Hackers spend millions buying expired domains to spread malware
Security firm Infoblox Threat Intel found that hackers were re-registering around 65,000 expired domains per day in the first half of 2026 — nearly one in five of all new registrations. One criminal group, dubbed "Sable Squirrel", controls over 10,000 such domains and is estimated to have spent more than $7 million acquiring them. The inherited trust scores and traffic of these domains allow attackers to bypass security filters and use them as malware distribution and command-and-control infrastructure.
Full text
Infoblox Threat Intel counted roughly 65,000 expired domains re-registered every day in the first half of 2026, close to one in five of all new registrations
An actor it calls Sable Squirrel controls more than 10,000 domains and is estimated, by extrapolation, to have spent over $7 million buying expired names for their inherited traffic and domain authority
Some of the domains are also used to function as command-and-control structures for existing malware that can be traced back to the same group
A domain name is the closest thing the web has to a credit history: age, inbound links, search visibility, and reputation all feed the reputation scores that security products consult before deciding whether a request is worth worrying about.
New research from Infoblox Threat Intel claims this history has become a commodity with a market price, and that at least one criminal operation has been buying it in bulk.
The study, published as a three-part series, focuses on what the industry calls dropcatch domains: names that lapsed, were released back to the registry, and were then re-registered by someone else entirely.
A dropcatch domain situation: A gambling business with a malware-enabling catch
Dropcatch domains aren't new; software has been primed to spot expiring domains for years, and it sometimes snags the occasional massive win for users who deploy such solutions.
This lets users start with domains that already have history that benefits them or flip certain domains for a price that is often a multiple of the domain's original purchase price.
Infoblox counted an average of 50,400 such re-registrations a day across generic top-level domains in the first half of 2026, rising to roughly 65,000 once country-code domains are added. That amounts to close to a fifth of all daily registrations. The rate is highest on .net and .xyz, where nearly three in ten newly observed names had a previous life, with .com behind them at 24.5%.
The problem is that not all of these are seemingly innocent or small-scale scalping operations: Infoblox has identified an entity it has labeled Sable Squirrel, part of a naming convention the company applies to domain hoarders. It controls more than 10,000 domains, most of which support a large Vietnamese-language sports piracy operation operating under brands including Xoilac, Cakhia, 90phut, Socolive, and MiTom.
Infoblox estimates the actor's total spend on expired domains at north of $7 million, which it describes as the largest domain acquisition budget it has identified for a single actor in the industry. The bigger problem is that Infoblox also found that a subset of these streaming domains runs as malware command and control while continuing to serve live football to human visitors.
More than 31,000 samples identified called back to Sable Squirrel's infrastructure, spanning Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, and njRAT, plus samples carrying HiddenTear ransomware signatures.
Infoblox said the operator's carelessness made finding a link easier: many samples carry the actor's brand names in their Windows executable metadata, with fields reading socolive, xoilac, and 8xbet. Infoblox confirmed 405 domains as malware C2, which is roughly four percent of the total domains the organization controls, and the weaponization arrived as a single wave in late 2025 rather than as the operation's original purpose.
Sable Squirrel's core business is gambling, and while the entity tries to mask it as a streaming operation, it also doubles as an acquisition channel for the same. While law enforcement has not been silent here, it has had limited luck at best: Vietnamese authorities froze some of the flagship sites in February 2026 and charged 30 suspects in March.
They also seized assets Infoblox puts at roughly $12 million, but it seems to have survived and continues to expand, having acquired and run World Cup-centric domains since June, further expanding its footprint in a world where it has already identified and secured a large chunk of what is arguably a very important commodity: Domain authority.
Similar stories
💻 Technology
North Korean hackers compromised OPPO and 1,600+ firms in 57 countries via fake job interviews
Android Authority · 15d ago
💻 Technology
Hackers demand ransom from Target after claiming 8.6GB data theft
TechRadar · 6h ago
💻 Technology
New malware iAuthFlow v2 hijacks Google accounts even after password reset
TechRadar · 7h ago
Similar stories
💻 Technology
North Korean hackers compromised OPPO and 1,600+ firms in 57 countries via fake job interviews
Android Authority · 15d ago
💻 Technology
Hackers demand ransom from Target after claiming 8.6GB data theft
TechRadar · 6h ago
💻 Technology
New malware iAuthFlow v2 hijacks Google accounts even after password reset
TechRadar · 7h ago
Should domain registrars impose a mandatory quarantine period on expired domains?
Comments
No comments yet
Comments
No comments yet — be the first to weigh in 👇
No comments yet. Be the first!