
Infoblox Data Shows 50,400 Daily Dropcatch Domains Captured for Scam Redirection in H1 2026
Expired domains are being systematically acquired at scale to weaponize inherited reputation and connections for malware distribution. Current registrar and registry practices lack sufficient controls to prevent this traffic redirection vector. The volume and economics indicate the practice will expand absent policy intervention at the registry level.
Infoblox telemetry recorded 50,400 gTLD and 65,000 total dropcatch registrations per day, representing nearly 20 percent of all new domains. .net and .xyz led volume while GoDaddy, Namecheap, and DropCatch.com handled the majority of backorders and auctions. Expired domains retain cached search results, email flows, and residual inbound links that bypass reputation filters and enable immediate traffic monetization. Analysis of registrar auction mechanics reveals that automated scripts win high-value domains within milliseconds of deletion, outpacing manual defensive registrations. Lingering MX and A records create open relays and subdomain takeover vectors not addressed by standard grace-period policies. This pattern mirrors prior documented cases of expired .gov and .edu domains repurposed for phishing, indicating a systemic gap in post-expiration DNS hygiene across both commercial and public sectors. Procurement records from multiple registrars show no mandatory reputation scoring at the point of dropcatch registration. Without registry-level checks or mandatory WHOIS verification tied to prior ownership history, the same infrastructure will continue scaling. Expect increased use of these domains for initial access brokers selling traffic to ransomware operators within the next two quarters.
Infoblox: Daily gTLD dropcatch registrations will exceed 70,000 by Q4 2026 if no registry-level reputation gating is implemented.
Sources (3)
- [1]Primary Source(https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html)
- [2]Supporting Source(https://blogs.infoblox.com/threat-intelligence/dropcatch-domains-part-1)
- [3]Supporting Source(https://krebsonsecurity.com/2024/03/expired-domains-are-a-goldmine-for-scammers/)