Infoblox tracks $7 million expired-domain campaign for scams and malware

Infoblox has identified a threat actor dubbed Sable Squirrel that has spent nearly $7 million acquiring expired domains to support illegal sports streaming, gambling promotion and malware infrastructure. The campaign illustrates how a domain can retain useful traffic, backlinks and reputation signals after its former owner allows it to expire.
During the first half of 2026, about 50,400 dropcatch domains were re-registered every day in generic top-level domains alone. Including country-code domains raises the figure to roughly 65,000 daily, or nearly 20% of all daily gTLD and ccTLD registrations. Infoblox uses “dropcatch domains” for names registered again after expiry.
Inherited trust becomes an operational asset
Most generic top-level domains offer a recovery window to the previous registrant. When that period ends, automated drop-catching services can attempt registration at the moment a name is released, often on behalf of customers with backorders. Where several buyers seek the same name, the domain can be sold through a public auction.
Infoblox said .net and .xyz led dropcatch activity at the top-level-domain level, followed by .com. GoDaddy, Namecheap and DropCatch.com were among the registrars handling substantial median daily volumes. For malicious buyers, the value goes beyond a memorable address: expired domains can retain cached search results, residual visitors, intended email, DNS records and, in some cases, a foothold on already compromised sites.
That risk also intersects with trusted-looking domain names in cybercrime because misleading or trusted-looking domain names can give criminal campaigns a more credible starting point while attackers redirect visitors elsewhere.
Sable Squirrel’s two-track domain operation
Infoblox assesses that Sable Squirrel controls more than 10,000 domains, largely supporting an Asian sports-piracy operation using brands including Xoilac, Cakhia, 90phut, Socolive and MiTom. The actor promotes betting services such as VSBet, ColaScore and 8xbet, using a traffic distribution system to selectively route users in Vietnam, South Korea, Japan, Taiwan, Singapore and Australia.
The group reportedly buys expired names through DropCatch.com, GoDaddy, Namecheap and Dynabot, while registering fresh lookalike domains for its streaming fleet. Infoblox cited healthymagination[.]com, maxfactor-international[.]com and cel-robox[.]com among domains obtained by the actor. The latter was used both as an illegal streaming site and as a command-and-control server for Quasar RAT.
More than 31,000 malware samples, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT and artifacts with HiddenTear ransomware signatures, communicated with Sable Squirrel infrastructure. Some streaming domains continued to display live content while also operating as malware command-and-control systems.
Fast weaponization and a broader scavenger economy
Infoblox found that 24% of maliciously repurposed dropcatch domains went live on the day they were registered, 76% within seven days and 94% within two weeks. Sable Squirrel used redirection and cloaking chains to send intended viewers to betting services while directing bots and other visitors to dead ends.
The company also tracks Stuffy Squirrel, Shady Squirrel and Swiping Squirrel, financially motivated actors controlling hundreds or thousands of domains. Their operations acquire residual traffic from expired, previously compromised domains and route it into advertising, scam, malware or initial-access ecosystems.
For businesses, domain-age and historical reputation should not be treated as standalone trust indicators. Security teams should monitor expired domains associated with their brands, inspect redirect behavior and reassess domains that rapidly change ownership, content or DNS configuration.

