Palo Alto Networks' Unit 42 reported that parked domains present elevated security risk and are frequently repurposed for malicious activity, including malware delivery, abusive redirects, and impersonation scams. In an analysis of domain activity between March and September 2020, researchers identified about 5 million newly parked domains and observed 6 million parked domains transition to other categories; 1.0% became malicious, 2.6% shifted to not-safe-for-work content, and 30.6% were classified as suspicious.
The report documented several abuse patterns in which attackers registered parked domains and later weaponized them, while some parking services exposed users to invasive tracking or harmful advertising chains. Case studies included an Emotet campaign using valleymedicalandsurgicalclinic[.]com, exploit-kit and survey redirects tied to peoplesvote[.]uk, and typosquatting abuse through xifinity[.]com, which redirected visitors to a fake McAfee-themed scare page. Unit 42 said organizations should monitor or block parked domains because they can rapidly shift from inactive holdings to active attack infrastructure.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
By September 14, 2020, WildFire captured malware hosted at valleymedicalandsurgicalclinic[.]com/ujftb/statement/wr7hoba7i9hz. Palo Alto Networks linked the domain to a global Emotet phishing campaign targeting multiple sectors and countries.
From March to September 2020, Palo Alto Networks identified 5 million newly parked domains and observed 6 million parked domains transition to other categories. It found that parked domains were far more likely than benign domains to become malicious, suspicious, or not-safe-for-work.
The domain valleymedicalandsurgicalclinic[.]com was registered and was initially classified by Palo Alto Networks as a parked domain based on its website content.
Palo Alto Networks documented abuse of the parked domain peoplesvote[.]uk, where visitors were intermittently redirected from an ad listing page to 0redira[.]com/jr.php and then sometimes to a U.S. election-themed survey site. The activity was attributed to insufficient advertisement control by the parking service above[.]com.
Palo Alto Networks reported that it had been detecting parked domains for more than nine years, establishing the long-term basis for its later analysis of abuse in the domain parking ecosystem.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.