August 14, 2026
How Expired Domains Become Weapons for Scams and Malware
Alternative title: The Hidden Cybercrime Economy Behind Expired Domains
By Rakesh Joshi
6 min read
An internet domain can look completely harmless simply because it has existed for years. But when that domain expires, its history, backlinks, reputation, and residual traffic can become valuable assets for cybercriminals.
Recent reporting has highlighted a threat actor associated with a large-scale operation involving more than $7 million spent acquiring expired domains. The domains have reportedly been repurposed across infrastructure connected to malicious redirects, scams, malware, and other abusive activity.
This demonstrates an important cybersecurity lesson:
A trusted domain name today does not guarantee that the same domain will remain trustworthy tomorrow.
What Is an Expired Domain?
A domain becomes expired when its registration is not renewed by its owner.
For example:
Legitimate website
example-news.com → News website
The owner eventually stops operating the website and does not renew the domain.
After expiration
example-news.com → Available for registration
A new owner can potentially acquire it.
The danger begins when attackers intentionally search for domains that already have:
- Established backlinks
- Search-engine history
- Existing visitors
- Older registration dates
- Brand recognition
- Links from other websites
- Historical reputation
Instead of building a malicious website from scratch, attackers can attempt to inherit some of the domain's existing ecosystem.
Why Would Hackers Spend Millions on Domains?
At first, spending millions of dollars on domain names sounds irrational.
But attackers can treat domains as cyber infrastructure.
A previously established domain may already receive users who type the address directly, follow old bookmarks, click old links, or encounter references to it elsewhere on the internet.
Researchers have previously documented malicious activity involving abandoned and expired domains, including redirects to technical-support scams, malicious advertising, and malware delivery.
The basic economic model is simple:
Acquire domains → inherit traffic/reputation → redirect users → monetize or compromise victims
At sufficiently large scale, even a small amount of traffic from thousands of domains can become valuable.
How the Attack Works
A simplified attack chain can look like this:
1. Find expired domains
Threat actors identify domains that are no longer registered but still have useful history or traffic.
2. Acquire the domains
The domains are registered through legitimate domain-registration mechanisms.
3. Rebuild the infrastructure
DNS records, hosting, redirects, and other infrastructure can be changed.
4. Wait for or attract traffic
Users may continue reaching the domain through old links, search results, bookmarks, or direct navigation.
5. Profile the visitor
Malicious infrastructure may determine characteristics such as device type, location, browser, or other signals.
6. Redirect the victim
Instead of reaching the content previously associated with the domain, the visitor can be sent through a redirect chain.
7. Deliver the final payload
Depending on the campaign, the destination could be:
- A phishing page
- A fake software update
- A technical-support scam
- Malicious advertising
- An information stealer
- A remote-access trojan
- A ransomware loader
This technique has been observed in the wild. Malwarebytes previously documented expired domains being used as part of redirect chains leading visitors toward scams and malware.
Example: A Forgotten Website Becomes a Trap
Imagine a website called:
oldtravelblog.example
For years, it was operated by a travel blogger.
Other websites linked to it, users bookmarked it, and search engines indexed its pages.
Eventually, the owner stops paying for the domain.
The domain expires.
Months later, an attacker acquires it.
Instead of restoring the original travel blog, the attacker configures the infrastructure so that visitors are redirected elsewhere.
A visitor searching for an old travel article might suddenly encounter:
"Your browser is out of date — Update Now"
The page may attempt to convince the visitor to download malicious software.
The victim did not necessarily click a suspicious advertisement or search for malware.
They simply followed an old link.
That is what makes this technique particularly dangerous.
The Trust Problem
Cybersecurity defenses frequently rely on reputation.
A domain that has existed for years may initially appear less suspicious than a newly registered domain.
Attackers can attempt to exploit this assumption.
The domain itself may be old.
The malicious infrastructure behind it may be new.
That creates an important distinction:
Domain age ≠ Current trustworthiness
A domain registered 15 years ago can still become malicious after a change in ownership or infrastructure.
Redirect Chains Make Detection Harder
The victim may not immediately go from the expired domain to the final malicious website.
Instead, the traffic can pass through multiple intermediate systems:
Expired Domain
↓
Redirector
↓
Advertising / Traffic Broker
↓
Intermediate Domain
↓
Scam or Malware Infrastructure
This makes investigation more difficult because the original domain may appear harmless during a basic scan.
Infoblox has documented parked-domain abuse in which the same domain can appear benign to automated scanners while delivering deceptive content to particular users.
This type of selective behavior is especially problematic for security researchers and automated URL-analysis systems.
Why Reputation Alone Is Not Enough
Security teams should avoid treating reputation as a permanent property.
A domain's risk profile can change because of:
- Ownership changes
- DNS changes
- Hosting changes
- Nameserver changes
- New redirect behavior
- New certificates
- New content
- Abandoned infrastructure being reclaimed
- Previously legitimate domains being repurposed
A domain that was safe yesterday may require investigation today.
The Bigger Cybersecurity Impact
This technique affects more than individual users.
Organizations can also be exposed.
Consider a company that has an old domain on an allowlist because employees historically needed access to it.
If that domain expires and is later acquired by an attacker, the organization may unknowingly continue trusting it.
Potential consequences include:
Phishing
Victims can be redirected to convincing login pages designed to steal credentials.
Malware Distribution
Visitors can be directed toward malicious downloads or exploit infrastructure.
Information Theft
Attackers may attempt to deliver information-stealing malware targeting passwords, browser data, cookies, or other sensitive information.
Ransomware
Expired domains can potentially become part of broader malware infrastructure, including ransomware-related campaigns.
Brand Abuse
Attackers can exploit the identity and historical reputation associated with the previous website.
Supply-Chain Risk
Old links embedded in applications, documentation, internal systems, or third-party websites may continue pointing toward a domain long after its original owner has abandoned it.
A Real-World Warning
The risk isn't theoretical.
In 2025, researchers reported taking control of more than 4,000 expired domains that had been associated with active backdoors. The domains were used as command-and-control infrastructure for compromised systems; registering them allowed researchers to sinkhole the infrastructure before malicious actors could potentially acquire it.
This illustrates an especially interesting security problem:
An expired domain can remain technically connected to systems that still exist.
If nobody monitors the domain lifecycle, someone else may eventually obtain control over it.
How Security Teams Can Defend Against This
Organizations should treat domain lifecycle management as part of their security program.
1. Monitor owned domains
Maintain an inventory of every registered domain and subdomain.
Track:
- Registration status
- Expiration dates
- Registrar
- Nameservers
- DNS records
- Certificate information
- Ownership information
2. Prevent accidental expiration
Use automatic renewal where appropriate and establish alerts before expiration.
A single forgotten domain can potentially create a significant security problem.
3. Audit old links
Search internal documentation, applications, repositories, websites, and marketing materials for domains that are no longer actively maintained.
4. Monitor DNS changes
Unexpected changes to DNS records, nameservers, hosting providers, or IP addresses should trigger investigation.
5. Don't rely solely on domain age
An old domain should not automatically receive a lower risk score.
Security systems should consider current behavior and historical context.
6. Use DNS and URL threat intelligence
Security teams can correlate domains against historical DNS records, passive DNS, WHOIS/RDAP data, malware intelligence, URL reputation, and other threat-intelligence sources.
7. Monitor ownership changes
A significant change in domain ownership or infrastructure can be an important indicator of risk.
8. Educate users
Employees should understand that a familiar-looking or old domain is not automatically safe.
Users should be suspicious of unexpected:
- Login prompts
- Software updates
- Security warnings
- File downloads
- Payment requests
What Individual Users Can Do
You don't need sophisticated security tools to reduce the risk.
Before downloading software from an unexpected website:
Stop → Verify → Download
Check the domain carefully.
Be especially cautious when a familiar website suddenly asks you to:
- Install an unknown application
- Disable security software
- Enter credentials
- Provide payment information
- Install a browser extension
- Call a support number
- Download an executable file
Keep your browser and operating system updated, use reputable security software, and avoid interacting with suspicious redirects.
The Bigger Lesson
The most interesting aspect of expired-domain attacks isn't the domain itself.
It is the trust surrounding the domain.
Cybercriminals don't always need to create trust from zero.
Sometimes they can acquire infrastructure that already has history.
That turns abandoned digital assets into potential weapons.
The reported multimillion-dollar investment demonstrates how valuable large-scale domain infrastructure can become for threat actors.
For defenders, the lesson is straightforward:
Don't ask only, "Is this domain old?"
Ask:
Who controls it now?
Where does it resolve?
Has its DNS changed?
What did it host historically?
Where does it redirect users?
Does its current behavior match its historical identity?
Cybersecurity isn't just about detecting malicious domains.
It's also about recognizing when trusted infrastructure has changed hands.
Final Takeaway
An expired domain may look like nothing more than an abandoned web address.
But to an attacker, it can represent traffic, reputation, infrastructure, and opportunity.
The next time you encounter an unfamiliar redirect from an old or familiar-looking website, remember:
A domain can have an old history — but a completely new owner.
Stay skeptical. Verify the destination. And never assume that an old domain is automatically a safe domain.