Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale.
DNS threat intelligence firm Infoblox has given the name dropcatch domains to those that get a second chance, where an expired domain becomes available for registration and is then snapped up by another party.
During the first half of 2026, 50,400 dropcatch domains were re-registered each day in the generic top-level domains (gTLDs) like ".com" alone, a figure that jumps to around 65,000 when country code top-level domains (ccTLDs) are taken into consideration. These account for nearly 20$ of all daily gTLD and ccTLD registrations, meaning one out of five newly registered domains is a dropcatch domain.
"These domains can be particularly interesting, even dangerous, because they inherit reputation and sometimes connections from their previous life," Infoblox said in an exhaustive three-part report shared with The Hacker News. "Researchers, security products, and reputation-based algorithms may view it more favorably than a genuinely brand-new registration. Threat actors know this and take advantage of it."
The cybersecurity company's analysis shows that .net and .xyz lead when it comes to dropcatch activity at the TLD level, surpassing .com, which comes in at the third spot. Other prominent TLDs include .org, .vip, .online, .store, .site, .app, and .shop. Most of these domains are re-registered via registrars like GoDaddy, Namecheap, and DropCatch.com, with each accounting for 5,246, 4,385, and 3,568 median daily dropcatch domains.
One aspect worth highlighting is that while the reasons why a domain expires may vary, most gTLDs adhere to a registration recovery policy that gives existing registrants an opportunity to renew the expired domain within a specific timeframe. And when this grace period elapses, the domain gets released and is once again available for registration.
This is where custom drop catching services like DropCatch.com come into play, as they track domains that are approaching deletion from the registry and automatically attempt to register them as soon as possible on behalf of customers who place a backorder to secure them. Should multiple parties express interest, and there exists more than one backorder for the same domain, they go into a public auction where the individual or party with the highest bid wins the domain.
"Every day 60,000 - 85,000 .com and .net domain names become available on the 'Daily Drop,'" DropCatch.com notes on its website. "The Drop is an extremely competitive market where advanced computer algorithms have a remarkable advantage by detecting the precise millisecond a domain name becomes available for registration and issuing hundreds of consecutive purchase attempts at once."
In some cases, these auctions can take place much before the domains are released to the registry pool, giving users a way to browse a list of domains approaching expiration, view current bids, and flag those that have garnered interest. This naturally raises a question: who is catching them?
Squirrels and Scavengers: When Trust Transfer Becomes a Security Issue
While defenders deliberately tend to catch such expired domains as a precautionary measure to combat future misuse, domain investors can also engage in the practice of buying, holding, and reselling internet domain names for a profit. However, this drop catching can pose a severe concern when a bad actor obtains control of a domain with a history.
"For threat actors specifically, the inherited reputation isn't the only thing valuable about acquiring a dropped domain," Infoblox explained. "They also come with a variety of lingering connections: email intended for the original domain holder, cached search results, inherited web traffic, and in some cases, a ready-made platform for code injection on already compromised sites. Lingering DNS records can also create opportunities for threat actors."
![]() |
| gTLDs ordered by dropcatch rate |
One such threat actor is Sable Squirrel, which is assessed to have spent nearly $7 million so far on expired domains to build a criminal enterprise spanning illegal sports streaming, online gambling promotion, and malware infrastructure.
"That money buys aged registration history, backlinks, residual traffic, and the kind of reputation signals many defenses still treat as indications of trustworthiness," the threat intelligence firm added. Evidence points to Vietnam being the epicenter of the operation, sharing strong overlaps with Xoi Lac TV, an illegal streaming network that was dismantled by Vietnamese authorities earlier this March.
In all, the threat actor hoards (hence the squirrel moniker) more than 10,000 domains, most of which act as a backbone for a large Asian sports piracy operation under brands such as Xoilac, Cakhia, 90phut, Socolive, and MiTom. According to Infoblox, these platforms act as acquisition channels to keep "fans returning" while using them to promote betting services like VSBet, ColaScore, and 8xbet Sable Squirrel operates in tandem.
The scheme essentially involves promoting the brands through Facebook, Instagram, Reddit, Twitch, Amazon Podcasts, self-owned YouTube channels, and ads on compromised job-posting and community sites to selectively redirect users located in Vietnam, South Korea, Japan, Taiwan, Singapore, and Australia to the illicit sports streaming sites via a traffic distribution system (TDS).
Saber Squirrel has also been found to publish Android apps for ColaScore and VSBet on the Google Play Store and through developer accounts that are suspected to be compromised. "This is not a one-off, we have found many variations of these compromised Play accounts distributing the same apps, and when Google suspends one, another appears to take its place," Infoblox said.
![]() |
| Sable Squirrel operation |
No less than 31,000 malware samples, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT, and artifacts bearing HiddenTear ransomware signatures, have communicated with Sable Squirrel's infrastructure. A subset of the streaming domains also function as malware command-and-control (C2), even as they continue to present live streaming content to visitors.
The Xoi Lac TV brand emerged in 2016, but it wasn't until November 2025 when the first malware C2 configurations appeared on Sable Squirrel domains that had already been serving streaming content, signaling a shift beyond illegal streaming and gambling. The threat actor is believed to have begun purchasing dropcatch domains as early as June 2023.
Interestingly, Sable Squirrel operates what has been described as a two-track domain model, one that involves buying expired domains at auctions through DropCatch[.]com, GoDaddy, Namecheap, and Dynabot to inherit the legitimacy of their predecessors, along with their registration history, inbound traffic, and backlinks, and freshly registered lookalikes that are used to run the streaming fleet.
Some of the dropcatch domains acquired by Sable Squirrel for illegal sports-streaming are listed below -
- healthymagination[.]com, a health initiative launched by General Electric in 2009
- maxfactor-international[.]com, a cosmetics brand owned by Procter & Gamble
- krogeralbertsons[.]com, a domain created for the proposed Kroger and Albertsons merger in 2022 before the deal was terminated in December 2024
- snsystems[.]com, a former Sony PlayStation developer tools company
- rezilion[.]com, a now-defunct cybersecurity company whose core assets were purchased by GitLab in 2024
- cel-robox[.]com, a former desktop 3D printer company
For instance, the "cel-robox[.]com" domain has been found to be purchased by Saber Squirrel to run it as an illegal streaming site as well as a C2 server for Quasar RAT, highlighting the dual-purpose nature of the infrastructure. Some of the prominent sectors that have been found reaching to malware C2 domains consist of education, IT and consulting, government, healthcare, and banking.
![]() |
| The three Scavengers |
Once re-registered, the dropcatch domains are swiftly weaponized for malicious activities, with 24% going live the same day, 76% by seven days, and 94% by the end of two weeks, indicating the threat actor's efforts to capitalize on the domains' reputation and inbound traffic to accomplish their goals.
While the end goal of the operation is to funnel sports fans to gambling sites, it does so through a redirection and cloaking chain using domains like "6789x[.]site," which is responsible for routing real viewers to the betting platforms while sending bots and anyone who is not the intended target to dead ends so that the betting page stays hidden.
"Sable Squirrel buys reputation by the domain, wires it into a streaming-to-gambling machine, and leverages a share of the same domains as malware infrastructure," Infoblox noted. "Sable Squirrel is not just buying a name. It is buying a head start, with residual trust, traffic, and backlinks that let the domain go to work almost immediately and evade security checks that lean too heavily on historical reputation."
"The same back-end services, sports data feeds, image infrastructure, and live chat components that power the Vietnamese streaming fleet also surface around Chinese-language betting brands and adjacent campaigns aimed at Indonesian and Russian-speaking audiences."
Abusing Expired, Compromised Domains
Sable Squirrel is just one of the many threat actors that acquire expired domains "wholesale" to run a streaming-to-gambling business and a malware operation simultaneously, effectively unlocking multiple revenue streams in the process. Others are opportunistic scavengers that hijack residual traffic from expired, previously compromised domains to power scam and malware ecosystems.
Infoblox is tracking three financially motivated scavengers, who control thousands of domains and fraudulently acquire the traffic and resell it to other services -
- Stuffy Squirrel (Active since at least 2020; controls over 500 domains), which operates a TDS and serves malicious JavaScript to site visitors to sell traffic to affiliate advertising networks that may serve popunder ads and unwanted push notifications, while serving legitimate decoy libraries such as Raphaël.js to scanners probing the dropcatch domain directly.
- Shady Squirrel (Active since at least July 2023; controls over 700 domains), a Russian-speaking threat actor that sends traffic to initial access brokers and cybercriminals like SocGholish and to tech support scams as well as affiliate marketing networks using Keitaro servers. SocGholish is believed to have regained access to thousands of compromised sites by teaming up with the threat actor merely days after its infrastructure was disrupted in a law enforcement operation.
- Swiping Squirrel (Active since at least 2022; controls over 3,000 domains), which sends their fraudulent traffic to zero click advertising platforms, who then resell it for scams or malware, while not engaging in malicious content distribution themselves.
"Instead of compromising websites themselves, these actors acquire expired domains and immediately begin receiving traffic from the infection chains their predecessors left behind," Infoblox said. "Then they inject their own content. They are, in effect, scavengers."
"The result is a race to acquire victims: the same compromised domain may be redirected by different dropcatch actors depending on website visitor characteristics, timing, and other factors."






