Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

Summary

Threat actors are spending significant amounts on expired domains to hijack their established traffic and reputation. These "dropcatch domains" are then used to redirect unsuspecting users towards scams and malware.

IFF Assessment

FOE

This tactic allows attackers to leverage the credibility of existing websites to effectively distribute scams and malware, posing a direct threat to users and defenders.

Defender Context

Defenders should be aware of this tactic, as it can lead to users falling victim to phishing and malware through seemingly legitimate redirects. Monitoring for newly registered domains that were previously established, especially those with high traffic, could be a valuable proactive measure.

Read Full Story →