Skip to content

Product1 publisher3 min readPublished

The cheapest attack surface is a domain someone else already made trustworthy

Astrolavos Lab counted 27,758 blacklisted and 238,279 malware-resolved domains that expired and were then maliciously re-registered, including an expired APT name.

The Product Desk · Product desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Any individual who re-registers an expired domain implicitly inherits the residual trust associated with the domain's prior use.
  • The researchers find that adversaries can, and do, use malicious re-registration to exploit domain ownership changes, undermining the security of both users and systems.
  • The study finds that many seemingly disparate security problems share a root cause in residual domain trust abuse.
  • The study measures the scope and growth of residual domain trust abuse over the past six years.
  • The researchers identified 27,758 domains from public blacklists that expired and were then maliciously re-registered.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

Astrolavos Lab, in a study titled "28 Registrations Later: Measuring the Exploitation of Residual Trust in Domains," measured six years of expired-domain turnover and identified 27,758 domains from public blacklists and 238,279 domains resolved by malware that expired and were then maliciously re-registered [10][4][5][6]. The reason this matters more than a fresh-registration statistic: whoever re-registers an expired name implicitly inherits the residual trust attached to its prior use [1], and the researchers report that adversaries can and do exploit those ownership changes to undermine the security of users and systems [2].

The two counts sum to 266,037 domains over the measurement window, an average of roughly 44,340 per year if you spread them evenly [11][13]. The malware-resolved figure outnumbers the blacklisted one by about 8.6 to 1 [12], and it is the number operators should read twice. A blacklisted domain carries reputational baggage that a re-registrant has to work around. A domain that malware resolves carries an installed base: hosts that will keep calling out to it on schedule regardless of who now answers. Acquiring one is not buying a name, it is acquiring a callback list you did not have to build. The paper's sharpest single instance is exactly that case, an expired APT domain that, by the researchers' account, could be used to revive existing infections [8].

The lab's framing is that a set of security problems that look unrelated in a ticket queue share one root cause in residual domain trust abuse [3], and that the problem had gone largely unnoticed [14]. Their proposed technical remedy is Alembic, described as a lightweight algorithm that uses only passive DNS observations to flag potential domain ownership changes [7]; they used it to surface several instances of abuse, including the APT case [8]. They also discuss policy remedies alongside the technical one [9].

Two honest limits. The study measures inherited trust, not price, and does not compare what a re-registered domain costs an attacker against a newly registered one [1][2]. And the counts are historical, covering the six years before the work was published [4], so treat them as evidence that the mechanism works at scale rather than as this quarter's volume.

The operational read is unglamorous. Most organisations have a list of names that are load-bearing and unowned: a marketing domain from a campaign that ended, an SPF include for a vendor that got acquired, a hardcoded update or telemetry host in a shipped device, an old corporate domain kept alive only by an MX record. Expiry converts each of those into an asset someone else can buy. The trust does not lapse with the registration, which is the whole point of the finding [1].

What to watch: whether your reputation and allowlist tooling treats a detected ownership change as a reset of history, or keeps scoring the new registrant on the old owner's record [1]; whether passive-DNS ownership-change signals of the kind Alembic produces show up in the feeds you already pay for [7]; and whether registries and registrars move on any of the policy remedies the paper raises rather than the technical one alone [9]. In the meantime, an inventory of every domain your systems trust but do not renew is a cheap piece of work with a known failure mode attached [5][6].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories