CISO Middle East Issue 03 | Page 31

E internet domains expire and become available for registration again. Infoblox Threat Intel observed approximately 65,000 re-registered, or‘ dropcatch’, domains every day during the first half of 2026, accounting for nearly 20 % of all newly observed domains.
CYBERCRIME

Infoblox Threat Intel exposes the criminal afterlife of expired domains

very day, tens of thousands of

E internet domains expire and become available for registration again. Infoblox Threat Intel observed approximately 65,000 re-registered, or‘ dropcatch’, domains every day during the first half of 2026, accounting for nearly 20 % of all newly observed domains.

By acquiring these domains, threat actors can inherit the trust, backlinks and web traffic associated with their former owners. While previously legitimate domains are attractive targets, researchers have also identified a thriving market for known malicious domains. New research from Infoblox Threat Intel examines how these expired domains are being repurposed and has uncovered several previously unknown threat actors.
One investigation identified a threat actor dubbed Sable Squirrel, which researchers estimate has invested more than $ 7 million acquiring over 10,000 expired domains. The domains support a criminal ecosystem spanning illegal streaming, online gambling and malware distribution, demonstrating how expired domains have evolved from forgotten web addresses into valuable cybercriminal infrastructure. Sable Squirrel also operates commandand-control nodes for multiple remote access trojans on the same infrastructure used to host illegal content.
The sheer volume of dropcatch domains is astounding. We’ ve known that bad guys buy expired domains to repurpose them, but the way in which they were used, and the amount of money actors are willing to spend wasn’ t well understood.
While Sable Squirrel acquires legitimate domains to take advantage of their established reputations, other threat actors are taking over known malicious domains previously embedded within compromised websites. Across three additional newly identified threat actors, Infoblox Threat Intel discovered thousands of dropcatch domains embedded in tens of thousands of compromised websites that continue to direct victims towards malicious payloads.
Most notably, the research uncovered an actor using these tactics to direct potential victims to SocGholish, the notorious‘ fake update’ infrastructure targeted by Operation Endgame in June 2026. The threat actor, tracked by Infoblox Threat Intel as Shady Squirrel, delivered malware through scareware and call centres before partnering with SocGholish operator TA569 in July.
“ The sheer volume of dropcatch domains is astounding. We’ ve known that bad guys buy expired domains to repurpose them, but the way in which they were used, and the amount of money actors are willing to spend wasn’ t well understood,” said Dr Renée Burton, VP of Infoblox Threat Intel.“ Expired domains can be a shortcut to both trust and traffic, making dropcatch
Dr Renée Burton, VP of Infoblox Threat Intel
domains a higher risk than the average newly registered domain.”
The research is detailed in a three-part series from Infoblox Threat Intel. Part one explains how dropcatch domains retain trust, reputation and traffic after expiring, creating opportunities for abuse. Part two examines the Sable Squirrel investigation, revealing an operation that invested more than $ 7 million in expired domains to support illegal streaming, gambling and malware.
The third part profiles three additional threat actors, Stuffy Squirrel, Shady Squirrel and Swiping Squirrel. These actors acquire expired malicious domains to inherit victim traffic from previously compromised websites, redirecting users towards scams, malware and advertising fraud. Together, the findings demonstrate how cybercriminals are increasingly profiting from infrastructure originally established by other threat actors.
WWW. INTELLIGENTCISO. COM / MIDDLE-EAST 31