A domain name is the closest thing the web has to a credit history: age, inbound links, search visibility, and reputation all feed the reputation scores that security products consult before deciding whether a request is worth worrying about.
New research from Infoblox Threat Intel claims this history has become a commodity with a market price, and that at least one criminal operation has been buying it in bulk.
The study, published as a three-part series, focuses on what the industry calls dropcatch domains: names that lapsed, were released back to the registry, and were then re-registered by someone else entirely.
Read more…
Source: TechRadar News
Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox
Related:
- Hunting MacSync Stealer infrastructure through behavioral pivots
August 18, 2026
MacSync Stealer is a macOS-focused information stealer that relies on changing infrastructure to deliver payloads, communicate with compromised devices, and exfiltrate data. Earlier reporting by RST Cloud identified the threat through a limited set of domains and documented rapid command-and-control (C2) replacement after public disclosure. Microsoft Defender Experts expanded that view by correlating recurring endpoints and network behaviors ...
- ‘Unprecedented’ number of Apple users received recent spyware alert, say investigators
August 17, 2026
An unprecedented number of Apple customers have reported receiving a recent threat notification alerting them to suspected spyware attacks targeting their devices, according to experts who investigate these types of incidents. Several people publicly and privately reported receiving Apple’s spyware alerts over the weekend, after Apple sent out a new wave of notifications on Friday alerting customers in ...
- Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline
August 17, 2026
Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the ...
- ChainDrop worm crawls into npm supply chain, evades standard defenses
August 15, 2026
A new variant of the Shai-Hulud npm worm has poisoned hundreds of packages while adding propagation techniques that can leave little trace in the corresponding source repositories. In Frank Herbert’s Dune, Shai-Hulud was the name of the giant self-sustaining desert sandworms that moved silently beneath the surface of the planet Arrakis. So it made sense that when ...
- Researchers find ultimate Windows kill switch which can disable antivirus with almost no user interaction
August 14, 2026
Microsoft has recently fixed a vulnerability that allowed threat actors to bypass advanced security measures, disable antivirus software, and expose the target device to full system takeover. All of this, it seems, could have been possible with a very simple script, and a single click from the victim’s side. Luckily, the vulnerability was discovered by white hat hackers, ...
- APT group HoneyMyte upgrades CoolClient
August 14, 2026
CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia. It supports such capabilities as keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and plugin-based extensions. Since its first public disclosure by Sophos in 2022 and subsequent ...

