The expired domains malware story became worth paying attention to on August 14, 2026, when fresh reporting pulled together new Infoblox research showing just how aggressively threat actors are buying old domains and turning them into scam, redirection, and malware infrastructure. If your team still treats an old URL as automatically safer than a brand-new one, that assumption is now expensive.
That matters because a trusted-looking domain can slip through ordinary habits. People click old bookmarks. Search engines keep stale results alive. Vendor documentation, support threads, forgotten campaign pages, and archived community posts keep pointing at domains long after the original owner is gone. Once a criminal buys that address, the trust does not disappear with the renewal notice.
Fresh coverage from The Hacker News and deeper reporting from Infoblox's dropcatch research make the practical lesson clear. This is not a domain-industry curiosity. It is a security control failure at the point where reputation, memory, and real traffic meet.
Key Takeaway: An expired domain is not just an abandoned asset. It can become a believable attack surface that inherits trust from its previous life.
Why expired domains malware risk is rising in 2026
The numbers alone should reset how you think about old URLs. Infoblox said it observed more than 50,000 re-registered dropped domains every day in generic top-level domains during the first half of 2026. When country-code domains were added, the figure climbed to around 65,000 per day. Roughly one in five newly observed registrations had a prior life.
That scale changes the problem. You are not dealing with a rare edge case where a hobby site changes hands once in a while. You are dealing with a large, liquid market where old domains with history, backlinks, cached search presence, and residual traffic are available to whoever values them most.
Threat actors value them because reputation is transferable in practice, even when ownership is not. A freshly registered domain often triggers skepticism from users and detection systems. An older domain can look familiar, show up in long-standing search results, and carry signals that make it appear less suspicious. That does not guarantee bypass, but it improves the odds enough to justify investment.
Key Stat: Infoblox found that 24% of dropcatch domains went live the same day they were re-registered, 76% within a week, and 94% within two weeks.
The result is simple. Defenders who focus heavily on new-domain risk but underweight ownership change, historical context, and lingering references are leaving a blind spot wide open.
What the August 14 reporting actually showed
The strongest example in the new reporting was a threat actor Infoblox calls Sable Squirrel. According to the company's analysis, the group has spent more than $7 million on expired domains to support a broader criminal machine tied to illegal streaming, gambling promotion, and malware command-and-control.
That is the part many teams miss. The domain is not the end product. It is infrastructure. Old domains can funnel users to scam pages, reinforce search visibility, preserve inbound traffic, host redirects, and in some cases operate as malware control points while still presenting apparently normal content to visitors.
Infoblox said it identified more than 10,000 domains under the actor's control and over 31,000 malware samples communicating with related infrastructure. That shifts the story from "bad people buy old websites" to "criminal operations are budgeting for trust the same way they budget for hosting, tooling, and distribution."
The specific examples also matter. Reporting described domains connected to prior corporate campaigns, defunct startups, community sites, and consumer-facing projects being repurposed into a criminal funnel. That is exactly why security teams should stop assuming that age, backlinks, or prior legitimacy equal present legitimacy.
How old trust survives longer than you think
An expired domain keeps value because the internet is forgetful in the wrong way. Links persist. Cached pages linger. Documentation does not update itself. Employees pass old references around without checking ownership. Marketing teams reuse lists of historical resources. Partners may still have hardcoded redirects or whitelisted destinations.
This creates several practical attack paths:
- A stale help article or vendor integration guide sends users to a domain that has changed hands.
- An old campaign microsite still receives search traffic and gets repurposed into a redirector.
- Residual email or contact attempts aimed at the former owner can become intelligence for the new one.
- Security tools that score domains partly on age or history may initially treat the domain less harshly than a brand-new registration.
None of these paths requires a breakthrough exploit. They only require defenders to assume continuity where none exists.
This is the same broad category of trust abuse that shows up in OpenAI organization impersonation attacks, where familiar context lowers suspicion, and in the aftermath of the RingCentral data breach, where ordinary business details become follow-on fraud material. The pattern is not identical, but the lesson is. Attackers do not always need to break trust. Sometimes they inherit it.
Where expired domains become a business problem
The most obvious risk is malware delivery, but that is not the only risk worth planning for. In many organizations, the first real damage comes from workflow confusion rather than immediate exploitation.
Search and referral traffic
If an old domain still has backlinks from forums, knowledge bases, media coverage, or customer documents, the new owner inherits a stream of plausible visitors. Some may land on scams. Others may be redirected through traffic-distribution systems that sort by geography, device type, or browser.
Internal references and user habits
Teams often store URLs in runbooks, saved emails, shared inbox macros, onboarding docs, and personal bookmarks. If those links point to resources that later expire, your users may keep walking into the same trap months after the original owner disappears.
This is one reason shared inbox security and browser hygiene at work matter more than they look on paper. The problem is not just whether a browser blocks a malicious site. The problem is whether your normal workflows keep feeding people to the wrong destination.
Detection blind spots
Many detection pipelines are built to catch obvious novelty. They watch for newly registered domains, suspicious TLDs, typo-squats, and sudden reputation spikes. Those controls still matter. But they can miss domains that look seasoned because the history belongs to someone else.
Common Mistake: Treating domain age as a safety signal without checking whether the current owner, registrar pattern, or hosting footprint still matches the original trust context.
What security teams should check this week
If you want a useful response, do not turn this into a vague awareness campaign. Turn it into a short trust-audit exercise.
Start with places where historical URLs tend to survive:
- knowledge bases and help-center articles
- onboarding guides and internal wiki pages
- shared inbox templates and saved customer replies
- marketing landing pages and archived campaign links
- allowlists in email, DNS, proxy, and web-filter controls
Then check whether the domains behind those references still belong to who you think they belong to. You do not need perfect attribution to improve your posture. You need a workable process for spotting obviously stale or repurposed destinations before your users validate them for attackers.
A practical review sequence
- Export known domains from internal documentation, browser bookmarks used by teams, and messaging templates.
- Compare them against current WHOIS and registrar history where available.
- Flag destinations that have expired recently, changed ownership, or now resolve to unrelated infrastructure.
- Review security controls that rely too heavily on historical reputation or age.
- Update internal references and remove stale trust anchors.
This is also a good moment to tighten response paths for suspicious redirects, unexpected login prompts, and "familiar" destinations that suddenly behave differently. If a trusted URL now bounces users through multiple hops or lands on low-quality content, treat that as a security event, not a nuisance.
Pro Tip: Ownership change is often the real signal. A domain can be old and still be newly dangerous.
What this changes for defensive strategy
The expired-domain problem sits between asset management, brand protection, email security, web filtering, and user education. That means it often belongs to everyone a little and no one enough. That is why it persists.
A better defensive model treats domains as living trust assets with lifecycle risk. If a partner domain goes dark, if a campaign property is no longer maintained, or if an old support destination starts resolving somewhere new, someone should own the follow-up. Otherwise, the cleanup never happens and attackers get the benefit of your organizational memory.
This also argues for better measurement. New-domain blocks are useful metrics, but they can hide the quieter failures. You should also ask:
- How many stale external URLs still exist in internal documentation?
- How often do users follow archived links to domains we no longer monitor?
- Which controls can detect ownership or infrastructure shifts instead of only raw domain age?
Those questions are less glamorous than talking about zero-days, but they usually map more directly to preventable loss.
Expired domains are now part of the trust economy attackers buy
The August 14 reporting mattered because it translated a quiet infrastructure pattern into a visible operational lesson. Threat actors are not only stealing credentials, exploiting software, or spamming users. They are also buying yesterday's trust and reusing it as distribution, redirection, and control infrastructure.
For defenders, that means the old habit of classifying domains into "new and risky" versus "old and probably fine" is no longer good enough. Expired domains malware risk lives in the gray zone where a familiar URL, an old backlink, or a forgotten runbook entry still carries enough credibility to move a user or a machine one step too far.
If you want to reduce that risk, start with the boring work. Review the links your team already trusts. Remove the ones nobody owns. Watch for ownership shifts, not just flashy indicators. In 2026, an old URL can be one of the newest ways into your environment.