- Kaspersky says empty web pages are watching you, and the research backs up the warning
- Over 90% of parked domains now send visitors somewhere malicious, and clearing your cookies will not help
- Blank pages are also a problem: many ‘Coming Soon’ placeholders are quietly fingerprinting your device
Kaspersky has unveiled a rather underreported attack vector which is increasingly being used by threat actors to harvest private data from unsuspecting victims: registered websites that are yet to be developed.
Its warning focuses on parked domains, the registered web addresses that have no real website behind them yet, arguing that the blank screens and “Coming Soon” placeholders users dismiss as harmless are frequently doing work in the background.
The company says simply loading one of these pages can trigger silent collection of a visitor’s IP address, approximate location, User-Agent string and cookie identifiers, and that operators go further by building browser fingerprints through other techniques, then feeding the result into advertising networks to assemble targeted profiles without consent from users.
Browser fingerprinting sans the permissions
The mechanics Kaspersky describes are worth understanding, because fingerprinting is the part most readers will not have encountered, and the part that conventional privacy habits do not touch.
For context, a cookie is a file placed on your machine that you can delete, thereby limiting tracking. A fingerprint is not stored on your machine at all. It is derived from how your specific hardware and software combination renders a test image, draws 3D graphics, or processes an audio signal, producing a value distinctive enough to identify the same device across unrelated sites.
Browser fingerprinting, the method used to capture such data within a browser session, is attractive to trackers because it is considerably harder to shake off. A private browsing window prevents your machine from keeping a local record of the visit, but it does not change how your hardware renders the test image, so the fingerprint it produces remains largely the same.
Such domains can also cause more direct damage than selling one’s information to advertisers. Kaspersky says threat actors embed scripts that bounce visitors onward to fraudulent platforms, adult content, or online casinos. It flags typosquatting as a particularly acute risk, in which a domain differing from a well-known brand by a letter or two can capture mistyped traffic, landing the user on a phishing page or triggering a drive-by download.
This isn’t the first time the problem has been reported, either, as recent research from Infoblox finding that in large-scale experiments, over 90% of the time, a visitor to a parked domain was routed to illegal content, scams, scareware, antivirus subscription traps, or malware.
Kaspersky recommends several ways to mitigate the risk, including avoiding suspicious links, clearing cache and cookies after an unintended visit, and using software that blocks web tracking.
Clearing cookies is worth noting, though: it addresses the cookie identifiers Kaspersky mentions, but by the company’s own explanation it does nothing about fingerprinting, because there is nothing stored locally to clear.
Parked domains, including blank pages that appear inert, are now a routine part of criminal infrastructure rather than digital litter and should be treated with caution. At best, you give away more information than you meant to. At worst, you become the victim of an attack you never saw coming.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
