Security researchers have uncovered that the majority of parked domains—websites that are expired, dormant, or typographical variants of popular sites—are now being weaponized to serve malicious content. Instead of merely displaying harmless search advertisements, these domains frequently redirect users to scams, malware, and other deceptive content, especially when accessed directly by users rather than automated scanners or VPNs. The threat is exacerbated by the use of lookalike domains, which can easily trick users into visiting malicious sites, as demonstrated by a case where a user attempting to reach the FBI’s Internet Crime Complaint Center was redirected to a scam page after mistyping the domain.
The research, led by Infoblox and reported by multiple sources, found that over 90% of visits to parked domains now result in exposure to illegal content, scareware, or malware. The complex ecosystem of domain parking and advertising makes it easy for threat actors to hide their activities and difficult for defenders to attribute attacks. Automated security tools often fail to detect these threats because parked domains can serve benign content to scanners while delivering malicious payloads to real users. This shift marks a significant escalation in the risk associated with direct navigation to parked or typo-squatted domains.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Cyber Security News and other outlets further publicized the Infoblox findings, highlighting the scale, professionalism, and growing use of typosquatting, fast-flux DNS, and profiling scripts in parked-domain abuse. This coverage helped frame parked domains as a significant and expanding threat vector.
KrebsOnSecurity summarized the Infoblox study, emphasizing that parked domains increasingly serve malicious content and that some, such as gmai[.]com, may also facilitate business email compromise by accepting misdirected email. The report reinforced that residential users are more likely than VPN users to receive malicious redirects.
On December 16, 2025, Infoblox published its report describing how parked domains have become a large-scale malvertising and scam delivery mechanism. The publication highlighted the role of affiliate traffic-resale networks and the difficulty of attribution and abuse mitigation in the parking ecosystem.
The research identified three major domain portfolio holders tied to weaponized parked-domain activity, including operators using lookalike domains, double fast-flux DNS, and typosquatting on major DNS infrastructure. Examples cited include domains such as scotaibank[.]com, gmai[.]com, ic3[.]org, and domaincntrol[.]com.
Infoblox researchers reported that more than 90% of visits to parked domains now expose users to scams, malware, phishing, or other unwanted content, up sharply from less than 5% about a decade earlier. The study found threat actors use device fingerprinting, residential-IP targeting, DNS-based filtering, and redirection chains to evade detection.
Infoblox's research says recent Google Ads policy changes made ad placement on parked domains opt-in, which appears to have pushed more traffic into riskier direct-search monetization models. The change is described as a factor that increased user exposure to malicious parked-domain traffic.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 36 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceblogs.infoblox.com
Open sourcekrebsonsecurity.com
Open sourceinfoblox.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.