Researchers detail a spam campaign using 21K hijacked abandoned domains and subdomains from brands like eBay, MSN, and VMware to send ~5M malicious emails daily
A massive ad fraud campaign named “SubdoMailing” is using over 8,000 legitimate internet domains and 13,000 subdomains to send …
Context & Ripple Effects
SubdoMailing extends a long-running pattern in which abuse operations exploit weakly governed internet infrastructure. Earlier reporting tied widely received spam campaigns to a previously documented GoDaddy weakness, while research on new cybersquatted names found many were used for malicious distribution.
What distinguishes this case is the reported scale of abandoned, legitimate-looking domains and subdomains. That gives a spam and ad-fraud operation brand-adjacent sending infrastructure rather than relying solely on newly registered lookalikes.
First-order effects
- Operators of the affected domains and subdomains face an immediate need to identify stale DNS, mail, and delegation settings that can be commandeered for malicious sending.
- Email recipients and mailbox providers must contend with roughly five million additional malicious messages per day delivered through infrastructure that may appear more established than newly created spam domains.
Second-order effects
- Brand owners and hosting or DNS providers are likely to tighten offboarding and monitoring of dormant web properties, since abandoned assets can become an abuse channel after active use ends.
- Email-security systems will need to weigh domain history and subdomain control more carefully; reputation signals based on a recognizable parent brand become less reliable when unused assets are hijacked.
Third-order effects
- If campaigns continue to source sending capacity from neglected legitimate infrastructure, domain-lifecycle hygiene becomes a security control alongside conventional phishing and spam filtering.
- The pattern points to fraud operations shifting from disposable domains toward overlooked assets with inherited trust—a structural advantage that defenders can reduce, but not eliminate, through ownership and delegation controls.
The trend: Abuse campaigns are increasingly monetizing gaps in the lifecycle management of legitimate digital infrastructure, not just registering new malicious domains.