A security researcher was able to purchase one of the Democratic Republic of Congo's top-level domains, potentially preventing malicious use by attackers
Fredrik Almroth thought the authorities would try to save the critical domain name. Nobody ever did.
Context & Ripple Effects
This is the latest entry in a recurring pattern: critical internet plumbing lapses and someone else claims it. Researchers previously bought an expired .mobi WHOIS server domain for $20, gaining the ability to mint counterfeit HTTPS certificates, and a misconfigured nameserver once handed outsiders all of North Korea's .kp top-level DNS data.
Here the buyer was defensive: Fredrik Almroth acquired one of the Democratic Republic of Congo's top-level domains after concluding no authority would step in — and nobody did. The purchase matters because whoever controls such a domain sits in the path of traffic and email for everything under it, and Cisco Talos has documented state-backed hackers brazenly hijacking domains across several countries' key infrastructure.
First-order effects
- The DRC's exposure closes immediately: with Almroth holding the domain rather than an attacker, phishing pages, malware distribution, and traffic interception under its namespace are off the table for now.
- Congolese authorities face an uncomfortable accounting — a nationally significant internet asset sat unclaimed long enough for an outside researcher to buy it, revealing no functioning custodian.
Second-order effects
- Attackers simply rotate: the same lapse-and-acquire playbook documented against the .mobi WHOIS server and hijacked registrar accounts at Webnic points them toward other poorly stewarded ccTLDs and expiry processes.
- Defensive researchers gain a template — buying lapsed critical domains before criminals do — which puts pressure on registries and registrars to tighten renewal monitoring and reclamation procedures.
Third-order effects
- If the pattern holds, ccTLD stewardship stops being an administrative chore and becomes a national-security function: countries that fail to fund their registry operations effectively outsource control of their namespace to whoever is watching the expiration calendar.
- A gray market forms around expiring critical infrastructure domains, contested between threat actors, bug-bounty-style defensive buyers, and brokers — with no established rules for who may hold a nation's domain and why.
The trend: Expired or mismanaged country-code domain infrastructure is becoming a recurring acquisition target, with defenders and attackers racing to claim namespaces their rightful custodians abandoned.