Mass domain registration

Summary

Attackers are taking over domains on an industrial scale to enable them to be easily rotated out when burned and added to blocklists. Attackers expect their phishing domains to last for a limited time before they are burned in some capacity — having a steady supply of domains ensures their campaigns can continue.

This can be achieved by:

  • Registering new domains in huge quantities ahead of time.
  • Compromising existing domains through website vulnerabilities.
  • Re-registering expired domains previously belonging to legitimate companies and services.

Examples