Cyber Security News

New Research Reveals 90% of Parked Domains Now Deliver Malware, Scams, and Phishing Attacks

The cybersecurity threat landscape has shifted dramatically, and parked domains have become a primary weapon for delivering malware, scams, and phishing attacks to unsuspecting internet users.

What was once considered a harmless domain monetization practice has transformed into a dangerous attack vector that masks malicious content behind an innocent facade.

Recent research demonstrates that the risks associated with parked domains have grown exponentially over the past decade, fundamentally changing how security professionals must approach domain-based threats.

Parked domains are essentially dormant web addresses without active websites. Traditionally, domain owners monetize these unused properties through parking services that display advertisements to visitors.

A monetization case study from Above.com demonstrates that domain portfolio owners can benefit greatly from using direct search (Source – Infoblox)

However, the introduction of direct search advertising—also known as zero-click parking—has created a sophisticated ecosystem where visitors are automatically redirected based on their device characteristics, location, and browsing behavior.

This feature was designed to deliver relevant content, but has instead become a mechanism for distributing malware and conducting fraud at scale.

A scan of ic3[.]org returned a non-threatening parking page (left) whereas a mobile user was instantly directed to deceptive content (right) (Source – Infoblox)

The attack begins when users inadvertently visit lookalike domains due to simple typos. A researcher attempting to visit the FBI’s Internet Crime Complaint Center accidentally navigated to ic3[.]org instead of ic3[.]gov, only to be redirected to a fake “Drive Subscription Expired” page.

This scenario represents the tip of the iceberg, as threat actors now deliberately register and weaponize thousands of these domains.

Infoblox analysts identified that malicious content now appears in over 90% of visits to parked domains, compared to less than 5% in previous studies conducted over a decade ago.

The technical infrastructure driving these attacks operates through sophisticated visitor profiling mechanisms.

When users land on a parked domain, they encounter lightweight fingerprinting that collects device information, geolocation data, and browser characteristics. This data determines whether the visitor is redirected to a harmless parking page or to malicious content.

Legitimate security scanners and VPN users typically encounter benign pages. In contrast, real users from residential IP addresses are routed through traffic distribution systems operated by advertising networks, resulting in multiple layers of redirection before reaching malicious content.

Device Fingerprinting and Traffic Distribution

The profiling system collects comprehensive device intelligence through JavaScript execution. This includes screen dimensions, pixel ratios, WebGL capabilities, audio features, storage availability, and network connection details.

One affiliate of the ExplorAds advertising platform implemented a sophisticated fingerprinting script containing Russian-language comments that sent base64-encoded device data to its traffic distribution system.

Device fingerprinting by ExplorAds advertising affiliate (Source – Infoblox)

This level of technical sophistication reveals a professionally managed operation rather than random abuse. Three major domain portfolio holders now operate these malicious ecosystems.

One actor controls nearly 3,000 lookalike domains via dedicated name servers, including Gmail.com, a Gmail typosquat that is actively used in phishing campaigns with Trojan malware attachments.

Another uses double fast-flux techniques with rotating name servers, such as koaladns[.]com and quokkadns[.]com.

ClickFix attack hosted on sportswear[.]homes (Source – Infoblox)

A third party owns domaincntrol[.]com, which differs from GoDaddy’s legitimate domaincntrol[.]com by a single letter and targets over 30,000 misconfigured domains.

The convergence of generative AI, expired-domain takeovers, and deliberately registered typosquats has created an ecosystem in which criminals profit from simple user mistakes. At the same time, security teams struggle to attribute and block these threats.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago