Threat actors have begun purchasing expired domains for the purposes of inheriting their reputations and traffic. They use these domains to redirect unsuspecting visitors to scams and malware. It's a simple but effective strategy, and it's happening at an astonishing scale.
DNS threat intelligence firm Infoblox has dubbed these re-registered domains "dropcatch domains." When a domain expires, it becomes available for purchase again. Threat actors snap them up, often within milliseconds, and immediately put them to work. They get the domain's history, its backlinks, its residual traffic, and most importantly, its reputation.
Here's why this works so well. Security products and email filters tend to trust older domains. A domain that has been registered for years and has legitimate backlinks looks safe. Threat actors know this and exploit it ruthlessly. They don't have to build trust from scratch. They just buy it.
Let me walk you through how dropcatch domains malicious infrastructure operates and what it means for your organization.
Key Facts about Dropcatch Domains
- 50,400 dropcatch domains registered per day just in .com
- 65,000 when ccTLDs are added
- Almost 20% of total domains registered per day are dropcatch domains
- Threat actors get reputation, backlinks, and traffic of former domain owner
- Domains are weaponized within hours of acquisition
- Illegal streaming, gambling, malware campaigns among many others
- Threat actor, Sable Squirrel, paid $7 million for expired domains
How Dropcatch Domains Work
The dropcatch domains malicious infrastructure relies on a surprisingly straightforward concept. When a domain expires, it becomes available for registration again. Threat actors grab these domains to benefit from their existing reputation and traffic.
What Happens When a Domain Expires:
Most gTLDs have a recovery period. It allows the original registrant the opportunity to reclaim his domain prior to its release back into the domain pool. Once this period has passed, the domain will be ready to register for any interested individual.
It becomes important in order to avoid losing their domains accidentally. But the timing system established by this process can also be noticed by the threat actors. They keep an eye on the domains that are going to expire soon, and wait for the right moment to steal them.
How Threat Actors Steal Them:
Some online services such as DropCatch.com are designed to catch the expired domains. They track domains approaching deletion and automatically try to register them the moment they become available. Customers place backorders on domains they want. If multiple people want the same domain, it goes to auction. The highest bidder wins.
DropCatch.com itself says: "Every day 60,000 - 85,000 .com and .net domain names become available on the 'Daily Drop.' The Drop is an extremely competitive market where advanced computer algorithms have a remarkable advantage by detecting the precise millisecond a domain name becomes available for registration and issuing hundreds of consecutive purchase attempts at once."
The Numbers Are Staggering:
During the first half of 2026, 50,400 dropcatch domains were re-registered every single day in .com alone. When you include country code top-level domains, that number jumps to about 65,000. That means nearly one out of every five newly registered domains is a dropcatch domain.
Why Dropcatch Domains Are So Dangerous
The danger of dropcatch domains malicious infrastructure comes down to one thing: inherited trust. When a domain is re-registered, it carries the reputation of its previous life.
Trust Factor:
Security and reputation-based systems always have more trust towards the older domain. An old domain with a history and back links is considered authentic. Threat actors pay a premium for this trust because it gives them a head start. They don't have to spend months building credibility. They just buy it.
This inherited trust is the key to the dropcatch domains malicious infrastructure. The old domain owned by a legitimate company may be able to evade filtering programs meant for new domains. This can be compared to putting on a stolen uniform in order to access security networks.
What Threat Actors Get:
A threat actor who purchases an expired domain does not only get the name.
They also inherit:
- Email intended for the original owner
- Cached search results that still point to the domain
- Web traffic from old backlinks
- A ready-made platform for code injection
- Lingering DNS records that can be abused
Speed Is Everything:
- Once re-registered, the dropcatch domains malicious infrastructure goes to work fast:
- 24% are weaponized the same day
- 76% within a week
- 94% within two weeks
Threat actors want to capitalize on the domain's reputation before security products update their ratings. The window of opportunity is small, but it's enough to cause real damage.
The Most Popular TLDs for Dropcatching
Infoblox identified which TLDs are most affected by dropcatch domains malicious infrastructure:
- .net dominates dropcatch activity
- .xyz comes in second
- .com is third
Other popular TLDs include:
- .org
- .vip
- .online
- .store
- .site
- .app
- .shop
The popularity of .xyz is worth noting. It is less expensive and comes with few restrictions, making it favorable for threats.
Top Registrars:
- GoDaddy: 5,246 median daily dropcatch domains
- Namecheap: 4,385 median daily dropcatch domains
- DropCatch.com: 3,568 median daily dropcatch domains
These are legitimate businesses, but threat actors are using their services to acquire domains at industrial scale.
Meet the Squirrels: The Actors Behind Dropcatch Domains
The dropcatch domains malicious infrastructure is run by a cast of threat actors. Infoblox has given them squirrel-themed names to track their activities.
Sable Squirrel: The Big Player
Sable Squirrel is the most significant operator in the dropcatch domains malicious infrastructure:
- Spent nearly $7 million on expired domains
- Controls more than 10,000 domains
- Runs a criminal enterprise spanning illegal sports streaming, gambling, and malware
The Business Model:
Sable Squirrel uses a two-track approach:
Track 1: Buying expired domains at auction to inherit legitimacy
Track 2: Registering lookalike domains to run the streaming fleet
The Brands:
- Xoilac
- Cakhia
- 90phut
- Socolive
- MiTom
Where They Operate:
- Vietnam is the center of the operation
- Targets users in Vietnam, South Korea, Japan, Taiwan, Singapore, and Australia
- Connected to Xoi Lac TV, an illegal streaming network shut down by Vietnamese authorities
The Malware Connection
The dropcatch domains malicious infrastructure doesn't just stream sports. It also serves malware. Operations of Sable Squirrel are dual-purpose.
31,000 Malware Samples:
Malware was identified to communicate with Sable Squirrel's infrastructures, including:
- Quasar RAT
- AsyncRAT
- DCRat
- NanoCore
- Remcos RAT
- njRAT
- HiddenTear ransomware
Dual-Purpose Domains:
There are domains that are used for streaming content as well as C2 channels for malware. The user watches the live-streaming of the games while, behind the scenes, the domain takes control of the compromised machines. This dual-purpose approach makes detection much harder.
Example:
"cel-robox[.]com" was bought by Sable Squirrel and used for both illegal streaming and Quasar RAT C2. One domain, two malicious uses.
The Traffic Distribution System
The dropcatch domains malicious infrastructure uses a clever traffic distribution system:
How It Works:
Domains like "6789x[.]site" route real viewers to betting platforms. Both bots and researchers get led to dead ends. The betting sites remain invisible to automatic searches.
Cloaking:
Pages on the Web that have gambling-related information are seen by real people; no one sees anything else. This helps bypass both security solutions and search engines.
Why Does This Matter?
Traffic distribution scheme for the dropcatch domain-based malicious infrastructure aims at earning maximum profit and hiding from detection. Real users are funneled to gambling sites where the threat actor earns commissions. Researchers and bots are blocked, preventing them from uncovering the operation.
The Scavengers
Beyond Sable Squirrel, Infoblox has identified three other actors. These are the scavengers of the dropcatch domains malicious infrastructure. They don't build their own operations. They scavenge from others.
Stuffy Squirrel:
- Active since at least 2020
- Controls over 500 domains
- Serves malicious JavaScript to visitors
- Sells traffic to ad networks
- Serves decoy content to scanners
Shady Squirrel:
- Active since July 2023
- Controls over 700 domains
- Russian-speaking threat actor
- Sends traffic to initial access brokers
- Distributes SocGholish and tech support scams
- Uses Keitaro servers
Swiping Squirrel:
- Active since 2022
- Controls over 3,000 domains
- Sends traffic to zero-click ad platforms
- Resells traffic for scams or malware
The Scavenger Model
The dropcatch domains malicious infrastructure includes a scavenger model:
How It Works:
- Threat actors buy expired domains
- They immediately start receiving traffic from the previous owner's visitors
- They inject their own content
- They effectively scavenge the previous owner's victims
- The Race:
"The result is a race to acquire victims. The same compromised domain may be redirected by different dropcatch actors depending on website visitor characteristics, timing, and other factors."
Implications for This:
If you manage to get hold of one hacked domain, rest assured that the threat actors have already started on their way to the next one.
High-Profile Dropcatch Domains
Sable Squirrel acquired several notable expired domains:
- healthymagination[.]com – GE's health initiative from 2009
- maxfactor-international[.]com – Procter & Gamble cosmetics brand
- krogeralbertsons[.]com – Domain for the failed Kroger/Albertsons merger
- snsystems[.]com – Former Sony PlayStation developer tools
- rezilion[.]com – Cybersecurity company whose assets were sold to GitLab
- cel-robox[.]com – Former 3D printer company
These domains had established reputations. Once these threat actors gained access to them, they gained the reputation that comes along with these brands.
What Organizations Should Do
Drop Catch Domains Malicious Infrastructure requires preventive measures:
Domain Monitoring:
- Monitor the re-registration of expired domains
- Keep track of domains nearing expiration
- Preventively register critical domains
Security Controls:
- Do not rely on reputation for domains alone
- Multiple IoCs need to be considered
- Watch out for domains exploited within 24 hours
- Block malicious domains from dropcatch
Detection:
- Monitor traffic to newly re-registered domains
- Look for suspicious redirection chains
- Watch for domains serving both streaming and malware
- Wrapping It Up
The dropcatch domains malicious infrastructure is a significant and growing threat. Threat actors are buying up expired domains at scale to inherit reputation and traffic.
Key points to remember:
- 50,000+ dropcatch domains re-registered daily
- Nearly 20% of all new domain registrations
- Domains weaponized within hours
- Sable Squirrel spent $7 million on expired domains
- 31,000 malware samples connected
- Used for illegal streaming, gambling, and malware
Organizations should monitor for re-registered expired domains. Don't rely solely on domain reputation. Block known malicious dropcatch domains.
The dropcatch domains malicious infrastructure is a reminder that trust signals can be counterfeited. Stay vigilant.
FAQ Section
What are dropcatch domains?
Dropcatch domains are expired domains that are re-registered by another party. These domains have their reputations, backlinks, and traffic from their previous lives, thus making them valuable to the attackers.
How do they work for attacks?
They can be utilized to perform various activities such as movie streaming of copyrighted movies, gambling ads, and establishment of malware C2 server. They are weaponized within hours of acquisition, with 24% going live the same day.
Who is Sable Squirrel?
Sable Squirrel is the threat actor who invested almost $7 million in expired domains. It operates a criminal organization covering illegal streaming of sports events, gambling, and malware infrastructure throughout Asia.
How many malware samples are linked to their infrastructure?
A total of 31,000 malware samples have been found to be connected to Sable Squirrel infrastructure and that includes such malware as Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, and HiddenTear ransomware.
What should organizations do?
Monitor for re-registered expired domains. Don't rely solely on domain reputation. Block known malicious dropcatch domains. Use multiple indicators of compromise.