Expired Domains and Rust Ransomware Redefine the 2026 Malware Landscape
The Expired Domain Economy: A New Malware Delivery Channel
In the first half of 2026, cybersecurity researchers uncovered a sprawling criminal enterprise built on an unlikely foundation: expired internet domain names. According to DNS threat intelligence firm Infoblox, threat actors are spending millions of dollars to acquire expired domains, inheriting their residual traffic, backlinks, and reputation signals to redirect unsuspecting visitors to scams and malware.
The practice, dubbed dropcatch domain acquisition, involves snapping up domains the moment they become available for re-registration after their original owners let them expire. During the first half of 2026, approximately 50,400 dropcatch domains were re-registered daily in generic top-level domains like .com alone. When country code top level domains are factored in, that figure climbs to roughly 65,000 per day, accounting for nearly 20 percent of all daily domain registrations.
How Inherited Reputation Becomes a Weapon
Expired domains carry valuable assets from their previous lives: cached search engine results, lingering inbound links, residual web traffic, and sometimes even pre-existing DNS records. Security products and reputation algorithms often treat these aged domains more favorably than freshly registered ones. Threat actors exploit this trust transfer to bypass initial security filters.
One threat actor tracked under the name Sable Squirrel has reportedly spent nearly $7 million acquiring expired domains to build a criminal network spanning illegal sports streaming, online gambling promotion, and malware infrastructure. Evidence traced the operation to Vietnam, with strong overlaps to the Xoi Lac TV illegal streaming network that was dismantled by Vietnamese authorities in March 2026.
The top level domains most targeted for dropcatch activity include .net, .xyz, .com, .org, .vip, .online, .store, .site, .app, and .shop. Major registrars facilitating these re-registrations include GoDaddy, Namecheap, and DropCatch.com, each processing thousands of dropcatch domains daily.
DeadLock Ransomware: Rust-Based Encryption Meets Decentralized Infrastructure
While expired domains represent a clever entry point for malware delivery, the encryption end of the pipeline has also evolved dramatically. Microsoft Threat Intelligence recently published a detailed analysis of DeadLock ransomware, an emerging operation that combines Rust-based encryption with decentralized recovery infrastructure using the Session messaging network and blockchain-backed services.
First observed in July 2025, DeadLock employs double extortion tactics: encrypting victim environments while threatening to publicly release exfiltrated data. As of July 2026, the operators have published more than 80 compromised organizations on their data leak site, with over half of the claimed victims based in Europe. Impacted sectors include information technology, mining, transportation and logistics, manufacturing, hospitality, and consumer goods across Europe, Asia, North America, South America, and Africa.
Technical Sophistication Sets DeadLock Apart
Several design choices make DeadLock particularly notable:
- Rust-based encryptor: Written in Rust, the malware benefits from memory safety and makes reverse engineering more difficult for analysts.
- Resource-aware throttling: The encryptor includes a mechanism to maintain system responsiveness during encryption, avoiding detection by performance monitoring tools.
- Geofencing: DeadLock implements language and country-based geofencing to avoid executing in environments associated with former Soviet and Commonwealth of Independent States countries, a pattern commonly seen among ransomware operators believed to operate from those regions.
- Decentralized recovery infrastructure: The operators use the Session messaging network combined with blockchain-backed services for victim communications and data leak operations, making disruption efforts significantly harder for law enforcement.
- Multi-group deployment: Microsoft has observed DeadLock being deployed by multiple groups, including affiliates of the Lynx and INC ransomware ecosystems.
Ransomware Escalation Across Critical Infrastructure
Theexpired domain and DeadLock stories are not isolated incidents. Ransomware attacks surged 16 percent in July 2026 alone, according to recent industry reports. The attacks are growing bolder and more disruptive, targeting critical infrastructure with increasing frequency.
In Canada, a ransomware attack recently disrupted hospital operations, affecting doors, elevators, ventilation, and air conditioning systems. The incident highlighted the physical safety implications of cyberattacks on healthcare facilities, where compromised building management systems can directly endanger patient lives.
Meanwhile, the United States and South Korea issued a joint warning about the growing Gunra ransomware threat, signaling international concern about the expansion of ransomware operations across borders. A threat group also claimed credit for a ransomware attack on Coca-Cola’s dairy unit, demonstrating that no industry is immune.
The 2026 Malware Playbook: Convergence and Innovation
What makes 2026 distinct in the malware landscape is the convergence of multiple sophisticated techniques into cohesive criminal operations. Threat actors are no longer relying on single vectors. Instead, they are building end-to-end pipelines that combine:
- Trust exploitation via expired domains with inherited reputation
- Advanced encryption using memory-safe languages like Rust
- Decentralized infrastructure powered by blockchain and encrypted messaging
- Geofencing to avoid triggering scrutiny in certain regions
- Double extortion combining encryption with data leak threats
This convergence means that traditional security measures, which often rely on domain reputation scores or signature-based detection, are increasingly insufficient. Organizations must adopt multi-layered defense strategies that account for the full attack chain.
Defensive Recommendations for Organizations
Given the evolving threat landscape, cybersecurity experts recommend the following measures:
Domain and DNS Security
- Monitor for typosquatting and expired domain registrations that mimic your brand
- Implement DNS filtering to block traffic to known malicious domains
- Use Domain-based Message Authentication Reporting and Conformance (DMARC) to prevent email spoofing via inherited domain reputation
- Consider defensive domain registration to prevent threat actors from acquiring your expired domains
Ransomware Prevention
- Maintain offline, encrypted backups tested regularly for recovery integrity
- Deploy endpoint detection and response solutions capable of identifying Rust-based malware
- Implement network segmentation to limit lateral movement during an attack
- Enforce multi-factor authentication across all remote access points
- Conduct regular ransomware tabletop exercises involving both IT and physical operations teams
- Monitor for credential theft, which remains the primary initial access vector for ransomware operators
Healthcare and Critical Infrastructure
- Segregate building management systems from corporate networks
- Implement fail-safe mechanisms for physical access and life safety systems that do not depend on network availability
- Develop incident response plans that account for operational technology disruptions, not just data loss
Looking Ahead
The malware landscape of 2026 demonstrates that cybercriminals are investing heavily in infrastructure and innovation. The $7 million spent by a single threat actor on expired domains illustrates the scale and profitability of these operations. The emergence of DeadLock ransomware with its decentralized, blockchain-backed infrastructure shows that attackers are learning from law enforcement disruptions and building more resilient criminal platforms.
For defenders, the message is clear: reactive security is no longer enough. Organizations must proactively monitor the domain ecosystem, harden their infrastructure against sophisticated encryption threats, and prepare for scenarios where both data and physical operations are simultaneously at risk. The cost of prevention remains a fraction of the cost of a successful attack, and in an era where hospital doors and elevator systems can be disabled by malware, the stakes have never been higher.
Edited by Palawan @QUE.COM
Website: https://QUE.COM Intelligence
Sponsored by: https://MAJ.COM AI Autonomous
Discover more from QUE.com
Subscribe to get the latest posts sent to your email.
