Executive Summary
- An expired domain is not necessarily a clean slate. The source post explains that an old domain may retain backlinks, search-engine history, email traffic, reputation signals, web traffic, DNS relationships and systems that still trust or reference it.
- If an attacker registers the expired domain, inherited history may make the attacker-controlled infrastructure appear more trustworthy than a completely new malicious domain.
The Attack Concept
- Legitimate Domain → Domain Expires → Attacker Registers It → Old Reputation + Traffic Remains → Malicious Infrastructure Added → Victims Redirected → Malware / Scam / C2.
- The post refers to this concept as domain dropcatching.
Why Organizations Should Care
- Old DNS records, CNAME references, API integrations, software calling an old domain, email addresses, password-reset addresses and allowlisted domains may remain after a business stops using a domain.
- If an organization no longer owns a referenced domain, another party may eventually control it, creating a potential security problem.
Reported Scale in the Source Post
- The supplied post cites Infoblox reporting approximately 65,000 dropcatch domains re-registered per day and says around one in five new registrations in the first half of 2026 had a previous registration history.
- It also cites a tracked actor, Sable Squirrel, as controlling more than 10,000 domains and spending nearly $7 million acquiring expired domains.
- The post associates some infrastructure with Quasar RAT, AsyncRAT, DCRat and Remcos RAT.
What Organizations Should Do
- Before allowing a domain to expire, search DNS records.
- Remove old CNAMEs and check certificates.
- Search source code for references.
- Check APIs and integrations.
- Review email addresses and password-reset addresses.
- Remove domain allowlists.
- Check SaaS/vendor dependencies.
- Monitor for unexpected DNS activity.
- Maintain a complete inventory of domains.
CyberRakshak Labs Insight
- A domain that nobody remembers can become an attack path that nobody is monitoring.
Source note: This research page expands the corresponding CyberRakshak Labs LinkedIn post supplied by the author. Claims and figures in the incident sections are presented as reported in that source post.