Expired internet domains can carry more than an old name. Backlinks, traffic, reputation, and references embedded in websites or systems may survive after ownership changes, giving new registrants access to trust or traffic built by someone else. Infoblox Threat Intel recently said it observed roughly 65,000 expired domains being re-registered each day in the first half of 2026.
In this TNGlobal Q&A, Dr. Renée Burton, Vice President of Threat Intel at Infoblox, explains how dropcatch domains are identified, why both previously legitimate and previously malicious domains can appeal to attackers, and what enterprises should do before allowing old domains to lapse.

Infoblox observed roughly 65,000 re-registered or “dropcatch” domains per day in the first half of 2026, representing nearly 20 percent of newly observed domains. How exactly does Infoblox define and identify a dropcatch domain, and how should security teams interpret that figure without assuming that every re-registered domain is malicious?
To understand domain dropcatching, we first need to define the Domain Name System (DNS) and why it sits at the core of cyber threat intelligence. DNS functions as the phonebook of the internet, translating web addresses into numerical IP addresses. Because virtually every connected device must query DNS before establishing a network connection, DNS serves as our baseline for detecting threat activity across the web.
Within this framework, dropcatch domains are expired domain names that are re-registered after they lapse. It’s surprisingly complicated to identify these changes, but we use a combination of historical registration data and DNS.
Not all 65,000 dropcatch domains that we identified are necessarily malicious. The dropcatch market is an active and legitimate commercial ecosystem of domain investors who acquire expired domains they expect to appreciate for resale or monetization. Although there are legitimate markets, security teams should treat dropcatch domains with some suspicion: they present a higher risk than a newly registered domain. Both old legitimate and old malicious domains are picked up by bad actors.
What makes an expired domain valuable to an attacker after ownership changes? Which forms of inherited trust or traffic tend to persist, and what signals are most useful in understanding why a previously legitimate domain may still attract users, systems, or security reputation after it is re-registered?
Expired domains are prized by threat actors because they provide a shortcut to both trust and traffic. If an attacker registers a brand-new domain, security tools and reputation algorithms often flag it immediately due to its lack of history.
In contrast, an expired domain inherits the previous owner’s clean record. This allows the attacker to pass traditional security filters that may rely on domain history as an indicator. This residual trust persists through legacy links scattered across the web and active search engine rankings.
Outdated security tools miss dropcatch domains because they mistake the clean history as a sign that the domain is safe. Predictive DNS security can help security teams avoid this trap by analyzing connections based on their real-time behavior, instead of their historical record.
The research estimates that the actor Infoblox calls Sable Squirrel spent more than $7 million acquiring over 10,000 expired domains. How did your team connect those domains to the same actor and estimate the acquisition spend, and what does that level of investment tell us about the economics of this type of infrastructure?
We found Sable Squirrel by combining DNS visibility with registration, web, and malware analysis. Although the front end shifted constantly under different brand names, the underlying infrastructure shared distinct digital fingerprints.
On the surface, their websites looked like consumer streaming products. After looking more closely, we found the same sports data feeds, image infrastructure, and live chat components. While this technique tricks legacy security tools, this consistent re-use of similar assets leaves valuable clues for us as threat intelligence researchers.
To calculate the $7 million spend, we used a simple extrapolation. We confirmed that the individual purchase prices for about 160 of their domains totaled over $430,000. We then applied that cost across their broader inventory of over 10,000 domains to estimate the total cost.
These figures show how cybercrime has industrialized into a full-scale criminal economy. The piracy streaming is just a front-end funnel to pull in victims. The real money comes from funneling users to controlled gambling sites. They also operate command-and-control on the very same domains, making illegal content sites a way to mask their malware operations. This is an extraordinary investment and implies that the actor is heavily resourced; they must be making a lot of money to grab this many domain names.
Your research also describes actors acquiring domains that were already malicious and remained embedded in compromised websites. How does that model differ from acquiring a previously legitimate domain for its reputation or backlinks, and why can inherited victim traffic remain useful even after the original malicious operation has changed hands?
Instead of paying millions for legacy reputation like Sable Squirrel, scavengers intentionally go after malicious domains that previous threat groups abandoned. These same actors have found other abandoned services, e.g., content delivery network (CDN) endpoints that lingered on major websites. Each of these creates a mechanism for the bad actors to send malicious content to the site visitor.
When major malware campaigns like TA2726 compromise thousands of legitimate websites, they inject scripts from a domain they control. If the original threat actors let those malicious domains expire or abandon them during infrastructure rotations, the compromised sites do not stop sending requests to the domain and anyone else can pick it up. By purchasing these domains, scavenger actors inherit active victim traffic flowing directly from existing compromises without having to build a victim funnel from scratch. They also can monetize this traffic instantly by redirecting visitors to scams, malware, or ad fraud.
These same actors who look for abandoned malicious domains sometimes luck into discovering a legitimate domain for a service that is no longer used. We documented the CDN domain imhd[.]io, which the Shady Squirrel actor picked up in early 2026 and gained access to multiple major media websites.
From an enterprise perspective, who should own the risk associated with domains that a company no longer actively uses? Before allowing a domain tied to an old product, campaign, subsidiary, or service to expire, what should organizations check for, and are there cases where keeping a domain registered indefinitely is the safer option?
Risk management for domain ownership is tricky, especially following mergers and acquisitions. The solution requires policies, processes, and automation that monitor the company’s exposure. In almost all cases, it is better to continue a domain registration that has historical ties to a company than let it lapse.
Even domains without an obvious corporate tie can be problematic. In a recent early access program, we identified dangling CNAME records at 31 out of roughly 40 participating organizations. In order to resolve this risk, organizations need to find these records in the first place. However, the solution isn’t adding more scanners or integrating more details; it’s about utilizing DNS as a security tool.
Every device that communicates on the network must communicate via the DNS. This means most organizations already have the intelligence they need. They just need the right tools to make their inactive domains visible.
What should organizations monitor after domains are retired or allowed to lapse? For companies managing hundreds or thousands of domains, which indicators or changes should be prioritized so that teams can detect potentially risky re-registration without treating every expired domain as an incident?
Once the domain has lapsed, the control is out of their hands. This is a problem that requires proactive approaches to ensure bad actors don’t get a hold of your property, rather than something that requires effort after the case.
Because legitimate users also re-register expired domains, broad blocking of all newly re-registered domains would create significant false positives. What signals can defenders combine to distinguish higher-risk dropcatch activity from ordinary domain reuse, and how quickly can those signals become actionable?
Broadly blocking all newly re-registered domains can cause false positives and operational disruption, although in very risk-averse environments it is a reasonable strategy. Dropcatch domains pose a higher risk based on our research, and we recommend blocking those to our user base during their early days.
However, the window to act is very short. Nearly a quarter (24%) of Sable Squirrel’s dropcatch domains went live the same day they were bought. Because an expired domain’s legacy reputation loses value over time, threat actors move extremely fast. Security teams must be able to respond within hours, not days.
Are you seeing any meaningful Asia Pacific-specific patterns in dropcatch abuse, whether around regional or country-code domains, registrar practices, languages, or particular types of organizations? If the threat is largely global rather than region-specific, what should APAC enterprises still take away from the research when managing regional domain portfolios?
We are seeing regional trends, especially with Vietnam emerging as a major operational hub. Sable Squirrel’s sports piracy network is built around Vietnamese-language content, with contact blocks tracing directly to Ho Chi Minh City. Chinese organized crime groups also utilize dropcatch domains to host illegal gambling sites at a very large scale in the region.
However, the infrastructure is not isolated. The same back-end services that power the Vietnamese streaming fleets also surface around Chinese-language betting platforms and adjacent campaigns aimed at Indonesian and Russian-speaking audiences.
The key takeaway for APAC enterprises is that regional domain portfolios are actively being targeted. As threat actors rely on high-volume dropcatch domains rapidly, traditional reputation lists can’t update fast enough. This is why protective DNS and pre-emptive security are so critical to block threats before they can reach APAC organizations.
Editor’s note: This Q&A has been lightly edited for clarity and style. The responses remain those of the interviewee.
Share your perspective: TNGlobal welcomes contributed insights and expert commentary from across Asia’s technology and innovation ecosystem. Submit a contribution for editorial consideration, or explore more conversations in our TNGlobal Q&A and Interviews archive.
Infoblox research finds 65,000 expired domains re-registered daily in first half of 2026

