How Cybercriminals Weaponize Expired Domains to Scale Malware and Fraud
forensic metrics here are stark. According to research from Infoblox Threat Intel, reported by IT Pro, roughly 65,000 dropcatch domains are registered per day in the first half of 2026 — nearly one in five of all newly observed domains.
Tobin Carmody·updated August 14, 2026

Within that pipeline, a single threat actor tracked as Sable Squirrel is estimated to have spent more than $7 million acquiring over 10,000 expired domains now serving illegal streaming, online gambling, and malware command-and-control. For domain investors, this is not abstract threat reporting. It is a contamination index that has to be priced into every dropcatch acquisition decision.
The Sable Squirrel Pipeline
Our review of the public data confirms the scale and structure. Sable Squirrel's portfolio funnels traffic toward what appears to be a large Asian sports piracy operation. The sites mimic consumer streaming products — live football, match schedules, chat rooms, mirrors, mobile promotion. Infoblox notes the streaming is the front layer; the underlying business is the betting platforms the group appears to control.
The dual-use architecture matters for anyone analyzing link graphs. Researchers identified over 31,000 malware samples connecting to Sable Squirrel domains, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, and samples carrying HiddenTear ransomware signatures. A human visitor sees a live football stream; an infected device uses the same hostname as a C2 channel. Same domain, two operational layers, one acquisition cost.
A Second Operator and the SocGholish Hand-off
A separate actor tracked as Shady Squirrel was observed handing victims to SocGholish, the "fake update" infrastructure targeted by Operation Endgame in June 2026. Infoblox tracks this group as having previously run scareware and call-center operations before partnering with SocGholish's operator, TA569, in July. This is not opportunistic squatting. It is a structured supply chain moving compromised traffic between branded criminal products.
What We Run on Every Dropcatch Now
Renée Burton, VP at Infoblox Threat Intel, framed the core problem directly: expired domains can be a shortcut to both trust and traffic, making dropcatch domains a higher risk than the average newly-registered domain. We adopt that framing and extend it to the acquisition workflow. When we evaluate a dropcatch, prior-use history is now a liability flag, not a bonus.
The forensic checks we run by default:
- Wayback snapshot pass for any prior pivot to spam, pharma, piracy, or gambling templates.
- DNS history audit against malware blocklists and known C2 feeds.
- Backlink profile review for anchor patterns associated with SocGholish-style fake-update lures.
- Registrar and dropcatch platform record, since prior-use metadata is not surfaced uniformly.
Infoblox puts daily dropcatch registrations at 65,000, with a substantial share pulled for "grey to black purposes." The risk surface for any investor buying into that inventory without server-log-level diligence is no longer theoretical. The $7 million figure is the floor of what one actor deployed into the pipeline. The matching diligence cost is now ours to absorb, or to pay in downstream reputation damage.