ThreatBeaconXThreatBeaconXSubscribe
HighMalware · 5 min read · 27 views

Hackers Spend Nearly $7 Million on Expired Domains to Spread Scams and Malware

Threat actors are increasingly acquiring expired domains to inherit their previous reputation, backlinks, search visibility, and residual traffic. Infoblox identified a major operation called Sable Squirrel that has spent nearly $7 million acquiring more than 10,000 expired domains for sports piracy, gambling promotion, traffic distribution, and malware infrastructure.

Written by ThreatBeaconX Research Team·Published Aug 15, 2026

Threat actors are increasingly purchasing expired or dropped domains to take advantage of their existing reputation, backlinks, search visibility and residual website traffic.

According to research from Infoblox, threat actors are using these domains to redirect visitors to scams, gambling platforms and malware, while some domains are also being used as command-and-control infrastructure.

The activity highlights a growing threat where attackers do not need to build a domain's reputation from scratch. Instead, they acquire domains that already have a history and immediately repurpose them for malicious operations.

Key Highlights

  • Around 50,400 dropcatch domains were re-registered daily during the first half of 2026 across generic TLDs.
  • Including country-code TLDs, the number increased to approximately 65,000 domains per day.
  • Dropcatch domains account for roughly one in five newly registered domains.
  • Threat actor Sable Squirrel has spent nearly $7 million on expired domains.
  • Sable Squirrel controls more than 10,000 domains.
  • More than 31,000 malware samples have communicated with Sable Squirrel infrastructure.
  • Malware families observed include Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT and njRAT.
  • Some acquired domains simultaneously host legitimate-looking streaming content and malware C2 infrastructure.
  • Other groups tracked as Stuffy Squirrel, Shady Squirrel and Swiping Squirrel also exploit expired domains.

What Are Dropcatch Domains?

A dropcatch domain is an expired domain that becomes available for registration and is quickly acquired by another party.

Organizations may allow domains to expire for legitimate reasons, after which the domain eventually becomes available to new registrants.

Threat actors monitor these domains and attempt to acquire them as soon as they are released.

The security risk comes from the domain's previous reputation and infrastructure history.

An expired domain may still have:

  • Search-engine rankings
  • Backlinks
  • Cached content
  • Existing DNS records
  • Residual website traffic
  • Email traffic
  • Reputation accumulated over years
  • Links from trusted websites

Attackers can inherit these properties after acquiring the domain.

Sable Squirrel Operation

One of the largest operations identified by Infoblox is Sable Squirrel.

The threat actor has reportedly spent nearly $7 million acquiring expired domains and operates more than 10,000 domains.

The infrastructure is primarily associated with a large Asian sports-piracy ecosystem.

The domains are used to promote illegal sports-streaming services and gambling platforms while also supporting malware distribution and C2 operations.

Sports Streaming to Malware Infrastructure

Sable Squirrel operates streaming websites under brands including:

  • Xoilac
  • Cakhia
  • 90phut
  • Socolive
  • MiTom

These websites attract users through sports-streaming content.

The operators then use traffic-distribution systems to selectively redirect users to gambling platforms.

The same infrastructure can also be used for malware operations.

This creates a multi-purpose ecosystem where one domain can simultaneously serve:

Sports Streaming → Traffic Distribution → Gambling → Malware C2

Malware Infrastructure

Infoblox identified more than 31,000 malware samples communicating with Sable Squirrel infrastructure.

Observed malware includes:

  • Quasar RAT
  • AsyncRAT
  • DCRat
  • NanoCore
  • Remcos RAT
  • njRAT
  • HiddenTear-related ransomware artifacts

Some streaming domains have also been observed functioning as malware command-and-control servers while continuing to provide streaming content.

This dual-use infrastructure can make malicious domains more difficult to identify through simple reputation-based detection.

Examples of Acquired Domains

Sable Squirrel has acquired expired domains that previously belonged to legitimate organizations or initiatives.

Examples include:

healthymagination[.]com
maxfactor-international[.]com
krogeralbertsons[.]com
snsystems[.]com
rezilion[.]com
cel-robox[.]com

One notable example is:

cel-robox[.]com

The domain was reportedly repurposed as an illegal streaming site and also used as C2 infrastructure for Quasar RAT.

Why Expired Domains Are Valuable

Security products frequently use domain age and reputation as signals when assessing risk.

A newly registered domain with no history may be considered suspicious.

An older domain with years of legitimate activity, backlinks and historical reputation may receive greater trust.

Threat actors exploit this difference.

By acquiring an established domain, attackers can effectively purchase:

  • Domain age
  • Reputation
  • Existing backlinks
  • Search visibility
  • Residual traffic
  • Historical trust

This allows malicious infrastructure to become operational much faster.

Rapid Weaponization

The research shows that newly acquired domains can be weaponized extremely quickly.

Approximately:

  • 24% became active on the same day they were registered.
  • 76% became active within seven days.
  • 94% became active within two weeks.

This demonstrates that defenders have a very limited window to identify and investigate suspicious changes to previously legitimate domains.

Other Dropcatch Threat Actors

Infoblox identified three additional financially motivated groups:

Stuffy Squirrel

Stuffy Squirrel has been active since at least 2020 and controls more than 500 domains.

The group operates traffic-distribution infrastructure and redirects visitors toward advertising networks, unwanted notifications and other monetization services.

Shady Squirrel

Shady Squirrel has been active since at least July 2023 and controls more than 700 domains.

The group redirects traffic toward:

  • Initial access brokers
  • SocGholish-related infrastructure
  • Technical-support scams
  • Affiliate advertising networks

Swiping Squirrel

Swiping Squirrel has controlled more than 3,000 domains since at least 2022.

The group primarily monetizes acquired traffic by redirecting users toward advertising platforms that may subsequently resell the traffic for scams or malware.

Detection and Hunting Opportunities

Security teams should monitor for:

  • Previously legitimate domains suddenly changing DNS records
  • Expired domains becoming active again
  • Unexpected changes in hosting providers
  • Domain redirects to gambling or suspicious websites
  • Domains suddenly hosting malware C2 infrastructure
  • New TLS certificates on previously inactive domains
  • Sudden changes in DNS nameservers
  • Large increases in traffic to previously dormant domains
  • Previously trusted domains serving JavaScript redirects
  • Traffic-distribution-system behavior
  • Connections to known Sable Squirrel infrastructure
  • Malware communicating with domains that previously hosted legitimate content

Recommended Mitigations

  1. Monitor important organizational domains for unauthorized DNS changes.
  2. Maintain an inventory of domains previously owned by the organization.
  3. Prevent accidental domain expiration through centralized renewal management.
  4. Monitor abandoned or expired third-party domains referenced by corporate systems.
  5. Do not rely solely on domain age or reputation for URL trust decisions.
  6. Analyze DNS history and hosting changes when investigating suspicious domains.
  7. Monitor traffic redirections from trusted domains.
  8. Block known malicious C2 infrastructure.
  9. Use behavioral DNS analytics to identify suspicious domain changes.
  10. Monitor newly registered certificates and nameserver changes.
  11. Correlate DNS intelligence with endpoint and network telemetry.
  12. Investigate dormant domains that suddenly begin hosting active content.

Threat Assessment

The abuse of expired domains represents a significant challenge for traditional reputation-based security controls.

Threat actors can inherit years of reputation and residual traffic without compromising the original organization.

The Sable Squirrel operation demonstrates how this technique can scale into a large criminal ecosystem supporting traffic monetization, gambling, piracy and malware distribution.

The presence of RAT families communicating with domains that still appear to host legitimate content makes infrastructure-based detection particularly challenging.

Conclusion

Expired-domain abuse is becoming an important component of modern cybercrime infrastructure.

Security teams should treat changes in domain ownership, DNS configuration, hosting providers and website behavior as important threat signals.

Organizations should also avoid assuming that an old or previously trusted domain is inherently safe. Domain reputation can change hands, and attackers can rapidly transform legitimate-looking infrastructure into a platform for scams and malware.

Indicators of Compromise

TypeValueNotes
Domainhealthymagination[.]com
Domainmaxfactor-international[.]com
Domainkrogeralbertsons[.]com
Domainsnsystems[.]com
Domainrezilion[.]com
Domaincel-robox[.]com
Domain6789x[.]site

MITRE ATT&CK Mapping

T1583.001 — Acquire Infrastructure: DomainsT1189 — Drive-by CompromiseT1102 — Web ServiceT1071.001 — Web Protocols