Home » Emerging Technologies » Cyber Security » Hackers Spend Millions Buying Expired Domains
News Desk -

Share

Cybercriminals are spending millions of dollars on expired domains to run scams, spread malware and stream illegal content, according to new research from Infoblox Threat Intel.

Every day, tens of thousands of internet domains expire and become available for registration again. Infoblox Threat Intel tracked roughly 65,000 re-registered, or “dropcatch,” domains daily during the first half of 2026. As a result, dropcatch domains now make up nearly 20% of all newly observed domains each day.

Consequently, when threat actors buy these domains, they also inherit the trust, backlinks and web traffic built up by the previous owner. Meanwhile, a parallel market has emerged for domains that are already known to be malicious. Together, these two trends form the basis of the new findings.

The research exposes several threat actors who had not been identified before. It also shows how dropped domains are being repurposed for large-scale criminal operations.

In one case, researchers uncovered a threat actor named Sable Squirrel. This group has reportedly invested more than $7 million to acquire over 10,000 expired domains. Those domains now support a wide criminal network that includes illegal streaming, online gambling and malware distribution. Notably, Sable Squirrel runs command-and-control servers for several remote access trojans on the very same infrastructure used for illegal content.

While Sable Squirrel targets legitimate domains for their positive reputation, other actors take a different approach. Instead, they seize well-known malicious domains that had already been planted on compromised websites. Infoblox Threat Intel identified three additional threat actors using this method. Together, they control thousands of dropcatch domains embedded across tens of thousands of hacked websites, which continue to redirect victims toward malicious payloads.

One of these actors, tracked as Shady Squirrel, stood out in particular. This group used scareware and call centers to deliver malware before eventually partnering with TA569, the operator behind SocGholish. SocGholish is a well-known “fake update” infrastructure that was the target of Operation Endgame in June 2026. Shady Squirrel began funneling victims toward SocGholish in July.

“The sheer volume of dropcatch domains is astounding,” said Dr. Renée Burton, VP of Infoblox Threat Intel. “We’ve known that bad guys buy expired domains to repurpose them, but the way in which they were used, and the amount of money actors are willing to spend, wasn’t well understood.”

She added that expired domains can act as a shortcut to both trust and traffic, which makes dropcatch domains riskier than the average newly registered domain.

The findings are laid out in a three-part series published by Infoblox Threat Intel. The first part explains how dropcatch domains retain trust, reputation and traffic after expiring, and how that creates opportunities for abuse. The second part details the Sable Squirrel investigation and its $7 million streaming and gambling operation. The third part profiles three more threat actors, Stuffy Squirrel, Shady Squirrel and Swiping Squirrel, who acquire expired malicious domains to inherit victim traffic and redirect users toward scams, malware and advertising fraud.

Taken together, the three reports show a clear pattern. Threat actors are increasingly profiting from infrastructure that other criminals built first, using expired domains as a low-cost, high-trust foothold for their operations.