started · updated
Threat actors spend millions on expired domains for malware
Threat actors are investing millions of dollars to acquire expired “dropcatch” domains to facilitate malware distribution, illegal gambling, and scam campaigns. Research from Infoblox Threat Intel indicates that in the first half of 2026, approximately 65,000 re-registered domains were observed daily, accounting for nearly 20% of all newly observed domains.
By purchasing these expired domains, attackers exploit the inherited reputation, backlinks, and web traffic accumulated by previous owners. This history can cause security products and reputation-based algorithms to view the domains more favorably than brand-new registrations. High rates of dropcatch activity are noted in .net and .xyz extensions, with .net and .xyz seeing nearly 30% of new registrations being previously registered domains.
Specific threat actors have been identified using this method. One actor, dubbed Sable Squirrel, is estimated to have spent over US$7 million to acquire more than 10,000 expired domains to support a criminal ecosystem. Another actor, Shady Squirrel, has been linked to the SocGholish “fake update” infrastructure. Other profiled actors include Stuffy Squirrel and Swiping Squirrel, who use compromised websites to redirect victims toward advertising fraud and scams.