/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers detail a spam campaign using 21K hijacked abandoned domains and subdomains from brands like eBay, MSN, and VMware to send ~5M malicious emails daily

A massive ad fraud campaign named “SubdoMailing” is using over 8,000 legitimate internet domains and 13,000 subdomains to send …

BleepingComputer Bill Toulas

Context & Ripple Effects

SubdoMailing extends a long-running pattern in which abuse operations exploit weakly governed internet infrastructure. Earlier reporting tied widely received spam campaigns to a previously documented GoDaddy weakness, while research on new cybersquatted names found many were used for malicious distribution.

What distinguishes this case is the reported scale of abandoned, legitimate-looking domains and subdomains. That gives a spam and ad-fraud operation brand-adjacent sending infrastructure rather than relying solely on newly registered lookalikes.

First-order effects

  • Operators of the affected domains and subdomains face an immediate need to identify stale DNS, mail, and delegation settings that can be commandeered for malicious sending.
  • Email recipients and mailbox providers must contend with roughly five million additional malicious messages per day delivered through infrastructure that may appear more established than newly created spam domains.

Second-order effects

  • Brand owners and hosting or DNS providers are likely to tighten offboarding and monitoring of dormant web properties, since abandoned assets can become an abuse channel after active use ends.
  • Email-security systems will need to weigh domain history and subdomain control more carefully; reputation signals based on a recognizable parent brand become less reliable when unused assets are hijacked.

Third-order effects

  • If campaigns continue to source sending capacity from neglected legitimate infrastructure, domain-lifecycle hygiene becomes a security control alongside conventional phishing and spam filtering.
  • The pattern points to fraud operations shifting from disposable domains toward overlooked assets with inherited trust—a structural advantage that defenders can reduce, but not eliminate, through ownership and delegation controls.

The trend: Abuse campaigns are increasingly monetizing gaps in the lifecycle management of legitimate digital infrastructure, not just registering new malicious domains.

Discussion

  • @babyboomerwriter.bsky.social BabyBoomerWriter on bluesky
    Shouldn't inspections by bot crawlers (to locate dormant IPs on the site) be included in platform security plans?  Non-operational IP addresses left in place to boost a site's membership count are not benign, they can clearly be weaponized to ensnare innocent people.