Site icon techcoffeehouse.com

Threat Actors Spend Millions On Expired Domains: Infoblox

Advertisements

Threat actors are spending millions of dollars acquiring expired “dropcatch” domains to distribute malware, host illegal gambling operations and run scam campaigns, according to new research from Infoblox Threat Intel.

Infoblox observed roughly 65,000 re-registered domains daily in the first half of 2026, representing nearly 20 per cent of all newly observed domains each day. By buying up expired domains, threat actors inherit the trust, backlinks and web traffic accumulated by the previous owner.

Millions spent building criminal infrastructure

One threat actor identified in the research, dubbed Sable Squirrel, is estimated to have invested more than US$7 million acquiring over 10,000 expired domains. Those domains underpin a criminal ecosystem spanning illegal streaming, online gambling and malware distribution, and the actor has been found operating command-and-control nodes for multiple remote access trojans on the same infrastructure as illicit content.

A second actor, tracked as Shady Squirrel, has been linked to SocGholish, the “fake update” infrastructure that was the target of Operation Endgame in June 2026. Shady Squirrel delivered malware through scareware and call centres before partnering with SocGholish operator TA569 in July.

“The sheer volume of dropcatch domains is astounding. We’ve known that bad guys buy expired domains to repurpose them, but the way in which they were used, and the amount of money actors are willing to spend wasn’t well understood,” said Dr Renée Burton, Vice President of Infoblox Threat Intel.

Three more actors profiled

The research, published as a three-part series, also profiles three additional threat actors — Stuffy Squirrel, Shady Squirrel and Swiping Squirrel — who acquire expired malicious domains embedded in tens of thousands of compromised websites to redirect victims toward scams, malware and advertising fraud.

Infoblox said expired domains represent a higher risk than newly registered ones precisely because they carry inherited legitimacy, making them a growing blind spot for organisations relying on domain age or reputation as a security signal.

Author

Exit mobile version