A new investigation by Infoblox threat researchers reveals that parked domains, once considered harmless placeholders filled with ads, have evolved into a significant cyber threat.
The study found that more than 90% of visits to parked domains now lead users to scams, malware, or phishing pages, marking a dramatic shift from a decade ago, when malicious content was detected on fewer than 5% of such sites.
From passive ads to active threats
Parked domains are inactive sites that owners monetize by displaying ads until they’re sold or repurposed. In recent years, however, the monetization model known as direct search, or zero-click parking, has made the system ripe for abuse.
Instead of serving static ads, these domains now redirect users through multiple layers of traffic distribution systems (TDSs), in which advertisers bid for incoming traffic.
Infoblox researchers found that real visitors, especially those on residential networks, are typically redirected through a complex chain of advertising and affiliate networks that profile the user before serving malicious pages.
Automated website scanners, by contrast, detect only benign parking content. This technique, known as cloaking, makes detection extremely difficult for defenders and reputation systems.
In one example, a researcher trying to access the FBI’s Internet Crime Complaint Center accidentally typed ic3[.]org instead of the official ic3[.]gov. The result was an immediate redirect to a fraudulent subscription scam, invisible to scanners or VPN-based crawlers.
Typosquatting, DNS abuse, and evasion tactics
The first, operating domains via torresdns[.]com, controls nearly 3,000 lookalike domains, including scotaibank[.]com (a Scotiabank impersonation) and gmai[.]com (a Gmail typo).
These domains fingerprint visiting devices, collect detailed information such as user agent, hardware details, and network characteristics, and then redirect visitors through advertising networks like Zeropark, Trillion Direct Search, ExplorAds, and AdventureFeeds.

Users are ultimately led to scams, fake captchas, or malware like Tedy, which Infoblox traced to payloads hosted on Mega.nz.
The second actor, controlling ic3[.]org maintains an extensive portfolio of over 80,000 domains and employs a rarely observed “double fast flux” DNS configuration.
By frequently rotating both name servers and IP addresses, this technique makes domains highly resilient to blocklisting or takedown efforts.
The actor targets major brands such as Netflix, YouTube, and Google, serving different content depending on whether the request originates from a real user or a scanning engine.
The third actor runs domaincntrol[.]com, a near-clone of GoDaddy’s official DNS domain domaincontrol[.]com. Thousands of websites inadvertently send traffic to this lookalike domain due to typos or misconfigured DNS records.
Infoblox discovered that this actor fingerprints all incoming visitors and delivers malware through deceptive pages, including a recent ClickFix campaign that distributed Babar malware.
In mid-2025, the actor began answering DNS queries exclusively from Cloudflare’s 1.1.1.1 resolver, effectively singling out users of Cloudflare’s secure DNS service, one of the most widely used globally.
A growing challenge for defenders
Even reputable parking and ad platforms are caught in the middle of this abuse. While companies such as Zeropark and Team Internet AG conduct rigorous “Know Your Customer” checks, the threat often arises downstream, as traffic is resold through affiliate networks where accountability breaks down.
The redirection layers effectively shield malicious advertisers from being identified. Ironically, Google’s March 2025 advertising policy change may have worsened the problem.
After requiring advertisers to opt in to parking traffic explicitly, many domain portfolio owners turned to direct search systems to maintain profitability, unknowingly driving end users deeper into a web of scams and malware.
Infoblox researchers warn that the parked-domain ecosystem is now deeply entwined with the global malvertising supply chain, blurring the line between legitimate ad networks and criminal abuse.
They call for greater transparency, stronger oversight of domain sales, and better cross-platform cooperation between parking providers and threat intelligence teams.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates