One actor spent $7 million acquiring 10,000 expired domains, turning forgotten web addresses into infrastructure for scams and malware.
Every day, tens of thousands of internet domains expire and become available for registration again. Infoblox Threat Intel observed roughly 65,000 re-registered, or “dropcatch,” domains daily during the first half of 2026 — nearly 20% of all newly observed domains each day. Through these purchases, threat actors inherit the trust, backlinks and web traffic built up by a domain’s former owner. Legitimate domains aren’t the only prize: a thriving market also exists for domains with known malicious histories. New research from Infoblox details how dropped domains are being repurposed and identifies several previously undocumented malicious actors.
One investigation identified a threat actor,, dubbed Sable Squirrel by Infoblox, estimated to have spent more than $7 million to acquire over 10,000 expired domains. Those domains now underpin a criminal operation spanning illegal streaming, online gambling, and malware distribution — evidence, researchers say, that expired domains have evolved from forgotten web addresses into valuable cybercriminal infrastructure. Notably, Sable Squirrel runs command-and-control nodes for multiple remote access trojans on the same infrastructure used to host illegal content.
Also Read: Are Banks Losing the Race Against Instant Fraud?Â
Where Sable Squirrel acquires legitimate domains to capture their positive reputation, other threat actors take over domains already flagged as malicious after being embedded in compromised websites. Across three additional newly identified actors, Infoblox found thousands of dropcatch domains embedded in tens of thousands of compromised sites, continuing to direct victims toward malicious payloads.
Most notably, the research identified one actor, tracked as Shady Squirrel, using these tactics to funnel victims toward SocGholish — the “fake update” infrastructure targeted by law enforcement’s Operation Endgame in June 2026. Shady Squirrel delivered malware through scareware and call centers before partnering with SocGholish’s operator, TA569, in July.
“The sheer volume of dropcatch domains is astounding,” said Dr. Renée Burton, vice president of Infoblox Threat Intel. “We’ve known that bad actors buy expired domains to repurpose them, but the way they’re being used, and the amount of money actors are willing to spend, wasn’t well understood. Expired domains can be a shortcut to both trust and traffic, making dropcatch domains a higher risk than the average newly registered domain.”
Also Read: You Gave Your AI Agent Access. Now, What Does It Have?
The research is detailed in a three-part series from Infoblox Threat Intel:
Part 1 explains how dropcatch domains retain trust, reputation and traffic after expiring, creating openings for abuse.
Part 2 details the Sable Squirrel investigation, outlining a criminal operation that invested more than $7 million in expired domains to support illegal streaming, gambling and malware distribution.
Part 3 profiles three additional threat actors — Stuffy Squirrel, Shady Squirrel and Swiping Squirrel — who acquire expired malicious domains to inherit victim traffic from previously compromised websites, redirecting users toward scams, malware and advertising fraud. Together, the three cases illustrate how threat actors profit from infrastructure originally built by other criminals.





