The criminal afterlife of expired domains
Infoblox Threat Intel has highlighted the threat from dropcatching - the automated reregistration of Internet domains once they expire. The organisation has observed approximately 65,000 such reregistered domains daily during 1H26, and said that dropcatch domains represent nearly 20% of all newly-observed domains each day.
Threat actors prize the legitimate domains as they inherit trust, backlinks and web traffic from the former owner, Indoblox said. There is a thriving market for known malicious domains as well.
One Infoblox investigation uncovered a threat actor dubbed Sable Squirrel, who researchers estimate has invested more than US$7 million acquiring over 10,000 expired domains. Those domains underpin a criminal ecosystem spanning illegal streaming, online gambling and malware distribution. Notably, Sable Squirrel operates command-and-control (C2) nodes for multiple remote access trojans (RATs) on the same infrastructure as illegal content.
Other threat actors have taken over well-known malicious domains that were inserted into compromised websites. Across three additional newly-identified threat actors, Infoblox Threat Intel found thousands of dropcatch domains embedded in tens of thousands of compromised websites that continue directing victims to various malicious payloads.
One threat actor, tracked as Shady Squirrel by Infoblox Threat Intel, delivers potential victims to SocGholish, the “fake update” infrastructure which was the target of Operation Endgame in June 2026. This threat actor sent malware through scareware and call centres before partnering up with SocGholish’s operator TA569 in July.
“The sheer volume of dropcatch domains is astounding. We’ve known that bad guys buy expired domains to repurpose them, but the way in which they were used, and the amount of money actors are willing to spend wasn’t well understood,” said Dr RenĂ©e Burton, VP of Infoblox Threat Intel.
"Expired domains can be a shortcut to both trust and traffic, making dropcatch domains a higher risk than the average newly-registered domain.”
The research is detailed in a three-part series:
Part 1: Explains how dropcatch domains retain trust, reputation and traffic after expiring, creating opportunities for abuse.
Part 2: Details the Sable Squirrel investigation, uncovering a criminal operation that invested more than US$7 million in expired domains to support illegal streaming, gambling and malware.
Part 3: Profiles Stuffy Squirrel, Shady Squirrel and Swiping Squirrel, threat actors that acquire expired malicious domains to inherit victim traffic from previously-compromised websites, redirecting users to scams, malware and advertising fraud.
Comments
Post a Comment