Infoblox Threat Intel published a report on August 14, 2026, documenting the dropcatch domain market as systemic cybercrime infrastructure. Roughly 65,000 expired domains are re-registered daily in the first half of 2026, and nearly 20% of all new daily registrations fall into this category. A single actor, dubbed Sable Squirrel, invested approximately $7 million to acquire more than 10,000 of these domains, exploiting inherited legitimacy signals to distribute malware and run scams.
- Approximately 65,000 expired domains are re-registered daily; nearly 20% of daily new registrations are dropcatch, peaking at 30% for .net and .xyz.
- Sable Squirrel spent roughly $7 million on over 10,000 expired domains, inheriting reputation, backlinks, and residual traffic from brands such as GE, P&G, Sony, and Kroger.
- A subset of domains used for illegal streaming simultaneously functions as C2 servers for RATs and ransomware, with over 31,000 malware samples communicating with the infrastructure.
- 94% of domains acquired by Sable Squirrel are weaponized within two weeks, rendering slow threat-intelligence update cycles ineffective.
The Inheritance Mechanism: Why an Old Domain Is Worth More Than a New One
When a domain expires and is re-registered, it retains signals that security systems and reputation algorithms treat as trust indicators: registration age, backlinks, cached search results, residual traffic, historical DNS records. This information asymmetry is the core of the problem. As Infoblox notes in the report, "expired domains can be a shortcut to both trust and traffic, making dropcatch domains a higher risk than the average newly-registered domain."
Criminals exploit the gap between what systems see and what actually happens. A domain like healthymagination.com, formerly owned by GE, or rezilion.com, a cybersecurity company whose assets were acquired by GitLab in 2024, arrives at auction with a formally low risk profile. Sable Squirrel acquired these and other branded domains — cel-robox.com (3D printer), maxfactor-international.com (P&G), krogeralbertsons.com, snsystems.com (Sony) — and reactivated them for entirely different purposes.
The speed is striking. According to Infoblox, 24% of domains re-registered by Sable Squirrel go live the same day as purchase, 76% within seven days, and 94% within two weeks. This window, highlighted by The Hacker News, is insufficient for many threat intelligence platforms that update reputation scores on monthly or quarterly cycles.
"Sable Squirrel buys reputation by the domain, wires it into a streaming-to-gambling machine, and leverages a share of the same domains as malware infrastructure."
— Infoblox Threat Intel, via The Hacker News
Dual-Use and the Two-Track Model: Streaming in Front, C2 Behind
Sable Squirrel has refined an operational model Infoblox calls "two-track." On one side, auctioned expired domains inherit legitimacy and traffic; on the other, fresh, lookalike domains form a fleet of illegal streaming platforms. The services — Xoilac, Cakhia, 90phut, Socolive, MiTom — offer live sports streams and redirect users to gambling sites. Monetization runs through gambling.
The more insidious component is the technical dual-use. A subset of the same streaming domains simultaneously serves as command-and-control servers for malware. As IT Pro documents, "a human visitor sees a live football streaming site while an infected device uses the same domain as a control channel." Documented RATs include Quasar, AsyncRAT, DCRat, NanoCore, Remcos, and njRAT; the HiddenTear ransomware is also present. Over 31,000 malware samples have communicated with the Sable Squirrel infrastructure, according to Infoblox as cited by IT Pro and The Hacker News.
The separation between legitimate facade and malicious infrastructure defeats controls based solely on visible content. An analyst visiting the domain with a standard browser sees a sports stream; only traffic from compromised endpoints activates the C2 channel.
The Shadow Registrars: GoDaddy, Namecheap, and the Auction Market
Sourcing occurs through major registrars and auction platforms. According to the Infoblox report cited by The Hacker News, daily dropcatch medians are: GoDaddy 5,246 domains, Namecheap 4,385, DropCatch.com 3,568. These actors operate legally; the expired domain auction market is transparent and regulated. The vulnerability lies not in the mechanism itself, but in the absence of buyer verification and post-sale monitoring.
The TLD distribution confirms concentration: in gTLDs, the average is 50,400 domains per day, with 15 TLDs covering 92% of activity. .net and .xyz register dropcatch rates near 30% of new registrations, .com at 24.5%. The phenomenon is structural, not marginal.
Renée Burton, VP of Infoblox Threat Intel, commented via IT Pro: "The sheer volume of dropcatch domains is astounding. We've known that bad guys buy expired domains to repurpose them, but the way in which they were used, and the amount of money actors are willing to spend wasn't well understood." The roughly $7 million figure for Sable Squirrel alone, with returns flowing through gambling and malware-as-a-service, indicates a criminal business model with investment logic and scalability.
Scavenger Actors and the Collaboration Network with SocGholish
Infoblox tracks three other "scavenger actors" beyond Sable Squirrel: Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel. Shady Squirrel, active since July 2023 and assessed as Vietnam-centric with strong infrastructural overlaps, inherits traffic from previously compromised domains and directs it to SocGholish and tech-support scams.
The SocGholish connection is particularly significant for infrastructure resilience. According to Infoblox as cited by Security Affairs, SocGholish restored access to thousands of compromised sites by collaborating with Shady Squirrel days after its infrastructure was hit by a law enforcement operation. IT Pro specifies that collaboration with the SocGholish operator TA569 began in July. This indicates the dropcatch domain market also serves as a failover mechanism for existing actors who lose their infrastructure.
At-Risk Sectors and the Failure of Reputation-Based Filters
Sectors that have recorded contact with Sable Squirrel C2 domains include education, IT and consulting, government, healthcare, and banking, according to Infoblox as cited by The Hacker News. The danger lies not in direct system compromise, but in detection difficulty. A domain with a multi-year registration history, backlinks from authoritative sources, and organic traffic evades filters that flag newly registered domains as high-risk.
The result is an inversion of the defensive paradigm: domain age, traditionally a trust indicator, becomes a vulnerability. Organizations relying on static reputation scores without verifying ownership changes or post-re-registration traffic anomalies expose their users to C2 channels that appear legitimate.
What to Do Now
- Verify reputation scores by comparing domain age against the last ownership change date: an "old" domain recently re-registered should be treated with the same caution as a new domain.
- Integrate historical DNS record and anomalous backlink monitoring into security systems: a sudden IP, nameserver, or content shift on a domain with established history indicates malicious reuse.
- Shorten threat intelligence feed update windows for expired domains: 94% weaponization within two weeks renders monthly or quarterly cycles obsolete.
- Analyze outbound traffic to streaming and gambling domains alongside beaconing indicators: the overlap of seemingly legitimate content and C2 patterns requires network-level inspection, not just endpoint analysis.
Why the Auction Market Is the Regulatory Blind Spot
The problem is not technically an exploit: domains are purchased legally. The intervention point is the market itself, where buyer anonymity, transaction speed, and the absence of post-sale verification allow a single actor to accumulate over 10,000 domains without friction. The roughly $7 million investment by Sable Squirrel suggests the return is multiplicative, spanning gambling, streaming, and C2 infrastructure rental.
The Infoblox report announces subsequent parts that may delve into other actors and techniques. What emerges already is that the domain name system, designed for persistence and trust, has been repurposed as a tool of criminal inheritance. The question is no longer whether a domain is old or new, but who controls it now and what they do with it.
Frequently Asked Questions
What exactly is a dropcatch domain?
An expired domain that is re-registered, often at auction, shortly after expiration. It retains reputation signals from the previous registration: age, backlinks, residual traffic, historical DNS records.
Were brand domains like GE or Sony purchased directly by Sable Squirrel?
The Infoblox report documents these domains in Sable Squirrel's portfolio but does not specify whether acquisition was direct or through intermediaries.
Why don't registrars block these purchases?
Registrars operate in an open market; expired domain auctions are legal. The report does not indicate specific preventive measures adopted by registrars, nor regulatory recommendations in this direction.
Sources
- https://securityaffairs.com/197251/uncategorized/crooks-are-buying-your-expired-domains-and-using-them-to-deliver-malware.html?amp
- https://securityaffairs.com/197251/uncategorized/crooks-are-buying-your-expired-domains-and-using-them-to-deliver-malware.html
- https://www.itpro.com/security/cyber-crime/expired-domains-are-a-goldmine-for-hackers-and-some-cyber-crime-groups-are-investing-millions-in-dropcatch-scams-to-deliver-malware
- https://www.scworld.com/brief/cybercriminals-invest-millions-in-expired-domains-for-illicit-activities
- https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html
- https://thehackernews.com/2025/01/expired-domains-allowed-control-over.html
- https://thehackernews.com/2026/06/operation-endgame-disrupts-socgholish.html
- https://thehackernews.com/2026/04/fake-captcha-irsf-scam-and-120-keitaro.html
- https://thehackernews.uk/zero-trust-claude-d
- https://thehackernews.uk/corelight-d
Information verified against cited sources and current as of publication.