HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Attackers Repurpose Expired Domains to Distribute Malware and Host C2 Infrastructure

Threat actors are buying expired domains that retain reputation and traffic, then using them for malware delivery and command‑and‑control. This highlights a third‑party risk gap that SOC 2 programs must address through continuous domain‑management controls.

LiveThreat™ Intelligence · 📅 August 17, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

Attackers Repurpose Expired Domains to Distribute Malware and Host C2 Infrastructure

What Happened — Threat actors are buying “drop‑catch” domains—expired names that retain reputation, backlinks, and lingering DNS records—and repurposing them for malware delivery, phishing scams, and command‑and‑control (C2) servers. In H1 2026, Infoblox reported that nearly 20 % of all new domain registrations were previously owned, with one actor (“Sable Squirrel”) spending ~$7 M to acquire >10 000 such domains.

Why It Matters for Compliance & Audit Readiness

  • The practice exploits a third‑party risk gap: legacy DNS and reputation signals bypass traditional perimeter controls, challenging the “asset inventory” requirement of SOC 2 CC6.1.
  • Continuous evidence of domain ownership and DNS hygiene is essential to demonstrate due diligence and to provide audit‑ready proof that your organization is not inadvertently serving malicious traffic.
  • Verisq’s Control Mapping capability can automatically map domain‑management controls to SOC 2 criteria and collect continuous evidence for auditors.

Who Is Affected – Primarily organizations that own public‑facing web assets across any sector (e.g., health, media, finance, SaaS), as well as DNS service providers and domain registrars.

Recommended Actions

  • Add domain registration and DNS records to your asset inventory; treat them as critical infrastructure.
  • Deploy continuous monitoring for domain reputation, DNS changes, and unexpected traffic spikes.
  • Map domain‑management policies to SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations) and retain evidence in a centralized Trust Center.

Source: Security Affairs

Technical Notes – Attack vector: acquisition of expired domains (third‑party dependency) → malicious hosting of RATs (Quasar, AsyncRAT, DCRat, Remcos) and illicit streaming sites. No specific CVE; the risk stems from domain lifecycle mismanagement and DNS record persistence. Source: same article

📰 Original Source
https://securityaffairs.com/197251/cyber-crime/crooks-are-buying-your-expired-domains-and-using-them-to-deliver-malware.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →