Attackers Repurpose Expired Domains to Distribute Malware and Host C2 Infrastructure
What Happened — Threat actors are buying “drop‑catch” domains—expired names that retain reputation, backlinks, and lingering DNS records—and repurposing them for malware delivery, phishing scams, and command‑and‑control (C2) servers. In H1 2026, Infoblox reported that nearly 20 % of all new domain registrations were previously owned, with one actor (“Sable Squirrel”) spending ~$7 M to acquire >10 000 such domains.
Why It Matters for Compliance & Audit Readiness
- The practice exploits a third‑party risk gap: legacy DNS and reputation signals bypass traditional perimeter controls, challenging the “asset inventory” requirement of SOC 2 CC6.1.
- Continuous evidence of domain ownership and DNS hygiene is essential to demonstrate due diligence and to provide audit‑ready proof that your organization is not inadvertently serving malicious traffic.
- Verisq’s Control Mapping capability can automatically map domain‑management controls to SOC 2 criteria and collect continuous evidence for auditors.
Who Is Affected – Primarily organizations that own public‑facing web assets across any sector (e.g., health, media, finance, SaaS), as well as DNS service providers and domain registrars.
Recommended Actions
- Add domain registration and DNS records to your asset inventory; treat them as critical infrastructure.
- Deploy continuous monitoring for domain reputation, DNS changes, and unexpected traffic spikes.
- Map domain‑management policies to SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations) and retain evidence in a centralized Trust Center.
Source: Security Affairs
Technical Notes – Attack vector: acquisition of expired domains (third‑party dependency) → malicious hosting of RATs (Quasar, AsyncRAT, DCRat, Remcos) and illicit streaming sites. No specific CVE; the risk stems from domain lifecycle mismanagement and DNS record persistence. Source: same article