$7 Million Spent on Expired Domains for Scam and Malware Redirects

0
7

Key Takeaways

  • Dropcatch domains (expired domains re-registered by others) constitute nearly 20% of all new gTLD and ccTLD registrations daily, with ~50,400 re-registered in gTLDs like ".com" alone each day in H1 2026.
  • Threat actors exploit these domains to inherit reputation, traffic, backlinks, and residual connections (e.g., cached search results, email), bypassing security systems that rely on historical trust signals.
  • The group "Sable Squirrel" has spent approximately $7 million acquiring over 10,000 dropcatch domains to power an illegal Asian sports streaming operation (brands like Xoilac, Cakhia) intertwined with gambling promotion and malware distribution (Quasar RAT, AsyncRAT, etc.).
  • Sable Squirrel uses a dual-track strategy: purchasing expired domains for immediate reputation leverage and registering fresh lookalikes for scalable streaming infrastructure, with 94% of weaponized domains active within two weeks.
  • Three secondary threat actors ("Stuffy Squirrel," "Shady Squirrel," "Swiping Squirrel") function as traffic scavengers, hijacking residual visitors from expired domains to resell access to ad networks, tech support scams, or initial access brokers.
  • Malware command-and-control (C2) infrastructure frequently coexists with legitimate-seeming content (e.g., live sports streams) on the same domains, affecting sectors like healthcare, banking, and government.

The Rise of Dropcatch Domain Abuse in Cybercrime
Threat actors are increasingly leveraging expired domains to inherit established web traffic and reputation for large-scale scams and malware campaigns. DNS threat intelligence firm Infoblox identifies these re-registered domains as "dropcatch domains," which become available after a domain’s registration expires and passes through registry recovery periods. During the first half of 2026, an average of 50,400 dropcatch domains were re-registered daily within generic top-level domains (gTLDs) such as ".com," rising to approximately 65,000 when country code top-level domains (ccTLDs) are included. This volume represents nearly 20% of all new gTLD and ccTLD registrations daily—meaning roughly one in five newly registered domains is a dropcatch domain. Infoblox emphasizes that these domains are "particularly interesting, even dangerous," as they retain signals of trustworthiness from their prior use, making them attractive to security systems and reputation-based defenses that threat actors deliberately exploit.

Mechanics of Domain Expiration and Automated Re-registration
The abuse stems from standard domain lifecycle processes. When a domain expires, most gTLDs follow a registration recovery policy, granting the original owner a grace period to renew. Once this period ends, the domain enters a pending-delete state and becomes available for public re-registration. Services like DropCatch.com automate the "drop catching" process by monitoring domains nearing deletion and instantly attempting to register them the moment they become available, often using algorithms that issue hundreds of registration requests per millisecond to win competitive auctions. DropCatch.com notes that 60,000–85,000 .com and .net domains enter the "Daily Drop" each day, creating a high-speed market where advanced automation gives significant advantages. Registrars such as GoDaddy (median 5,246 daily dropcatch domains), Namecheap (4,385), and DropCatch.com itself (3,568) dominate this space, facilitating the rapid acquisition of expired domains by both legitimate investors and malicious actors.

Why Reputation Inheritance Fuels Malicious Campaigns
The core danger of dropcatch domains lies in the inherited assets they carry beyond just a web address. Infoblox explains that threat actors value not only the "aged registration history" but also "backlinks, residual traffic, and the kind of reputation signals many defenses still treat as indications of trustworthiness." Crucially, these domains may retain lingering connections like emails intended for the previous owner, cached search results from legitimate use, and existing web traffic streams. In some cases, compromised sites leave behind accessible platforms ideal for code injection. This inherited reputation allows malicious domains to bypass security filters that heavily weigh historical trust, enabling near-immediate operation for scams, malware distribution, or phishing—effectively giving attackers a "head start" without the delay of building credibility from scratch for a brand-new domain.

Sable Squirrel: A $7 Million Operation Built on Expired Domains
Infoblox identifies "Sable Squirrel" (noted as a potential typo for "Sable" in the source, but consistently referenced as such) as a financially motivated threat actor that has invested approximately $7 million in acquiring expired domains to construct a vast criminal enterprise. This operation centers on illegal sports streaming across Asia, promoting brands such as Xoilac, Cakhia, 90phut, Socolive, and MiTom to drive traffic toward gambling services like VSBet, ColaScore, and 8xbet. Evidence strongly links the group’s epicenter to Vietnam, overlapping with the dismantled Xoi Lac TV illegal streaming network disrupted by Vietnamese authorities in March 2026. Sable Squirrel controls over 10,000 domains, which serve as the backbone for its streaming platforms. These sites are actively promoted via Facebook, Instagram, Reddit, Twitch, Amazon Podcasts, owned YouTube channels, and ads on compromised job-posting and community sites, specifically targeting users in Vietnam, South Korea, Japan, Taiwan, Singapore, and Australia through a traffic distribution system (TDS) that redirects victims to illicit streams and betting pages.

Weaponized Infrastructure: Streaming, Gambling, and Malware Convergence
Sable Squirrel’s infrastructure demonstrates a sophisticated dual-use model where domains serve both revenue-generating streams and malicious purposes concurrently. The group operates what Infoblox describes as a "two-track domain model": one track involves purchasing expired domains through services like DropCatch.com, GoDaddy, and Namecheap to inherit their predecessors’ legitimacy, traffic, and backlinks; the other track uses freshly registered lookalike domains to scale the streaming fleet. Critically, a significant portion of Sable Squirrel’s domains functions as malware command-and-control (C2) servers. Infoblox reports that no fewer than 31,000 malware samples—including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT, and HiddenTear ransomware variants—have communicated with Sable Squirrel’s infrastructure. Notably, some domains originally serving illegal streaming content (e.g., healthymagination[.]com, once a GE health initiative; maxfactor-international[.]com, a P&G cosmetics brand; krogeralbertsons[.]com, tied to a failed merger; snsystems[.]com, ex-Sony PlayStation tools; rezilion[.]com, a cybersecurity firm acquired by GitLab; and cel-robox[.]com, a former 3D printer company) have been repurposed to host both live streams and C2 malware. For instance, cel-robox[.]com operates as an illegal streaming site while simultaneously serving as a C2 server for Quasar RAT, highlighting how threat actors consolidate resources to maximize efficiency and evade detection.

The Scavenger Ecosystem: Hijacking Residual Traffic for Profit
Beyond Sable Squirrel’s integrated operation, Infoblox tracks three distinct financially motivated threat actors acting as "scavengers" that focus exclusively on hijacking residual traffic from expired, often previously compromised, domains. These actors do not primarily distribute malware themselves but instead monetize the inherited visitors. Stuffy Squirrel (active since at least 2020, controlling 500+ domains) uses a TDS to serve malicious JavaScript that sells traffic to affiliate networks for popunder ads and push notifications, while deploying benign decoy libraries like Raphaël.js to avoid detection by security scanners probing the domain directly. Shady Squirrel (active since July 2023, controlling 700+ domains), a Russian-speaking actor, redirects traffic to initial access brokers and cybercriminal groups like SocGholish (which reportedly regained access to thousands of compromised sites shortly after law enforcement disrupted its infrastructure) and to tech support scams and affiliate networks via Keitaro servers. Swiping Squirrel (active since 2022, controlling 3,000+ domains) sends its fraudulent traffic to zero-click advertising platforms, which then resell the access for scams or malware distribution without engaging in direct malicious content delivery. Infoblox characterizes these groups as operating in a "race to acquire victims," where the same expired domain might be redirected by different actors based on visitor characteristics, timing, or other factors, creating a fragmented but highly efficient market for abused web traffic.

Conclusion: A Systemic Exploitation of Trust in the DNS
The widespread abuse of dropcatch domains represents a significant evolution in cybercriminal tactics, transforming a routine domain lifecycle process into a potent weapon for monetization and evasion. By automating the acquisition of expired domains and exploiting the inherent trust embedded in their historical DNS records, reputation, and traffic streams, threat actors like Sable Squirrel and the scavenger groups bypass traditional security reliance on novelty or obvious malicious indicators. This model enables near-instantaneous deployment of scams, malware C2, and illicit streaming services, turning residual legitimate infrastructure into a foundation for multi-vector criminal enterprises. As Infoblox’s research underscores, the battle against such threats requires moving beyond simplistic domain age or reputation checks toward deeper analysis of real-time behavior, connection patterns, and the specific abuse vectors enabled by inherited digital assets—a challenge made more acute by the sheer scale of daily dropcatch activity, which now constitutes a substantial fraction of the global domain registration ecosystem. The convergence of sports piracy, gambling fraud, and malware on these hijacked domains illustrates how cybercriminals are increasingly innovating not just in their payloads, but in the very foundations of how they establish and maintain malicious operations online.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here