Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains for RAT C2, SocGholish and Streaming-Gambling Fraud — Threadlinqs Intelligence
As of 2026-08-15, Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains for RAT C2, SocGholish and Streaming-Gambling Fraud is a high-severity malware threat attributed to Sable Squirrel, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 33 indicators of compromise.
Threat ID: TL-2026-2022 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Sable Squirrel · FINANCIAL
Infoblox tracks four financially-motivated 'Squirrel' actors (Sable, Stuffy, Shady, Swiping) that systematically re-register expired domains to inherit their reputation, backlinks and DNS history.
Infoblox Threat Intel's multi-part 'dropcatch' research (published 2026-08-14, covered by Security Affairs on 2026-08-15) documents 65,000 expired domains being re-registered daily across gTLDs and ccTLDs in H1 2026 (~19-20% of all new registrations), concentrated in 15 TLDs. These 'dropcatch' domains retain residual web traffic, backlinks, cached search rankings, email forwarding and lingering DNS/CNAME records from their prior owners, giving buyers instant, laundered trust that new domains lack. Once re-registered, 24% of dropcatch domains are weaponized the same day, 76% within 7 days, and 94% within two weeks.
Four distinct but related actor clusters exploit this pattern. Sable Squirrel (active since at least June 2023, epicenter Vietnam, overlapping the dismantled Xoi Lac TV pirate-streaming network) has spent over $7M on 10,000+ domains -- including aged, high-trust corporate domains such as healthymagination[.]com (GE), krogeralbertsons[.]com, maxfactor-international[.]com (P&G), snsystems[.]com (former Sony PlayStation dev tools) and rezilion[.]com (cybersecurity firm later acquired by GitLab) -- and runs them as illegal sports-streaming brands (Xoilac, Cakhia, 90phut, Socolive, MiTom, ColaTV), online-gambling platforms (VSBet, ColaScore, 8xbet, 6686), and, since November 2025, RAT command-and-control: 405 C2-configured domains and 31,000+ malware samples communicating with them, delivering AsyncRAT 0.5.8, Quasar RAT, DCRat, NanoCore, Remcos RAT, njRAT and non-executing HiddenTear signatures. Malware samples embed the operator's own streaming/gambling brand names in binary metadata (CompanyName 'socoLIVE', ProductName 'xoilac', LegalTrademarks '8xbet') and Windows Run-key persistence, directly linking the malware to the streaming/gambling infrastructure. Roughly 12% of Infoblox's enterprise customers queried Sable Squirrel C2 domains, concentrated in education, IT/consulting, government, healthcare and banking.
Stuffy Squirrel (active since 2020, 500+ domains), Shady Squirrel (Russian-speaking, active since July 2023, 700+ domains) and Swiping Squirrel (active since 2022, 3,000+ domains) instead scavenge domains previously compromised by other intrusion actors (TA2726, Magecart, Balada Injector) and simply inherit the residual infected-site traffic rather than compromising sites themselves. All three run multi-layer cloaking (URL-path matching, server-side TDS filtering, referrer checks, user-interaction gating) so automated scanners see benign content while real visitors are redirected through Keitaro TDS instances into tech-support scams, SocGholish fake-browser-update malware, and zero-click ad-fraud platforms (ZeroPark, PushHouse, ExoClick). Shady Squirrel notably re-enabled SocGholish delivery via a newly registered domain (advanceslibrary[.]com, registered 2026-06-27) roughly ten days after the June 2026 Operation Endgame takedown seized 300+ SocGholish servers and 140 domains, restoring a live fake-update payload by 2026-07-10. Shady Squirrel separately ran an April-July 2026 tech-support-scam operation abusing 10,000+ Microsoft Azure static-web-hosting accounts monthly to display fake Microsoft security warnings with call-center phone numbers targeting Japan and the U.S.
Infoblox's underlying finding: security tooling that grants trust based on domain age, aged backlinks or historical reputation is systematically exploitable by this dropcatch pattern, and orphaned/dangling DNS CNAME records left behind by decommissioned services are a related, compounding hijacking vector (roughly a third of identified dangling CNAMEs were trivially takeable).
Target sectors: education, consulting, government administration, health, banking, media-streaming, online-gambling
Target regions: vietnam, south korea, japan, taiwan, singapore, australia, united states of america
Timeline
- Stuffy Squirrel begins operating dropcatch/scavenger domain infrastructure (first of three infrastructure generations).
- Swiping Squirrel begins acquiring dropcatch domains to sell traffic into zero-click ad-fraud platforms.
- Sable Squirrel activity begins, epicentered in Vietnam and overlapping the Xoi Lac TV illegal sports-streaming network.
- Shady Squirrel begins operating Russian-speaking dropcatch/scavenger infrastructure feeding tech-support scams and SocGholish.
- Sable Squirrel begins early testing of Quasar RAT on dropcatch domain infrastructure.
- First AsyncRAT 0.5.8 sample observed communicating with Sable Squirrel C2 infrastructure; first C2 configurations appear on dropcatch domains.
- Mass C2 deployment wave: 86% of Sable Squirrel's identified malware-C2-configured domains go live.
- Xoi Lac TV flagship illegal-streaming properties frozen amid an organized-crime enforcement action in Vietnam.
- 30 suspects charged and roughly 300 billion VND (~$12M) in assets seized in the Xoi Lac TV crackdown; DCRat sample volume surges (7,610 samples) in the aftermath.
- Pre-World Cup spike: 12% of Sable Squirrel's dropcatch domain acquisitions concentrate ahead of the 2026 FIFA World Cup.
- Operation Endgame disrupts SocGholish infrastructure, seizing over 300 servers and 140 domains.
- Shady Squirrel registers advanceslibrary[.]com to rebuild SocGholish delivery capability roughly ten days after Operation Endgame.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 33 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1596.001, T1583.001, T1584.001, T1608.001, T1608.004, T1583.006, T1684.001, T1204.002, T1547.001, T1071.001