Skip to main content
Emerging ThreatsMalware & Ransomware

Hackers Exploit Dropcatch Domains to Redirect Traffic to Scams and Malware

A cluttered computer workstation with a blank laptop screen sits unoccupied in a dimly lit server room with rows of…

“These domains can be particularly interesting, even dangerous, because they inherit reputation and sometimes connections from their previous life,” Infoblox told The Hacker News — and the data behind that sentence is stark: during the first half of 2026 roughly 50,400 expired domains were re-registered each day in gTLDs like .com, and about 65,000 per day when ccTLDs are included, meaning nearly one in five new domain registrations is a re-registration of an expired name.

Infoblox: scope and scale of dropcatch registrations

DNS threat intelligence firm Infoblox calls these re-registrations "dropcatch domains." Its three-part analysis shows that dropcatch activity is concentrated in a set of TLDs: .net and .xyz lead, with .com third, followed by .org, .vip, .online, .store, .site, .app, and .shop. Major registrars dominate the re-registration pipeline — Infoblox reports median daily dropcatch volumes of 5,246 at GoDaddy, 4,385 at Namecheap, and 3,568 at DropCatch.com.

DropCatch.com itself describes the market as hyper-competitive: “Every day 60,000 - 85,000 .com and .net domain names become available on the 'Daily Drop,'” and advanced algorithms attempt registration to the precise millisecond a domain is released. Infoblox documents how registries’ recovery and deletion schedules, combined with backorder and auction services, create predictable windows for capture.

Sable Squirrel: nearly $7 million and more than 10,000 domains

Infoblox attributes a large, organized enterprise to a threat actor it calls Sable Squirrel. According to the analysis, Sable Squirrel has spent nearly $7 million acquiring expired domains, hoards more than 10,000 domains, and uses them to run an integrated criminal business that mixes illegal sports streaming, online gambling promotion, and malware infrastructure.

The operation runs branded streaming fleets — under names such as Xoilac, Cakhia, 90phut, Socolive, and MiTom — that act as acquisition channels to promote betting services including VSBet, ColaScore, and 8xbet. Infoblox links the operation’s center of gravity to Vietnam, noting strong overlaps with Xoi Lac TV, an illegal streaming network dismantled by Vietnamese authorities earlier this March.

Tactics: auctions, traffic distribution, cloaking, and dual use

Infoblox details a two-track domain model attributed to Sable Squirrel: one track acquires aged, dropped domains via DropCatch.com, GoDaddy, Namecheap, and Dynabot to inherit registration history, backlinks, and residual traffic; the other creates fresh lookalikes to run the streaming fleet. The inherited connections — cached search results, inbound traffic, lingering DNS records, and even email flows — are the exact assets Infoblox says threat actors monetize.

Once re-registered, the timeline is rapid: 24% of dropcatch domains go live the same day, 76% within seven days, and 94% within two weeks. The operation uses a traffic distribution system (TDS) and cloaking chains (for example domains such as 6789x[.]site) to route real viewers in target countries — Vietnam, South Korea, Japan, Taiwan, Singapore, and Australia — to betting platforms while diverting bots and non-targets to dead ends.

Infoblox also documents dual-purpose abuse: streaming domains can double as malware command-and-control (C2). No less than 31,000 malware samples — including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT, and artifacts bearing HiddenTear ransomware signatures — have communicated with Sable Squirrel infrastructure. The domain cel-robox[.]com is cited as an example used both for illegal streaming and as a Quasar RAT C2.

Three dropcatch scavengers: Stuffy, Shady, and Swiping Squirrel

Infoblox is tracking at least three other financially motivated dropcatch actors that operate at scale. Stuffy Squirrel (active since at least 2020) controls over 500 domains and runs a TDS serving malicious JavaScript and resale traffic to affiliate advertising networks. Shady Squirrel (active since at least July 2023) controls over 700 domains, is Russian-speaking, and routes traffic to initial access brokers and cybercriminals including SocGholish as well as to tech-support scams and affiliate networks via Keitaro servers. Swiping Squirrel (active since at least 2022) controls over 3,000 domains and funnels fraudulent traffic to “zero click” advertising platforms that resell it for scams or malware.

Infoblox summarizes the behavior succinctly: rather than compromising sites, these actors “acquire expired domains and immediately begin receiving traffic from the infection chains their predecessors left behind,” then inject new malicious content.

What this means for technologists, policymakers, and end users

  • Technologists and security teams: Infoblox’s data underlines that historic reputation is exploitable — defenders should not treat registration age or backlinks as sole trust signals when assessing domains that have changed hands.
  • Policymakers and registries: the existence of pre-release auctions, automated backorders, and high-frequency re-registrations (one in five new domains) highlights how registry policies and marketplace practices can be leveraged at scale by criminal operators.
  • End users and digital platforms: streaming brands, social platforms, and app stores are being used to funnel victims to gambling and malware; Infoblox found Android apps for ColaScore and VSBet published on Google Play through developer accounts that are suspected compromised, with suspended accounts quickly replaced.

Infoblox’s findings map a simple market logic: expired domains bring residual trust, and sophisticated buyers are willing to pay — in Sable Squirrel’s case, millions of dollars — to convert that trust into traffic, revenue, and command infrastructure. The public record in the report is concrete: large volumes of daily re-registrations, named TLD and registrar patterns, a roster of abused domains and malware families, and identifiable actor clusters. For defenders and policy makers alike, the lesson is literal and immediate — dropped domains are not neutral; many are already weapons.

Source: The Hacker News — "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware"