442/69 monday, August 17, 2026

Reports indicate a growing trend in cyberattacks in which threat actors purchase expired website domains that have been abandoned and repurpose them as infrastructure to deceive users and distribute malware. Statistics show that in the first half of the year, previously used domains accounted for 20% of all new domain registrations, or approximately 65,000 domains per day. By reusing domains with a long history, attackers can inherit the trust previously associated with those domains. As a result, security systems or web filtering software may assess them as low risk and allow these malicious domains to bypass protections, directly affecting both general users and organizations that rely on domain reputation systems.
According to the report and related statistics, the top three domain extensions with the highest proportion of re-registered expired domains were .net at 28.9%, followed by .xyz at 28.5%, and .com at 24.5%. Threat actors exploit residual search history, remaining traffic, and lingering DNS configurations for their own benefit. Initial reports identified a threat actor known as Sable Squirrel, which spent more than USD 7 million purchasing over 10,000 expired domains, including domains formerly owned by cybersecurity companies. These domains were then used to build networks of online gambling websites, illegal sports streaming sites, and command-and-control (C2) infrastructure for malware distribution. In addition, opportunistic attackers have been observed buying domains that were previously compromised to capture residual victim traffic and redirect users to technical support scams or malware delivery sites.
Given this threat trend, network administrators and cybersecurity personnel should improve risk assessment practices and avoid relying solely on a domain’s age or historical reputation when deciding whether to allow network access. Instead, organizations should increase monitoring of abnormal connection behavior and continuously review in-depth threat intelligence. Agencies and organizations should also maintain strict domain management processes by removing or decommissioning DNS records linked to systems that are no longer in use to prevent impersonation or abuse. General users are advised to carefully verify whether a website’s content aligns with its domain name. If a previously trusted website suddenly changes to gambling-related content or displays prompts to download suspicious software, users should avoid accessing it and refrain from downloading any files to reduce the risk of becoming victims of cyberattacks.
