Attackers Repurpose Expired Domains to Distribute Malware and Host C2 Infrastructure
What Happened – Threat‑intel researchers report that attackers are buying “drop‑catch” domains—expired names that retain historic reputation, backlinks, and lingering DNS records—and using them to deliver ransomware‑droppers, RATs, and phishing‑lures. In H1 2026, roughly 65 000 domains per day were re‑registered, with about 20 % carrying a prior life that can be abused for malicious traffic.
Why It Matters for Compliance & Audit Readiness
- The practice exploits a control gap in external‑asset inventory and domain‑ownership monitoring that SOC 2 trust‑service criteria (CC6 – System Operations and CC7 – Change Management) expect organizations to address.
- Continuous evidence of domain‑ownership validation and DNS‑record hygiene is required to demonstrate due diligence and to satisfy audit queries about third‑party exposure.
- Verisq’s Control Mapping capability can automatically map domain‑ownership checks to SOC 2 controls and collect immutable evidence for auditors.
Who Is Affected – All sectors that own public‑facing domains, especially technology/SaaS, finance, healthcare, and media firms that rely on brand reputation and inbound traffic.
Recommended Actions
- Add domain‑ownership verification to your asset‑inventory process; treat each domain as a critical asset subject to change‑management controls.
- Deploy continuous DNS‑monitoring to detect unexpected record changes or traffic spikes on legacy domains.
- Map these checks to SOC 2 CC6/CC7 controls and retain logs as audit evidence.
Technical Notes – Attackers leverage the residual reputation of expired domains, residual backlinks, and stale MX records to bypass reputation‑based filters. Malware families observed include Quasar RAT, AsyncRAT, DCRat, and Remcos RAT. No specific CVE is cited; the threat vector is the misconfiguration/abuse of domain lifecycle.
Source: Security Affairs