Published Security3 min read
At 65,000 expired domains a day, registration age has stopped meaning anything
Infoblox Threat Intel says dropcatch registrations are now close to one in five new domains, and one actor spent over $7 million on 10,000 of them. Clean history is being bought, not earned.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Cybercriminals are investing millions of dollars to acquire expired domain names and repurpose them for malicious activities including malware distribution, scams, illegal streaming and online gambling, according to a report by Infoblox Threat Intel.
- Dropcatch domains are attractive to threat actors because they retain trust, backlinks and web traffic from their previous legitimate use, making them appear more favourable to security systems than new registrations.
- Approximately 65,000 dropcatch domains are registered daily.
- Dropcatch registrations account for nearly one in five new domain registrations.
- A dropcatch volume of 65,000 per day at nearly one in five of all new registrations implies a total new-domain flow of roughly 325,000 per day.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Infoblox Threat Intel has put a number on a practice that quietly breaks one of the cheapest controls in the stack: roughly 65,000 expired domains are re-registered every day through dropcatch services, accounting for nearly one in five new domain registrations [3][4]. According to the report, as covered by IT Pro, criminals are spending millions of dollars on those domains specifically because they arrive with the trust, backlinks and residual traffic accumulated by their previous legitimate owners [1][2].
The arithmetic is the point. If 65,000 dropcatch registrations are close to a fifth of the daily total, the overall new-domain flow is somewhere around 325,000 a day [5], and the dropcatch share alone runs to roughly 23.7 million domains a year [6]. That is not a niche technique operated by a handful of specialists. It is a supply chain with pricing, volume and repeat buyers.
The named examples show what the money buys. Infoblox tracked an actor it calls Sable Squirrel, which spent more than $7 million on over 10,000 expired domains used for illegal streaming and malware command and control [7]. That is on the order of $700 per domain [8], which tells you the buyer is not sweeping up junk at floor prices but paying for specific histories. The same domains reportedly host what look like ordinary streaming sites while simultaneously serving as C2 channels for Quasar RAT and HiddenTear ransomware [9]. A second group, Shady Squirrel, has worked with the SocGholish fake-update infrastructure, pushing malware through scareware and call centres [10].
For defenders, the uncomfortable part is that this is an attack on the signal, not on the perimeter. Newly registered domain heuristics, reputation scores weighted by age, and allowlists built on established backlink profiles all reward exactly the property a dropcatch buyer has just purchased. Infoblox's own framing is that the combination of volume and inherited trust makes these domains arguably a greater risk than newly registered ones [11], which inverts the assumption baked into a lot of filtering policy. A domain registered yesterday at least announces itself. A domain registered in 2014, dropped in 2024 and recaught last week does not, and your feed may still be scoring it on a decade of somebody else's behaviour.
None of this makes age worthless as an input; it makes age worthless on its own. The distinguishing event is not first registration but change of control: a new registrant, new nameservers, new hosting, a gap in resolution, a WHOIS record that resets while the backlink graph stays intact. Those are observable, and they are what reputation systems built on age alone do not capture.
What to watch: whether reputation vendors start publishing re-registration or ownership-change dates as a separate field rather than folding them into a single age score; whether the registrar and dropcatch industry faces any pressure over the buyers spending seven figures at a time [1]; and whether the streaming-front pattern Infoblox describes for Sable Squirrel [9] shows up in other categories where a plausible public-facing site provides cover for C2.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Cybercriminals are investing millions of dollars to acquire expired domain names and repurpose them for malicious activities including malware distribution, scams, illegal streaming and online gambling, according to a report by Infoblox Threat Intel.
ReportedSource: Infoblox Threat Intel, as covered by IT Pro and summarised by SC WorldView cited source - [2]
Dropcatch domains are attractive to threat actors because they retain trust, backlinks and web traffic from their previous legitimate use, making them appear more favourable to security systems than new registrations.
- [3]
Approximately 65,000 dropcatch domains are registered daily.
- [4]
Dropcatch registrations account for nearly one in five new domain registrations.
- [7]
An actor tracked as Sable Squirrel spent over $7 million on more than 10,000 expired domains used for illegal streaming and malware command and control.
- [9]
The domains often host seemingly legitimate streaming sites while simultaneously serving as command and control channels for malware including Quasar RAT and HiddenTear ransomware.
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- scworld.comSC StaffAug 14Cybercriminals invest millions in expired domains for illicit activities
- securityaffairs.comPierluigi PaganiniAug 15Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware
Additional citations
- Infoblox Threat Intel, as covered by IT Pro and summarised by SC World
- Infoblox Threat Intel



