Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains for RAT C2, SocGholish and Streaming-Gambling Fraud

Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains (TL-2026-2022), also tracked as Dropcatch Domain Abuse Campaign, is a high-severity malware campaign, first published 2026-08-15. It is attributed to Sable Squirrel with medium confidence, affects Domain registration ecosystem (GoDaddy, Namecheap, DropCatch.com, maps to 13 MITRE ATT&CK techniques (T1027, T1036.005, T1071.001), and is covered by 9 detection rules and 33 indicators of compromise.

Key facts for TL-2026-2022

Threat ID
TL-2026-2022
Also known as
Dropcatch Domain Abuse Campaign, Squirrel Scavenger Cluster
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-08-15
Last reviewed
2026-08-15
Attribution
Sable Squirrel
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
education, consulting, government administration, health, banking, media-streaming, online-gambling
Target regions
vietnam, south korea, japan, taiwan, singapore, australia, united states of america
Detection rules
9
Indicators of compromise
33

Malware and tooling in Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains

Malware and tooling: AsyncRAT, DCRat, HiddenTear, NJRat, NanoCore, Quasar RAT, Remcos, SocGholish - S1124, DCRAT - S9017, Keitaro

Infoblox tracks four financially-motivated 'Squirrel' actors (Sable, Stuffy, Shady, Swiping) that systematically re-register expired domains to inherit their reputation, backlinks and DNS history. Sable Squirrel alone spent ~$7M acquiring 10,000+ domains that now serve dual duty as illegal Vietnamese sports-streaming/gambling fronts and C2 for Quasar RAT, AsyncRAT, DCRat and Remcos RAT, while Shady Squirrel scavenged 700+ former TA2726/other domains to revive SocGholish delivery weeks after Operation Endgame's takedown.

How Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains works

Infoblox Threat Intel's multi-part 'dropcatch' research (published 2026-08-14, covered by Security Affairs on 2026-08-15) documents 65,000 expired domains being re-registered daily across gTLDs and ccTLDs in H1 2026 (~19-20% of all new registrations), concentrated in 15 TLDs. These 'dropcatch' domains retain residual web traffic, backlinks, cached search rankings, email forwarding and lingering DNS/CNAME records from their prior owners, giving buyers instant, laundered trust that new domains lack. Once re-registered, 24% of dropcatch domains are weaponized the same day, 76% within 7 days, and 94% within two weeks.

Four distinct but related actor clusters exploit this pattern. Sable Squirrel (active since at least June 2023, epicenter Vietnam, overlapping the dismantled Xoi Lac TV pirate-streaming network) has spent over $7M on 10,000+ domains -- including aged, high-trust corporate domains such as healthymagination[.]com (GE), krogeralbertsons[.]com, maxfactor-international[.]com (P&G), snsystems[.]com (former Sony PlayStation dev tools) and rezilion[.]com (cybersecurity firm later acquired by GitLab) -- and runs them as illegal sports-streaming brands (Xoilac, Cakhia, 90phut, Socolive, MiTom, ColaTV), online-gambling platforms (VSBet, ColaScore, 8xbet, 6686), and, since November 2025, RAT command-and-control: 405 C2-configured domains and 31,000+ malware samples communicating with them, delivering AsyncRAT 0.5.8, Quasar RAT, DCRat, NanoCore, Remcos RAT, njRAT and non-executing HiddenTear signatures. Malware samples embed the operator's own streaming/gambling brand names in binary metadata (CompanyName 'socoLIVE', ProductName 'xoilac', LegalTrademarks '8xbet') and Windows Run-key persistence, directly linking the malware to the streaming/gambling infrastructure. Roughly 12% of Infoblox's enterprise customers queried Sable Squirrel C2 domains, concentrated in education, IT/consulting, government, healthcare and banking.

Stuffy Squirrel (active since 2020, 500+ domains), Shady Squirrel (Russian-speaking, active since July 2023, 700+ domains) and Swiping Squirrel (active since 2022, 3,000+ domains) instead scavenge domains previously compromised by other intrusion actors (TA2726, Magecart, Balada Injector) and simply inherit the residual infected-site traffic rather than compromising sites themselves. All three run multi-layer cloaking (URL-path matching, server-side TDS filtering, referrer checks, user-interaction gating) so automated scanners see benign content while real visitors are redirected through Keitaro TDS instances into tech-support scams, SocGholish fake-browser-update malware, and zero-click ad-fraud platforms (ZeroPark, PushHouse, ExoClick). Shady Squirrel notably re-enabled SocGholish delivery via a newly registered domain (advanceslibrary[.]com, registered 2026-06-27) roughly ten days after the June 2026 Operation Endgame takedown seized 300+ SocGholish servers and 140 domains, restoring a live fake-update payload by 2026-07-10. Shady Squirrel separately ran an April-July 2026 tech-support-scam operation abusing 10,000+ Microsoft Azure static-web-hosting accounts monthly to display fake Microsoft security warnings with call-center phone numbers targeting Japan and the U.S.

Infoblox's underlying finding: security tooling that grants trust based on domain age, aged backlinks or historical reputation is systematically exploitable by this dropcatch pattern, and orphaned/dangling DNS CNAME records left behind by decommissioned services are a related, compounding hijacking vector (roughly a third of identified dangling CNAMEs were trivially takeable).

MITRE ATT&CK techniques used in TL-2026-2022

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1219 Remote Access Tools

Execution

T1204.002 User Execution: Malicious File

Persistence

T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services; T1584.001 Compromise Infrastructure: Domains; T1608.001 Stage Capabilities: Upload Malware; T1608.004 Stage Capabilities: Drive-by Target

Reconnaissance

T1596.001 Search Open Technical Databases: DNS/Passive DNS

stealth

T1684.001 Impersonation

Affected products and versions in Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains

  • Domain registration ecosystem (GoDaddy, Namecheap, DropCatch.com, Dynadot) — Expired/lapsed domain registrations acquired via dropcatch
    Vulnerable versions: Any domain permitted to lapse and become available for third-party re-registration, particularly aged domains carrying residual reputation, backlinks, cached search rankings, or lingering DNS/CNAME records
    Fixed in: N/A - mitigated operationally via registrar auto-renewal, active domain-portfolio monitoring, and DNS/CNAME record cleanup at decommissioning, not a vendor patch
  • Multiple prior domain owners (General Electric, Procter & Gamble, Kroger-Albertsons, Sony, Rezilion/GitLab, veinteractive) — Previously-owned corporate/brand domains that lapsed and were re-registered by Sable Squirrel
    Vulnerable versions: healthymagination[.]com, maxfactor-international[.]com, krogeralbertsons[.]com, snsystems[.]com, rezilion[.]com, veinteractive[.]com and similar lapsed brand domains
    Fixed in: N/A - domains were not renewed by their original owners

Remediation for Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains

Immediate actions

  • Block/alert on DNS resolution and network egress to the identified Sable/Stuffy/Shady/Swiping Squirrel domain IOCs
  • Audit outbound traffic for connections to newly re-registered ('dropcatch') domains, especially ones resolving within days of a WHOIS/registrar change
  • Inventory and remove dangling CNAME/DNS records pointing to decommissioned, expired, or third-party-hosted resources the organization no longer controls

Workarounds

  • User-awareness training on fake browser-update prompts (SocGholish) and unsolicited tech-support pop-ups/call-center numbers
  • Block known Sable Squirrel streaming/gambling and Shady Squirrel tech-support-scam phone numbers and redirect chains at the web proxy where cloaked redirection is suspected

Longer-term hardening

  • Enable registrar auto-renewal and pre-expiration alerting for all organization-owned domains, including retired legacy/brand/campaign domains that are no longer actively used but still carry brand trust
  • Deploy continuous DNS hygiene monitoring to detect orphaned CNAME/A records before the underlying domain or cloud resource lapses
  • Reduce reliance on raw domain-age/historical-reputation signals in web-filtering and email-security tooling; treat aged domains that recently changed registrant/nameservers as elevated risk
  • Formally deprovision DNS entries and notify downstream integrators when decommissioning a domain or cloud-hosted service

Weaknesses (CWE) in Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains

CWE-706

Timeline of Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains

  • Stuffy Squirrel begins operating dropcatch/scavenger domain infrastructure (first of three infrastructure generations).
  • Swiping Squirrel begins acquiring dropcatch domains to sell traffic into zero-click ad-fraud platforms.
  • Sable Squirrel activity begins, epicentered in Vietnam and overlapping the Xoi Lac TV illegal sports-streaming network.
  • Shady Squirrel begins operating Russian-speaking dropcatch/scavenger infrastructure feeding tech-support scams and SocGholish.
  • Sable Squirrel begins early testing of Quasar RAT on dropcatch domain infrastructure.
  • First AsyncRAT 0.5.8 sample observed communicating with Sable Squirrel C2 infrastructure; first C2 configurations appear on dropcatch domains.
  • Mass C2 deployment wave: 86% of Sable Squirrel's identified malware-C2-configured domains go live.
  • Xoi Lac TV flagship illegal-streaming properties frozen amid an organized-crime enforcement action in Vietnam.
  • 30 suspects charged and roughly 300 billion VND (~$12M) in assets seized in the Xoi Lac TV crackdown; DCRat sample volume surges (7,610 samples) in the aftermath.
  • Pre-World Cup spike: 12% of Sable Squirrel's dropcatch domain acquisitions concentrate ahead of the 2026 FIFA World Cup.
  • Operation Endgame disrupts SocGholish infrastructure, seizing over 300 servers and 140 domains.
  • Shady Squirrel registers advanceslibrary[.]com to rebuild SocGholish delivery capability roughly ten days after Operation Endgame.
  • A live fake browser-update payload confirms Shady Squirrel's restored SocGholish delivery chain is operational.
  • Infoblox publishes multi-part threat intelligence research documenting Sable, Stuffy, Shady and Swiping Squirrel dropcatch campaigns.
  • Security Affairs and other outlets report on the Infoblox dropcatch domain research, surfacing it for SOC detection coverage.

Sources cited for Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains

Threats related to Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains

Detection coverage for TL-2026-2022

As of 2026-08-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2022 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats