Organizations register domains for many reasons, the obvious one being to use as their primary online presence. In many cases organizations also register domains that they might not use but want to prevent others from using. The most prevalent reason is brand reputation protection by registering lookalike domains, including those that contain common typos (typosquatting), use uncommon top-level domains (TLDs) such as .cam or .co instead of .com, and variations on the primary domain such as bitsightratings[dot]com. This is a prudent practice, and Bitsight can help identify domains that might be used by threat actors in our Domain Squatting risk vector.
In many cases the organizations don't intend to use the domains, merely hold them in virtual escrow. The registrars know that and offer a service, called parking, whereby anyone trying to reach the domain, let's say by typing it into a web browser, actually ends up at a page hosted by the registrar. Registrars host thousands of parked domains on any given page, but the content rarely has any association with the domains themselves. Instead, registrars make money from parked domains by hosting ads. The registrant of the domain can also receive some share of the ad revenue.
Are Parked Domains Really a Security Risk?
Many organizations view parked domains as dormant, low-risk, and therefore, not worth the investment in robust security measures. This misconception and the tendency to overlook them can make parked domains an attractive target for cybercriminals, whose motives are:
Credential Stealing
Similar to man-in-the-middle (MITM) attacks, parked domains that don't have the stringent security controls of active domains may be hijacked by threat actors. They can set up lookalike sites to bait visitors who believe they've landed at a legitimate and safe web property owned by your organization into entering usernames and passwords.
Malware Distribution
Instead of, or in addition to, credential stealing, attackers can infect visitors to the lookalike site with viruses, trojans, and other malicious software. In effect the attackers turn your legitimate domain into a watering hole, causing extensive damage to end users and tarnishing the reputation of your organization.
Website Defacement
Again, with control of the parked domain an attacker can redirect web visitors to a site that contains offensive content or otherwise embarrass the legitimate owners of the parked domain.
Phishing Schemes
While the previous nefarious schemes require taking control of the domain itself, either by compromising the system hosting the parked domain or exploiting the chain of ad links, email spoofing is often overlooked by owners of parked domains. This oversight makes it trivial for attackers to use the domain in email return addresses, creating convincing phishing attacks.
| The consequences of exploiting parked domains most often manifests in reputation damage to the legitimate owner of the parked domain. It also erodes trust in users if they become victims of credential theft, malware infections, or successful phishing attacks. |