Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
exploitHackMalware

Sable Squirrel Spends Million on Expired Domains for Malware

By ogwatermelon
August 17, 2026 4 Min Read
0
August 16, 2026

A threat actor tracked as Sable Squirrel has spent nearly $7 million acquiring expired domains to build a sprawling criminal enterprise. Consequently, the group operates illegal sports streaming platforms, online gambling promotions, and malware infrastructure across more than 10,000 domains. This operation highlights a growing threat vector where attackers weaponize domain reputation rather than registering fresh domains from scratch.

What Happened: Sable Squirrel Weaponizes Expired Domains for Malware and Fraud

DNS threat intelligence firm Infoblox disclosed the Sable Squirrel campaign in August 2026. Furthermore, the report reveals that the threat actor has been purchasing dropcatch domains since at least June 2023. These are domains that previously expired and were re-registered by new owners, inheriting the original reputation, backlinks, and residual traffic.

Infoblox found that 50,400 dropcatch domains were re-registered daily in gTLDs like .com during the first half of 2026. Moreover, when ccTLDs are included, the daily figure rises to approximately 65,000. Therefore, one in five newly registered domains is a dropcatch, creating a massive pool of potentially weaponized infrastructure.

Technical Details of the Dropcatch Domain Abuse

Sable Squirrel operates what Infoblox describes as a two-track domain model. First, the group buys expired domains at auctions through registrars like DropCatch.com, GoDaddy, Namecheap, and Dynabot. These purchases inherit existing registration history, inbound traffic, and search engine credibility. Second, the group registers fresh lookalike domains to run the streaming fleet.

Exploitation and Delivery

The dropcatch domains are weaponized rapidly. For example, Infoblox observed that 24% go live the same day they are re-registered. Moreover, 76% are active within seven days, and 94% within two weeks. This speed capitalizes on residual trust before security vendors can re-evaluate the domain’s reputation.

The operation targets users across Vietnam, South Korea, Japan, Taiwan, Singapore, and Australia. In addition, the group promotes brands through Facebook, Instagram, Reddit, Twitch, Amazon Podcasts, and compromised job-posting sites. Visitors are redirected via a traffic distribution system (TDS) to illicit streaming platforms while bots and unintended targets are sent to dead ends.

Malware Infrastructure

No fewer than 31,000 malware samples have communicated with Sable Squirrel infrastructure. Furthermore, the samples include well-known remote access trojans such as Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, and njRAT. Some domains also serve as command-and-control servers while simultaneously presenting live streaming content.

Notable dropcatch domains repurposed by the group include:

  • healthymagination[.]com — a former General Electric health initiative
  • maxfactor-international[.]com — a cosmetics brand owned by Procter & Gamble
  • krogeralbertsons[.]com — created for the proposed Kroger and Albertsons merger
  • snsystems[.]com — a former Sony PlayStation developer tools company
  • rezilion[.]com — a defunct cybersecurity company whose assets were purchased by GitLab
  • cel-robox[.]com — a former desktop 3D printer company

Business and Operational Impact

The Sable Squirrel operation has broad implications for organizations and individuals. Because the group inherits existing domain reputation, traditional security filters may mistakenly allow traffic to these domains. The impact spans multiple sectors:

  • Financial losses: The group has spent an estimated $7 million on domain acquisitions alone
  • Malware infections: Over 31,000 malware samples have beaconing infrastructure tied to Sable Squirrel domains
  • Sector targeting: Education, IT consulting, government, healthcare, and banking have been observed reaching malware C2 domains
  • Platform abuse: Android apps for betting services have been published on the Google Play Store using compromised developer accounts

Mitigation and Recommendations

Organizations should adjust their defenses to account for dropcatch domain abuse. Because reputation-based blocking alone is insufficient, defenders need additional layers of detection and prevention.

Immediate Actions for Defenders

  1. Monitor DNS logs for lookups to known Sable Squirrel domains and infrastructure
  2. Review web proxy and firewall logs for traffic to recently re-registered expired domains
  3. Implement time-based reputation scoring that weights domain age more heavily
  4. Block or alert on traffic to domains that changed ownership recently
  5. Inspect Android apps from the Google Play Store for suspicious betting or streaming brands

Long-Term Strategy

Security teams should incorporate domain age and ownership history into threat intelligence platforms. Furthermore, organizations that allow expired domains to lapse should monitor for re-registration and consider defensive registration of critical domains. In addition, DNS threat intelligence feeds that track dropcatch activity can provide early warning of emerging campaigns.

Bottom line: Sable Squirrel proves that domain reputation is a weapon. Organizations must stop trusting domains solely based on age and history. Instead, combine continuous DNS monitoring, ownership change detection, and behavioral analysis to catch threats before they reach endpoints.

Incident Summary

Threat Actor: Sable Squirrel
First Observed: June 2023 (domain purchases); November 2025 (malware C2)
Disclosure Date: August 14, 2026
Affected Regions: Vietnam, South Korea, Japan, Taiwan, Singapore, Australia
Domain Count: Over 10,000
Malware Families: Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT, HiddenTear
Sector Impact: Education, IT consulting, government, healthcare, banking
Financial Estimate: ~$7 million in domain acquisition costs
Patch Status: N/A — this is an operational threat, not a software vulnerability

References

  1. Infoblox, “Drop Something, Don’t Worry, Someone Caught It,” August 2026, https://www.infoblox.com/blog/threat-intelligence/drop-something-dont-worry-someone-caught-it/, accessed August 16, 2026.
  2. The Hacker News, “Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware,” August 14, 2026, https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html, accessed August 16, 2026.
  3. DropCatch.com, “How It Works — Overview,” https://www.dropcatch.com/hiw/overview, accessed August 16, 2026.
  4. WatchTowr Labs, “The Perils of Expired Domains — We’re Reading Your Email,” https://labs.watchtowr.com/the-perils-of-expired-domains-were-reading-your-email/, accessed August 16, 2026.

Tags:

ExploitHackMalware
Author

ogwatermelon

Follow Me
Other Articles
Previous

Mirai Successor Hijacks Routers for SOCKS5 Proxies and DDoS Attacks

Next

Threema DDoS Attack Disrupts Secure Messaging Service

AI Botnet Breach CVE Exploit Hack Incident Infostealer Linux Mac Malware Network Phishing Ransomware RCE supply chain Vishing Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Infostealer
  • Linux
  • Mac
  • Malware
  • Phishing
  • Ransomware
  • RCE
  • supply-chain
  • Uncategorized
  • Vishing
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.