Ownerless web domains rigged to redirect visitors to dangerous addresses

(Image credit: Shutterstock / ProStockStudio)

Fraudsters are using lapsed web domains to redirect visitors to dangerous URLs, designed to spread adware and other forms of malicious content.

According to security firm Kaspersky, around 1,000 inactive domains are rigged to redirect users to blacklisted pages, some of which are capable of triggering malware downloads.

Cybercriminals used these thousand domains to route users to over 2,500 unrelated URLs, 89% of which were designed to generate advertising profits (malvertising campaigns) and 11% either contained malicious code or prompted the visitor to download infected documents and executables.

Dangerous web domains

If a company or individual decides not to renew their ownership of a web domain, the URL traditionally redirects visitors to an auction stub notifying them of its availability.

However, in some instances, hackers have found a way to replace the auction stub with a dangerous redirect mechanism. Kaspersky believes scams of this kind are likely made possible by flaws in ad filtering systems.

Researchers found one of the malicious pages identified received an average of 600 redirects every ten days, with hackers likely receiving payment based on the number of visitors funneled to the site.

“Unfortunately, there is little users can do to avoid being redirected to a malicious page. The domains that have these redirects were - at one point - legitimate resources...and there is no way of knowing whether or not they are now transferring visitors to pages that download malware,” explained Dmitry Kondratyev, Junior Malware Analyst at Kaspersky.

“In general, malvertising schemes like these are complex, making them difficult to fully uncover, so your best defense is to have a comprehensive security solution on your device.”

Beyond installing high-quality antivirus software, Kaspersky also noted users can minimize the risk of infection by installing applications and updates from trusted sources only.

TOPICS
Joel Khalili
News and Features Editor

Joel Khalili is the News and Features Editor at TechRadar Pro, covering cybersecurity, data privacy, cloud, AI, blockchain, internet infrastructure, 5G, data storage and computing. He's responsible for curating our news content, as well as commissioning and producing features on the technologies that are transforming the way the world does business.

Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does