Inherited Trust as an Attack Tool

Cybercriminals Spend Nearly $7 Million on Expired Domains

expired domains, dropcatch domains, domain hijacking, cybercrime, how cybercriminals exploit expired domains, expired domains used for cyber attacks, Compromised Domains
Facebook
X
LinkedIn
Reddit
WhatsApp

Infoblox has uncovered how cybercriminals are spending around $7 million to acquire expired domains, along with their reputation and residual traffic.

DNS security company Infoblox refers to domains whose registrations expire and are subsequently registered by another party as dropcatch domains. During the first half of 2026, around 50,400 such domains were newly registered every day across generic top-level domains such as .com. Including country code top-level domains, the figure rises to approximately 65,000 per day, meaning that nearly one in five newly registered domains worldwide falls into this category. Infoblox explains:

Ad

“These domains can be particularly interesting, even dangerous, because they inherit reputation and sometimes connections from their previous life.”

Infoblox

Ad

Security products and reputation-based algorithms often rate these domains more favorably than genuinely new registrations. Attackers deliberately exploit this advantage. Looking at individual TLDs, Infoblox’s analysis shows .net and .xyz leading dropcatch activity, followed by .com in third place.

Most of these domains are re-registered through registrars such as GoDaddy and Namecheap, as well as specialized services such as DropCatch.com. These services specifically track domains approaching final deletion and automatically attempt to register them on behalf of paying customers. When several parties compete for the same domain, a public auction determines the winner.

Former Brand Domains Turned Into Streaming and Betting Portals

According to Infoblox, the threat actor it calls “Sable Squirrel” has built a criminal business model around illegal sports streaming, online gambling advertising and malware infrastructure by acquiring such domains. Infoblox traces the group to Vietnam, with significant overlaps with the illegal streaming network Xoi Lac TV, which Vietnamese authorities dismantled in March. The group is believed to control more than 10,000 domains. Most serve as the foundation for a large-scale Asian sports piracy operation operating under brands including Xoilac, Cakhia, 90phut, Socolive and MiTom. Users are simultaneously redirected to betting operators.

Among the previously known domains acquired by the group are, according to Infoblox, a former healthcare initiative operated by General Electric, a former domain belonging to cosmetics brand Max Factor, and a domain registered for the ultimately failed merger between supermarket chains Kroger and Albertsons. A domain formerly belonging to a developer tools provider for PlayStation is now being used both as an illegal streaming site and as a command-and-control server for the Quasar RAT malware, according to Infoblox. The case illustrates how the same infrastructure can serve multiple purposes.

Overall, at least 31,000 different malware samples have communicated with the group’s infrastructure, Infoblox reports. These include established malware families such as Quasar RAT, AsyncRAT, DCRat and Remcos RAT. The attackers also put acquired domains to use remarkably quickly after re-registration. According to Infoblox, 24 percent become active on the same day, 76 percent within a week and 94 percent within two weeks.

Opportunistic Actors Also Exploit Compromised Domains

In addition to groups such as Sable Squirrel that deliberately acquire domains to support their own criminal business models, Infoblox has identified several financially motivated actors that specifically take over previously compromised, expired domains to resell the traffic they generate. These include “Stuffy Squirrel,” active since at least 2020 and controlling more than 500 domains; “Shady Squirrel,” a Russian-speaking group active since July 2023 and controlling more than 700 domains; and “Swiping Squirrel,” active since 2022 and controlling more than 3,000 domains.

Infoblox describes their approach as follows:

“Rather than compromising websites themselves, these actors acquire expired domains and immediately begin receiving traffic from infection chains left behind by their predecessors.”

Infoblox

(Editorial Team)

Ad

Weitere Artikel