Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
Summary
Threat actors are spending significant amounts on expired domains to hijack their established traffic and reputation. These "dropcatch domains" are then used to redirect unsuspecting users towards scams and malware.
IFF Assessment
FOE
This tactic allows attackers to leverage the credibility of existing websites to effectively distribute scams and malware, posing a direct threat to users and defenders.
Defender Context
Defenders should be aware of this tactic, as it can lead to users falling victim to phishing and malware through seemingly legitimate redirects. Monitoring for newly registered domains that were previously established, especially those with high traffic, could be a valuable proactive measure.