Home Business News Threat Actors Are Buying History And Trust: Infoblox Threat Intel Exposes the...

Threat Actors Are Buying History And Trust: Infoblox Threat Intel Exposes the Criminal Afterlife of Expired Domains

12

New research reveals how cybercriminals are spending millions to acquire expired domains  and repurpose them for malware, scams, illegal streaming and online gambling

DUBAI, UAE, August, 2026: Every day, tens of thousands of internet domains expire and become available for registration again. Infoblox Threat Intel observed approximately 65,000 re-registered “dropcatch” domains daily during the first half of 2026. Dropcatch domains represent nearly 20% of all newly observed domains each day. Through these purchases, threat actors inherit trust, backlinks and web traffic from the former owner. Not only are legitimate domains prized by threat actors, but there is a thriving market for known malicious domains as well. This new research delves into the details of how these dropped domains are repurposed and exposes several malicious actors not previously known.

One investigation uncovered a threat actor dubbed Sable Squirrel, who researchers estimate has invested more than $7 million acquiring over 10,000 expired domains. Those domains underpin a criminal ecosystem spanning illegal streaming, online gambling and malware distribution, demonstrating how expired domains have evolved from forgotten web addresses into valuable cybercriminal infrastructure. Notably, Sable Squirrel operates command-and-control (C2) nodes for multiple remote access trojans (RATs) on the same infrastructure as illegal content.

Sable Squirrel acquires legitimate domains to capture their positive reputation, but other threat actors take over well-known malicious domains that were inserted into compromised websites. Across three additional newly identified threat actors, Infoblox Threat Intel found thousands of dropcatch domains embedded in tens of thousands of compromised websites that continue directing victims to various malicious payloads. 

Most notably, the research uncovered one actor who uses tactics to deliver potential victims to SocGholish, the notorious “fake update” infrastructure which was the target of Operation Endgame in June 2026. This threat actor, tracked as Shady Squirrel by Infoblox Threat Intel, delivered malware through scareware and call centers before partnering up with SocGholish’s operator TA569 in July.

“The sheer volume of dropcatch domains is astounding. We’ve known that bad guys buy expired domains to repurpose them, but the way in which they were used, and the amount of money actors are willing to spend wasn’t well understood.” said Dr. Renée Burton, VP of Infoblox Threat Intel. “Expired domains can be a shortcut to both trust and traffic, making dropcatch domains a higher risk than the average newly registered domain.” 

The research is detailed in a three-part series from Infoblox Threat Intel:

  • Part 1: Explains how dropcatch domains retain trust, reputation and traffic after expiring, creating opportunities for abuse. 
  • Part 2: Details the Sable Squirrel investigation, revealing a criminal operation that invested more than $7 million in expired domains to support illegal streaming, gambling and malware. 
  • Part 3: Profiles three additional threat actors – Stuffy Squirrel, Shady Squirrel and Swiping Squirrel. These threat actors acquire expired malicious domains to inherit victim traffic from previously compromised websites, redirecting users to scams, malware and advertising fraud. Together, they demonstrate how threat actors profit from infrastructure built by other criminals.

Pic:

  • Dr. Renée Burton, VP of Infoblox Threat Intel
  • Depiction of threat actors Stuffy Squirrel, Shady Squirrel and Swiping Squirrel

About Infoblox Threat Intel:

Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet’s inner workings allows us to track down threat actors that others can’t see. We’re proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox DNS Detection and Response solutions, so customers automatically get its benefits, along with ridiculously low false positive rates. 

About Infoblox:

Infoblox is a leading platform for preemptive security and hybrid, multi-cloud networking that delivers enterprise resilience and agility. Trusted by over 5,700 customers, including the majority of Fortune 100 companies as well as emerging innovators, we seamlessly integrate, secure and automate critical network services so businesses can move fast without compromise. Visit Infoblox.com, or follow us on LinkedIn.