Expired Domain Abuse Fuels Large Scale Scam And Malware Operations

Expired Domain Abuse Fuels Large Scale Scam And Malware Operations

Threat actors are increasingly purchasing expired internet domains to inherit their existing reputation, web traffic and trust, allowing them to redirect unsuspecting users to scam websites, illegal gambling platforms and malware infrastructure on a large scale. According to DNS threat intelligence company Infoblox, these re registered websites are known as dropcatch domains because they are acquired immediately after becoming available following expiration. During the first half of 2026, around 50,400 expired domains within generic top level domains such as .com were re registered every day. When country code top level domains are included, the figure rises to approximately 65,000 domains daily, representing nearly 20 percent of all new domain registrations. Infoblox warned that these domains inherit historical reputation, backlinks, cached search results and existing traffic from previous owners, making them more trustworthy in the eyes of security products and reputation based systems than completely new domain registrations. The company stated that cybercriminals actively exploit this inherited trust to increase the effectiveness of their malicious campaigns.

Infoblox found that .net and .xyz currently lead in dropcatch activity, followed by .com, .org, .vip, .online, .store, .site, .app and .shop. Many of these domains are acquired through registrars and drop catching services such as GoDaddy, Namecheap and DropCatch.com, which automatically attempt to register expired domains the moment they become available. If multiple buyers request the same domain before it is released, the domain is typically sold through a public auction. While security researchers sometimes acquire expired domains to prevent abuse and domain investors purchase them for resale opportunities, Infoblox warned that threat actors view them as valuable assets because they inherit more than just domain names. Expired domains often retain inbound links, email traffic, DNS records and web visitors from their previous owners, providing cybercriminals with an established online presence that can be rapidly converted into malicious infrastructure. According to the company, many re registered domains become operational within hours, with 24 percent activated on the same day they are acquired, 76 percent within one week and 94 percent within two weeks.

Among the most active threat groups identified by Infoblox is Sable Squirrel, which the company estimates has spent nearly 7 million dollars acquiring expired domains to support a criminal operation involving illegal sports streaming, gambling promotion and malware distribution. The group is believed to control more than 10,000 domains and is linked to sports streaming brands including Xoilac, Cakhia, 90phut, Socolive and MiTom. Evidence collected by Infoblox indicates that the operation has strong connections to Vietnam and overlaps with the former Xoi Lac TV network that was dismantled by Vietnamese authorities earlier this year. According to the report, Sable Squirrel promotes betting platforms including VSBet, ColaScore and 8xbet while using Facebook, Instagram, Reddit, Twitch, YouTube, Amazon Podcasts and compromised websites to redirect users in Vietnam, South Korea, Japan, Taiwan, Singapore and Australia. Infoblox also identified more than 31,000 malware samples communicating with infrastructure controlled by the group, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT and malware carrying HiddenTear ransomware signatures. Several of the streaming domains also function as malware command and control servers while continuing to display live sports content to visitors. The report also found that Sable Squirrel has acquired well known expired domains previously associated with organizations and brands, including healthymagination.com, maxfactor international.com, krogeralbertsons.com, snsystems.com, rezilion.com and cel robox.com, demonstrating how trusted domains are repurposed for criminal activities.

Infoblox also identified three additional financially motivated groups that rely on expired domains for cybercrime. Stuffy Squirrel operates more than 500 domains and redirects users to malicious advertising networks while presenting legitimate content to security scanners to avoid detection. Shady Squirrel, a Russian speaking threat actor controlling more than 700 domains, sends traffic to initial access brokers, tech support scams and malware operators including SocGholish using Keitaro infrastructure. Swiping Squirrel controls more than 3,000 domains and redirects fraudulent traffic to advertising platforms that later distribute scams and malware without directly hosting malicious content. According to Infoblox, these groups do not need to compromise websites themselves because they inherit victims through traffic already flowing to expired domains abandoned by previous owners. The company warned that cybercriminals are effectively purchasing trust, reputation and visitors instead of building them from scratch, enabling them to launch malicious campaigns more quickly while bypassing security systems that continue to rely heavily on historical domain reputation.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment