Cybersecurity researchers have identified a growing trend where threat actors are acquiring expired domain names to leverage their established reputation, existing web traffic, and DNS history for malicious purposes, including malware delivery, scams, and command-and-control (C2) infrastructure. Approximately 65,000 domain names are re-registered daily after expiring, with these "dropcatch" domains accounting for nearly 20% of all new domain registrations in the first half of 2026.
Infoblox Threat Intel, which published a report on this activity, notes that one in five newly registered domains has a prior history. While some of these domains are acquired by legitimate investors or researchers, a significant portion falls into the hands of attackers who recognize the inherent value of a domain with an established past. Such domains may be viewed more favorably by security products and reputation-based algorithms than genuinely new registrations due to their age and historical signals.
The inherited value extends beyond reputation scores. Expired domains often retain residual web traffic from old backlinks, receive email intended for previous owners, appear in cached search results, and may even have lingering DNS records pointing to infrastructure no longer controlled by the original registrant. This pre-existing infrastructure provides a ready-made platform for various illicit activities.
Among generic top-level domains (gTLDs), an average of 50,400 dropcatch domains are registered daily, with 15 TLDs making up about 92% of this activity. The .net and .xyz TLDs show the highest rates, with nearly 30% of new registrations being previously registered, while .com accounts for 24.5%. The identities of those acquiring these domains and their specific uses are often obscured by WHOIS privacy, domain transfers, parking services, and auctions.
Infoblox has been tracking a threat actor dubbed "Sable Squirrel," which has reportedly spent nearly $7 million acquiring expired domains. This actor has built a criminal operation encompassing illegal sports streaming, gambling promotion, and malware infrastructure. Sable Squirrel controls over 10,000 domains, operating streaming platforms under brands like Xoilac, Cakhia, and 90phut, which target Vietnamese, Korean, Japanese, and Australian users and direct them to betting sites. A subset of these streaming domains also functions as C2 servers for malware such as Quasar RAT, AsyncRAT, DCRat, and Remcos RAT.
Notable expired domains acquired by Sable Squirrel include healthymagination.com, which was originally associated with a General Electric health initiative, and rezilion.com, a cybersecurity company whose assets were sold to GitLab in 2024. The acquisition of a defunct infosec firm's domain and its subsequent redirection to malware infrastructure highlights the attackers' understanding of how security tools evaluate domain age. Once Sable Squirrel re-registers a domain, it moves quickly, with 24% going live the same day and 94% within two weeks, aiming to capture traffic before security systems update their assessments.
Beyond Sable Squirrel, Infoblox is also monitoring three "scavenger" actors: Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel. These groups operate differently, acquiring expired domains that were previously compromised by other attackers and inheriting the existing infection traffic. Shady Squirrel, believed to be Russian-speaking and active since at least July 2023, reportedly funnels this traffic to SocGholish and tech support scam networks. It is claimed that SocGholish regained access to thousands of compromised sites by collaborating with Shady Squirrel shortly after its own infrastructure was disrupted by law enforcement.
The research suggests that defenders should question, rather than implicitly trust, domain age and reputation as security indicators, given that an old domain in new hands is only as trustworthy as its current owner. This phenomenon underscores a significant challenge in cybersecurity, as threat actors increasingly exploit the legacy attributes of expired domains to enhance the credibility and effectiveness of their malicious operations.






