Sable Squirrel and the $7M Expired Domain Economy Fueling Malware Distribution

expired domains malware economy Sable Squirrel domain dropcatching threat intelligence

An old address on the internet can appear far more trustworthy than a brand-new one – even after its original owner has long since abandoned it. In a series of reports, researchers at Infoblox have mapped out an entire shadow economy built around expired domains. Threat actors are systematically acquiring web addresses with years of established history, inheriting their residual traffic and the trust that security systems have accumulated toward them, and then repurposing those acquisitions for fraud: distributing malware, running illegal streaming operations, and promoting online gambling.

A Market of Staggering Scale

The scale of this market proved substantial. During the first half of 2026, Infoblox recorded more than 50,000 domain re-registrations daily within generic top-level domains alone – a figure that climbed to nearly 65,000 once country-code domains were included. Roughly 20% of new registrations in generic top-level domains involved addresses that had previously belonged to other owners. Domains become available for re-registration when companies close, projects wind down, or renewal payments simply lapse.

Why an Old Domain Is Worth More Than Its Name

The value of an aged domain extends well beyond the name itself. Once a domain is re-registered, existing backlinks, residual visitor traffic, and accumulated reputation frequently persist. Security systems that factor in domain age and history often treat such an address as inherently less suspicious than an entirely new one. In some cases, legacy infrastructure continues reaching out to the domain automatically, entirely unaware that ownership has changed hands.

Sable Squirrel: A $7 Million Domain Acquisition Operation

Infoblox linked one particularly large-scale scheme to a group tracked as Sable Squirrel, which controls more than 10,000 domains. Infoblox confirmed that the group purchased approximately 160 expired domains for over $430,000, with the group’s total spending on such domains estimated at more than $7 million overall. The acquired addresses had previously belonged to media outlets, businesses, nonprofit organizations, sports projects, and other entirely legitimate former owners.

Sable Squirrel leverages this infrastructure to operate illegal sports streaming services and promote gambling to audiences in Vietnam and other countries. Critically, however, a portion of those same domains simultaneously serve infected devices. Infoblox identified more than 31,000 malware samples communicating with domains under the group’s control – including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, and samples bearing the signatures of the HiddenTear ransomware family.

Inheriting Compromised Infrastructure: Stuffy Squirrel and Shady Squirrel

A separate scheme has emerged among groups that specifically acquire domains previously controlled by other threat actors. Compromised websites can retain old malicious code for years, continuing to send outbound requests to that address long after ownership changes. Infoblox documented how new owners inherit a ready-made stream of visitors without ever needing to compromise the sites themselves, subsequently redirecting that traffic toward advertising, fraudulent pages, or additional malware. Infoblox named Stuffy Squirrel and Shady Squirrel among the operators running this particular playbook.

Long-Running Operations Built to Evade Detection

Certain schemes have persisted for years, deliberately engineered to slip past automated scanning tools. Stuffy Squirrel has been active since at least 2020 and now controls over 500 domains. Shady Squirrel, meanwhile, redirected visitors toward fraudulent technical support scams throughout 2026 before pivoting to distribute SocGholish malware traffic.

According to Infoblox’s assessment, a lapsed domain today can retain not only its former reputation but also a ready-made audience – meaning a forgotten internet address is fully capable of becoming a valuable asset for an entirely different, and often malicious, owner.

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Leave a Reply