Threat actors are increasingly buying expired domain names and using their previous reputation, traffic and connections to redirect victims to scams, malware and other malicious services on a large scale.
DNS threat intelligence company Infoblox calls these “dropcatch domains.” The term refers to expired domains that become available for registration and are quickly acquired by another party. During the first half of 2026, around 50,400 dropcatch domains were re-registered every day across generic top-level domains such as .com. When country-code domains are included, the number rises to about 65,000 per day, representing nearly one in five newly registered domains.
The attraction for cybercriminals is that an expired domain can retain some of the reputation and connections it built under its previous owner. It may still have backlinks, search engine visibility, cached results, incoming traffic and even DNS records that can be useful to an attacker. This can make the domain appear more trustworthy to security systems and users than a newly registered domain.
Infoblox found that .net and .xyz are the leading top-level domains for dropcatch activity, followed by .com. Other frequently used extensions include .org, .vip, .online, .store, .site, .app and .shop. Domains are commonly re-registered through services including GoDaddy, Namecheap and DropCatch.com.
Expired domains do not immediately become available after their registration ends. Most generic top-level domains have a recovery period during which the original owner can renew the domain. Once that period ends, the domain is released and can be registered again. Drop-catching services monitor these domains and automatically attempt to register them when they become available, with domains attracting multiple buyers sometimes going to auction.
While expired domains can be purchased for legitimate reasons, including domain investing and defensive security research, Infoblox says the practice can become a serious security problem when criminals acquire domains with valuable histories. A previously trusted domain can come with residual traffic, email intended for the former owner, backlinks and other connections that can be abused.
One threat actor tracked as Sable Squirrel has reportedly spent nearly $7 million acquiring expired domains. Infoblox says the operation has built infrastructure supporting illegal sports streaming, gambling promotion and malware distribution, with evidence pointing to Vietnam as the center of its activity.
The group controls more than 10,000 domains, many of which support Asian sports piracy operations operating under brands including Xoilac, Cakhia, 90phut, Socolive and MiTom. These platforms attract sports viewers and direct some of their traffic toward betting services including VSBet, ColaScore and 8xbet.
Sable Squirrel promotes these services through platforms such as Facebook, Instagram, Reddit, Twitch and YouTube, as well as compromised job-posting and community websites. A traffic distribution system is used to selectively redirect visitors in countries including Vietnam, South Korea, Japan, Taiwan, Singapore and Australia toward the illegal streaming sites.
Infoblox also found that the threat actor has distributed Android applications associated with ColaScore and VSBet through Google Play and developer accounts suspected of being compromised. The company said it has seen multiple versions of the compromised accounts distributing the same applications, with replacement accounts appearing after Google suspends them.
The infrastructure linked to Sable Squirrel has also communicated with at least 31,000 malware samples, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT and njRAT. Some samples also contain signatures associated with HiddenTear ransomware. Infoblox found that some of the streaming domains themselves are being used as malware command-and-control infrastructure while continuing to serve streaming content.
The Xoi Lac TV brand dates back to 2016, but Infoblox says the first malware command-and-control configurations appeared on Sable Squirrel domains in November 2025. The company believes the threat actor began acquiring dropcatch domains as early as June 2023.
Sable Squirrel uses two types of domains. One involves expired domains purchased through auctions and drop-catching services to inherit their previous registration history, backlinks and traffic. The other consists of newly registered lookalike domains used as part of its streaming infrastructure.
Some of the expired domains identified by Infoblox include healthymagination.com, maxfactor-international.com, krogeralbertsons.com, snsystems.com, rezilion.com and cel-robox.com. The domains previously belonged to organizations or projects associated with areas including healthcare, cosmetics, technology and cybersecurity.
Infoblox found that cel-robox.com was acquired and used both as an illegal streaming website and as command-and-control infrastructure for Quasar RAT. Organizations in sectors including education, IT and consulting, government, healthcare and banking were among those observed reaching malware command-and-control domains.
The researchers found that these domains can be weaponized very quickly after being re-registered. Around 24% were active on the same day they were acquired, 76% became active within seven days and 94% were active within two weeks.
The operation also uses redirection and cloaking systems to send selected sports fans toward gambling platforms while attempting to keep those pages hidden from bots and other visitors. Infoblox said Sable Squirrel effectively uses expired domains to buy a head start through inherited trust, traffic and backlinks.
Sable Squirrel is not the only group using expired domains in this way. Infoblox is also tracking several financially motivated groups that acquire expired domains and redirect the traffic left behind by their previous owners toward scams, malware and advertising services.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
One of them, Stuffy Squirrel, has been active since at least 2020 and controls more than 500 domains. It uses traffic distribution systems and malicious JavaScript to redirect visitors toward affiliate advertising networks, pop-up advertisements and unwanted notifications while showing legitimate content to security scanners. Shady Squirrel, active since at least July 2023, controls more than 700 domains and redirects traffic toward initial access brokers, cybercriminals and technical-support scams. Swiping Squirrel, active since at least 2022, controls more than 3,000 domains and sends fraudulent traffic to zero-click advertising platforms that can resell it for scams or malware.
Infoblox describes these groups as scavengers because they do not necessarily need to compromise websites themselves. Instead, they acquire expired domains that continue receiving traffic from infections or other activity left behind by previous owners, then add their own content and redirect the existing visitors.





