The number of malicious dormant domains is increasing and, as researchers warn, approximately 22.3% of domains that are quite old pose some form of risk.

See also: iCloud+: Custom email domain feature available in beta (how to use it)
As revealed, the malicious actors who attacked SolarWinds relied on domains that had been registered years before their malicious activities began.
Based on this, efforts have been accelerated to identify old domains before they have the opportunity to launch attacks and support malicious activities.
A report from Palo Alto Networks' Unit42 reveals the findings of its researchers, after examining tens of thousands of domains daily throughout September 2021.
They concluded that about 3.8% are directly malicious, 19% are suspicious, and 2% are unsafe for work environments.
The goal behind registering a domain long before malicious actors use it is to create a “clean record” that will prevent security detection systems from undermining the success of malicious campaigns.
Typically, recently registered domains are more likely to be malicious, so security solutions treat them as suspicious and are more likely to flag them.
See also: LockBit ransomware: Encrypts Windows domains using group policies
However, Unit42 explains in its report that older domains are three times more likely to be malicious than newer ones.
In some cases, they remained dormant for two years before DNS traffic suddenly increased by 165 times, indicating the start of an attack.

An obvious sign of a malicious domain is a sudden increase in its traffic. Legitimate services that registered their domains and launched their services months or years later, show a gradual increase in traffic.
Domains that were not intended for legal use generally have incomplete, cloned, or generally questionable content.
Another clear sign of an old domain intended to be used in malicious campaigns is the creation of DGA subdomains.
DGA (Domain Generation Algorithm) is an established method of generating unique domain names and IP addresses that act as new C2 points of contact. The goal is to evade detection and blacklists.
Looking at the DGA component alone, Palo Alto's detectors detected two suspicious domains each day, which created hundreds of thousands of subdomains on the day they were activated.
See also: USA: Domains used by APT29 in recent phishing campaign seized
In most cases, old domains are used by sophisticated hackers who operate in a more organized context and have long-term plans.
They are used to abuse DGA to infiltrate data via DNS traffic, operate proxy layers, or impersonate well-known brand domains (cybersquatting).
Although detecting DGA activity is still difficult, security researchers can achieve a lot by monitoring DNS data such as queries, responses, and IP addresses and focusing on identifying patterns.
