started · updated
Infoblox Threat Intel exposes cybercriminal use of expired domains
Infoblox Threat Intel has revealed that cybercriminals are heavily investing in the mass acquisition of expired internet domains, a practice known as “dropcatching.” During the first half of 2026, researchers observed approximately 65,000 re-registered domains daily, accounting for nearly 20% of all newly observed domains.
By purchasing these domains, threat actors inherit the established trust, backlinks, and web traffic of the previous owners. This allows them to bypass many security hurdles. One identified threat actor, dubbed Sable Squirrel, is estimated to have invested over $7 million to acquire more than 10,000 expired domains to support an ecosystem involving illegal streaming, online gambling, and malware distribution.
In addition to Sable Squirrel, researchers identified other actors, such as Shady Squirrel, who use these domains to deliver malware like SocGholish through scareware and fraudulent tactics. The research highlights a growing market where both previously legitimate domains and known malicious domains are repurposed to serve as critical cybercriminal infrastructure.
Entities
Infoblox Threat Intel · Sable Squirrel · Shady Squirrel · SocGholish