How Malware Operators Are Outbidding Investors for High-Authority Expired Domains
According to TechRadar, security researchers at Infoblox traced more than 10,000 domains to a single actor they call Sable Squirrel.
Corinne Talbot·updated August 23, 2026

$7 Million in Expired Domains — Bought by a Malware Operation
When I read that a threat actor spent an estimated $7 million acquiring expired domains, my first thought wasn't about the malware. It was about the competition.
The operation specifically targeted expired domains that still carried inherited traffic, backlinks, and search reputation — the exact same signals you and I look for when evaluating drop-catch inventory.
What Sable Squirrel Actually Did
The mechanics are worth understanding, even if you'd never touch this side of the market. Infoblox found that the acquired domains served dual purposes: some continued to function as legitimate-looking web properties, leveraging the authority they'd built under previous owners, while others quietly operated as malware command-and-control infrastructure.
This is the part that should make you pause. The $7 million figure is an estimate of what one actor spent on expired-domain acquisitions alone. That's institutional-level budget flowing through the same auction houses and drop-catching services you use. When you're bidding against someone willing to spend seven figures on domain inventory for infrastructure purposes, it changes the competitive landscape in ways most investors don't account for.
Why This Matters for Your Portfolio
I've written before about due diligence on expired domains — checking backlink profiles, verifying traffic claims, understanding what you're actually buying. This case adds another layer: the domains you're competing for may also be targets for actors with very different end goals.
The inherited authority that makes an expired domain valuable to a legitimate buyer — clean backlink profile, residual organic traffic, niche relevance — is exactly what makes it attractive for malware distribution. That shared demand profile means you're not just competing with other investors and end-users. You're occasionally bidding against operations with seven-figure budgets and no need for the domain to generate legitimate ROI.
Meanwhile, the legitimate side of the market continues its steady pace. Nameshift reported 25 domain sales during the August 10–16 period, with Megatech.eu leading at €3,500. The top ten sales totaled €14,285, with.NL domains showing the strongest representation. Real transactions between real buyers — the kind of activity that keeps portfolios liquid and pricing transparent.
What I'd Take From This
Three things, if you're actively buying expired inventory:
Check the history harder. If a domain you're eyeing has a murky ownership gap or was previously held by a known threat actor, that history can surface in security databases and affect future resale conversations.
Understand your competition depth. Seven-figure spending on expired domains by a single actor suggests the market for authority-rich names is deeper than most investors assume. Price your acquisitions accordingly — and don't assume you're the only one who spotted that clean backlink profile.
Don't ignore DNS and hosting signals. If a domain's previous records show suspicious patterns or its backlink profile includes links from compromised sites, that's not just a red flag — it's a potential liability for your portfolio's reputation with future buyers.
The expired-domain market rewards those who do their homework. Cases like this one just raise the bar on what "homework" actually means.