Phishing-as-a-service operators are systematically acquiring aged, expired domains with years of clean certificate history to bypass enterprise email filters that rely heavily on domain age as a trust signal. A detailed case study of a Sneaky2FA deployment shows how a nine-year-old scrapbooking blog domain was drop-caught and repurposed for credential theft against US government targets. The key detection signals — a certificate authority change after years of stable issuance, a multi-month cert gap, and sudden appearance of anomalous subdomains — are not tracked by most age-weighted reputation classifiers. Recommended mitigations include monitoring certificate transparency logs for hosting-pattern instability and subdomain wordlist anomalies, and deprioritizing domain age as a primary trust signal.

7m read timeFrom csoonline.com
Post cover image
Table of contents
How age-weighted reputation became the blind spotWhat aged-domain acquisition actually looks like
158 Impressions