Enterprise cybersecurity teams and network defense specialists are facing an escalating threat vector in domain name infrastructure. A comprehensive threat intelligence investigation by DNS security firm Infoblox, disclosed on August 15, 2026, reveals that organized cybercriminal syndicates have spent nearly $7 million acquiring expired domains to weaponize their established reputation for widespread malware distribution and fraud.

How the ‘Dropcatch’ Domain Scavenging Ecosystem Operates

In the domain ecosystem, “dropcatching” refers to the automated bidding and re-registration of domain names immediately after their original ownership lapses. Rather than building new domains from scratch—which are routinely flagged by security filters as newly registered domains (NRDs)—adversaries specifically hunt for expired domains with high domain authority, existing backlink profiles, and clean reputation histories.

According to researchers, threat groups like Sable Squirrel have automated this pipeline at an industrial scale. By acquiring thousands of expired corporate, institutional, and regional media domains, the operators inherit steady streams of organic traffic.

Bypassing Secure Web Gateways via Inherited Trust

Once acquired, the threat actors configure dynamic DNS routing and conditional JavaScript redirectors on the expired domains. The attack mechanism poses severe risks to corporate networks:

  • Evasion of Reputation-Based Filtering: Because the domain names are years or decades old with established reputation records, legacy Secure Web Gateways (SWGs) and firewall content filters classify the traffic as trustworthy.
  • Targeted Malware & RAT Delivery: Visitors are dynamically profiled based on user-agent, IP geolocation, and referrer headers before being redirected to Remote Access Trojan (RAT) payloads, fake software updates, or real-time credential traps.
  • Ransomware & Malvertising Distribution: Compromised domain networks serve as reliable distribution channels for secondary ransomware loaders and illegal gambling platforms.

Recommended Defensive Countermeasures

To prevent enterprise endpoints from falling victim to dropcatch traffic diversion schemes, security operations centers (SOCs) should adopt several critical defensive controls:

  • Track Domain Ownership and Nameserver Velocity: Upgrade DNS security monitoring to evaluate WHOIS registrant shifts and nameserver modifications (Newly Acquired Domains or NADs) rather than relying solely on initial creation dates.
  • Implement Behavioral DNS Traffic Auditing: Monitor enterprise egress telemetry for sudden spikes in requests to re-routed legacy domains hosting anomalous CNAME or A record changes.
  • Secure Enterprise Domain Portfolio Lifecycles: Maintain strict corporate domain management policies, including multi-year auto-renewals and registrar locks, to ensure decommissioned sub-brands and campaign domains are never dropped.

Source: The Hacker News / Infoblox Threat Intelligence