LIVE · cybersecurity feed
Live wire
malware

Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware

Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. Infoblox Threat Intel calls these dropcatch domains, and in the first half of 2026 they […]

zeroday.news ·

Cybersecurity researchers have identified a growing trend where threat actors are acquiring expired domain names to leverage their established reputation, existing web traffic, and DNS history for malicious purposes, including malware delivery, scams, and command-and-control (C2) infrastructure. Approximately 65,000 domain names are re-registered daily after expiring, with these "dropcatch" domains accounting for nearly 20% of all new domain registrations in the first half of 2026.

Infoblox Threat Intel, which published a report on this activity, notes that one in five newly registered domains has a prior history. While some of these domains are acquired by legitimate investors or researchers, a significant portion falls into the hands of attackers who recognize the inherent value of a domain with an established past. Such domains may be viewed more favorably by security products and reputation-based algorithms than genuinely new registrations due to their age and historical signals.

The inherited value extends beyond reputation scores. Expired domains often retain residual web traffic from old backlinks, receive email intended for previous owners, appear in cached search results, and may even have lingering DNS records pointing to infrastructure no longer controlled by the original registrant. This pre-existing infrastructure provides a ready-made platform for various illicit activities.

Among generic top-level domains (gTLDs), an average of 50,400 dropcatch domains are registered daily, with 15 TLDs making up about 92% of this activity. The .net and .xyz TLDs show the highest rates, with nearly 30% of new registrations being previously registered, while .com accounts for 24.5%. The identities of those acquiring these domains and their specific uses are often obscured by WHOIS privacy, domain transfers, parking services, and auctions.

Infoblox has been tracking a threat actor dubbed "Sable Squirrel," which has reportedly spent nearly $7 million acquiring expired domains. This actor has built a criminal operation encompassing illegal sports streaming, gambling promotion, and malware infrastructure. Sable Squirrel controls over 10,000 domains, operating streaming platforms under brands like Xoilac, Cakhia, and 90phut, which target Vietnamese, Korean, Japanese, and Australian users and direct them to betting sites. A subset of these streaming domains also functions as C2 servers for malware such as Quasar RAT, AsyncRAT, DCRat, and Remcos RAT.

Notable expired domains acquired by Sable Squirrel include healthymagination.com, which was originally associated with a General Electric health initiative, and rezilion.com, a cybersecurity company whose assets were sold to GitLab in 2024. The acquisition of a defunct infosec firm's domain and its subsequent redirection to malware infrastructure highlights the attackers' understanding of how security tools evaluate domain age. Once Sable Squirrel re-registers a domain, it moves quickly, with 24% going live the same day and 94% within two weeks, aiming to capture traffic before security systems update their assessments.

Beyond Sable Squirrel, Infoblox is also monitoring three "scavenger" actors: Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel. These groups operate differently, acquiring expired domains that were previously compromised by other attackers and inheriting the existing infection traffic. Shady Squirrel, believed to be Russian-speaking and active since at least July 2023, reportedly funnels this traffic to SocGholish and tech support scam networks. It is claimed that SocGholish regained access to thousands of compromised sites by collaborating with Shady Squirrel shortly after its own infrastructure was disrupted by law enforcement.

The research suggests that defenders should question, rather than implicitly trust, domain age and reputation as security indicators, given that an old domain in new hands is only as trustworthy as its current owner. This phenomenon underscores a significant challenge in cybersecurity, as threat actors increasingly exploit the legacy attributes of expired domains to enhance the credibility and effectiveness of their malicious operations.

malware
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.

vulnerability

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.

CVE-2026-58231critical

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek.

vulnerability

Police bust cybercrime ring accused of stealing €30 million in four-day spree

German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. Brazilian police named the operation “Klonen.” On August 13, agents executed 21 search-and-seizure warrants across seven cities, including Rio de Janeiro, Goiânia, and