HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Attackers Repurpose Expired Domains to Distribute Malware and Host C2 Infrastructure

Threat‑intel shows criminals buying expired domains—about 20 % of new registrations—to inherit reputation, backlinks, and stale DNS records, then using them for malware delivery and command‑and‑control. This highlights a control gap that SOC 2 programs must close with continuous domain‑ownership monitoring.

LiveThreat™ Intelligence · 📅 August 15, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
2 recommended
📰
Source
securityaffairs.com

Attackers Repurpose Expired Domains to Distribute Malware and Host C2 Infrastructure

What Happened – Threat‑intel researchers report that attackers are buying “drop‑catch” domains—expired names that retain historic reputation, backlinks, and lingering DNS records—and using them to deliver ransomware‑droppers, RATs, and phishing‑lures. In H1 2026, roughly 65 000 domains per day were re‑registered, with about 20 % carrying a prior life that can be abused for malicious traffic.

Why It Matters for Compliance & Audit Readiness

  • The practice exploits a control gap in external‑asset inventory and domain‑ownership monitoring that SOC 2 trust‑service criteria (CC6 – System Operations and CC7 – Change Management) expect organizations to address.
  • Continuous evidence of domain‑ownership validation and DNS‑record hygiene is required to demonstrate due diligence and to satisfy audit queries about third‑party exposure.
  • Verisq’s Control Mapping capability can automatically map domain‑ownership checks to SOC 2 controls and collect immutable evidence for auditors.

Who Is Affected – All sectors that own public‑facing domains, especially technology/SaaS, finance, healthcare, and media firms that rely on brand reputation and inbound traffic.

Recommended Actions

  • Add domain‑ownership verification to your asset‑inventory process; treat each domain as a critical asset subject to change‑management controls.
  • Deploy continuous DNS‑monitoring to detect unexpected record changes or traffic spikes on legacy domains.
  • Map these checks to SOC 2 CC6/CC7 controls and retain logs as audit evidence.

Technical Notes – Attackers leverage the residual reputation of expired domains, residual backlinks, and stale MX records to bypass reputation‑based filters. Malware families observed include Quasar RAT, AsyncRAT, DCRat, and Remcos RAT. No specific CVE is cited; the threat vector is the misconfiguration/abuse of domain lifecycle.

Source: Security Affairs

📰 Original Source
https://securityaffairs.com/197251/uncategorized/crooks-are-buying-your-expired-domains-and-using-them-to-deliver-malware.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →