Infoblox Threat Intel reports that nearly 20% of daily gTLD registrations are dropcatch domains—previously registered domains that expired and were re-registered. Threat actors exploit the inherited reputation and lingering connections of these domains to facilitate malware distribution, phishing, and infrastructure hijacking. Threat actors Shady Squirrel and Sable Squirrel are actively using this technique.
Infrastructure Hijacking
1 post
Drop Something? Don’t Worry, Someone Caught it