Email. Old domains receive old mail: password resets, invoices, partner correspondence, and any account still registered under an address there.
- Reputation debt. When a former domain of yours starts serving RAT command-and-control, the breach reports and blocklists say your brand name.
What to check this week
- List every domain your organization has ever registered, including campaigns, acquisitions, regional variants and defensive registrations, with its expiry date and the card or account it renews on. Lapses usually trace to a card that expired or an employee who left, not a decision.
- Decide, per domain, to renew or to retire deliberately. Retiring means removing every reference to it first: DNS records elsewhere, SPF includes, OAuth redirect URIs, webhooks, documentation and email accounts.
- Search your zones for pointers to domains you do not control. CNAMEs, MX, NS delegations and SPF includes. Confirm each target's registration is current and belongs to a vendor you still use.
- Watch expiry dates continuously, with alerts far enough ahead that a procurement cycle fits inside the window. A 30-day notice from a registrar that goes to a departed employee's inbox is how the GE-style case happens.
How Attack Surface Scan covers this
Attack Surface Scan tracks the registration expiry of every verified domain and alerts as the date approaches, alongside the certificate and DNS checks on the same domain. Its dangling-CNAME detection flags records on your domains that point at hostnames which no longer resolve or belong to a provider where the target is unclaimed, which is the mechanism that turns someone else's dropcatch into your incident. Lookalike-domain monitoring covers the adjacent case, where the name was never yours but is close enough to be used against you.
Sources
- Infoblox Threat Intel: The Second Life of Expired Domains
- The Hacker News: Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
- TechNode Global: Infoblox research finds 65,000 expired domains re-registered daily in first half of 2026
- Intelligent CISO: Infoblox Threat Intel exposes the criminal afterlife of expired domains