Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains for RAT C2, SocGholish and Streaming-Gambling Fraud
Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains (TL-2026-2022), also tracked as Dropcatch Domain Abuse Campaign, is a high-severity malware campaign, first published 2026-08-15. It is attributed to Sable Squirrel with medium confidence, affects Domain registration ecosystem (GoDaddy, Namecheap, DropCatch.com, maps to 13 MITRE ATT&CK techniques (T1027, T1036.005, T1071.001), and is covered by 9 detection rules and 33 indicators of compromise.
Key facts for TL-2026-2022
- Threat ID
- TL-2026-2022
- Also known as
- Dropcatch Domain Abuse Campaign, Squirrel Scavenger Cluster
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-08-15
- Last reviewed
- 2026-08-15
- Attribution
- Sable Squirrel
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- education, consulting, government administration, health, banking, media-streaming, online-gambling
- Target regions
- vietnam, south korea, japan, taiwan, singapore, australia, united states of america
- Detection rules
- 9
- Indicators of compromise
- 33
Malware and tooling in Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains
Malware and tooling: AsyncRAT, DCRat, HiddenTear, NJRat, NanoCore, Quasar RAT, Remcos, SocGholish - S1124, DCRAT - S9017, Keitaro
Infoblox tracks four financially-motivated 'Squirrel' actors (Sable, Stuffy, Shady, Swiping) that systematically re-register expired domains to inherit their reputation, backlinks and DNS history. Sable Squirrel alone spent ~$7M acquiring 10,000+ domains that now serve dual duty as illegal Vietnamese sports-streaming/gambling fronts and C2 for Quasar RAT, AsyncRAT, DCRat and Remcos RAT, while Shady Squirrel scavenged 700+ former TA2726/other domains to revive SocGholish delivery weeks after Operation Endgame's takedown.
How Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains works
Infoblox Threat Intel's multi-part 'dropcatch' research (published 2026-08-14, covered by Security Affairs on 2026-08-15) documents 65,000 expired domains being re-registered daily across gTLDs and ccTLDs in H1 2026 (~19-20% of all new registrations), concentrated in 15 TLDs. These 'dropcatch' domains retain residual web traffic, backlinks, cached search rankings, email forwarding and lingering DNS/CNAME records from their prior owners, giving buyers instant, laundered trust that new domains lack. Once re-registered, 24% of dropcatch domains are weaponized the same day, 76% within 7 days, and 94% within two weeks.
Four distinct but related actor clusters exploit this pattern. Sable Squirrel (active since at least June 2023, epicenter Vietnam, overlapping the dismantled Xoi Lac TV pirate-streaming network) has spent over $7M on 10,000+ domains -- including aged, high-trust corporate domains such as healthymagination[.]com (GE), krogeralbertsons[.]com, maxfactor-international[.]com (P&G), snsystems[.]com (former Sony PlayStation dev tools) and rezilion[.]com (cybersecurity firm later acquired by GitLab) -- and runs them as illegal sports-streaming brands (Xoilac, Cakhia, 90phut, Socolive, MiTom, ColaTV), online-gambling platforms (VSBet, ColaScore, 8xbet, 6686), and, since November 2025, RAT command-and-control: 405 C2-configured domains and 31,000+ malware samples communicating with them, delivering AsyncRAT 0.5.8, Quasar RAT, DCRat, NanoCore, Remcos RAT, njRAT and non-executing HiddenTear signatures. Malware samples embed the operator's own streaming/gambling brand names in binary metadata (CompanyName 'socoLIVE', ProductName 'xoilac', LegalTrademarks '8xbet') and Windows Run-key persistence, directly linking the malware to the streaming/gambling infrastructure. Roughly 12% of Infoblox's enterprise customers queried Sable Squirrel C2 domains, concentrated in education, IT/consulting, government, healthcare and banking.
Stuffy Squirrel (active since 2020, 500+ domains), Shady Squirrel (Russian-speaking, active since July 2023, 700+ domains) and Swiping Squirrel (active since 2022, 3,000+ domains) instead scavenge domains previously compromised by other intrusion actors (TA2726, Magecart, Balada Injector) and simply inherit the residual infected-site traffic rather than compromising sites themselves. All three run multi-layer cloaking (URL-path matching, server-side TDS filtering, referrer checks, user-interaction gating) so automated scanners see benign content while real visitors are redirected through Keitaro TDS instances into tech-support scams, SocGholish fake-browser-update malware, and zero-click ad-fraud platforms (ZeroPark, PushHouse, ExoClick). Shady Squirrel notably re-enabled SocGholish delivery via a newly registered domain (advanceslibrary[.]com, registered 2026-06-27) roughly ten days after the June 2026 Operation Endgame takedown seized 300+ SocGholish servers and 140 domains, restoring a live fake-update payload by 2026-07-10. Shady Squirrel separately ran an April-July 2026 tech-support-scam operation abusing 10,000+ Microsoft Azure static-web-hosting accounts monthly to display fake Microsoft security warnings with call-center phone numbers targeting Japan and the U.S.
Infoblox's underlying finding: security tooling that grants trust based on domain age, aged backlinks or historical reputation is systematically exploitable by this dropcatch pattern, and orphaned/dangling DNS CNAME records left behind by decommissioned services are a related, compounding hijacking vector (roughly a third of identified dangling CNAMEs were trivially takeable).
MITRE ATT&CK techniques used in TL-2026-2022
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1219 Remote Access Tools
Execution
T1204.002 User Execution: Malicious File
Persistence
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services; T1584.001 Compromise Infrastructure: Domains; T1608.001 Stage Capabilities: Upload Malware; T1608.004 Stage Capabilities: Drive-by Target
Reconnaissance
T1596.001 Search Open Technical Databases: DNS/Passive DNS
stealth
Affected products and versions in Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains
- Domain registration ecosystem (GoDaddy, Namecheap, DropCatch.com, Dynadot) — Expired/lapsed domain registrations acquired via dropcatch
Vulnerable versions: Any domain permitted to lapse and become available for third-party re-registration, particularly aged domains carrying residual reputation, backlinks, cached search rankings, or lingering DNS/CNAME records
Fixed in: N/A - mitigated operationally via registrar auto-renewal, active domain-portfolio monitoring, and DNS/CNAME record cleanup at decommissioning, not a vendor patch - Multiple prior domain owners (General Electric, Procter & Gamble, Kroger-Albertsons, Sony, Rezilion/GitLab, veinteractive) — Previously-owned corporate/brand domains that lapsed and were re-registered by Sable Squirrel
Vulnerable versions: healthymagination[.]com, maxfactor-international[.]com, krogeralbertsons[.]com, snsystems[.]com, rezilion[.]com, veinteractive[.]com and similar lapsed brand domains
Fixed in: N/A - domains were not renewed by their original owners
Remediation for Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains
Immediate actions
- Block/alert on DNS resolution and network egress to the identified Sable/Stuffy/Shady/Swiping Squirrel domain IOCs
- Audit outbound traffic for connections to newly re-registered ('dropcatch') domains, especially ones resolving within days of a WHOIS/registrar change
- Inventory and remove dangling CNAME/DNS records pointing to decommissioned, expired, or third-party-hosted resources the organization no longer controls
Workarounds
- User-awareness training on fake browser-update prompts (SocGholish) and unsolicited tech-support pop-ups/call-center numbers
- Block known Sable Squirrel streaming/gambling and Shady Squirrel tech-support-scam phone numbers and redirect chains at the web proxy where cloaked redirection is suspected
Longer-term hardening
- Enable registrar auto-renewal and pre-expiration alerting for all organization-owned domains, including retired legacy/brand/campaign domains that are no longer actively used but still carry brand trust
- Deploy continuous DNS hygiene monitoring to detect orphaned CNAME/A records before the underlying domain or cloud resource lapses
- Reduce reliance on raw domain-age/historical-reputation signals in web-filtering and email-security tooling; treat aged domains that recently changed registrant/nameservers as elevated risk
- Formally deprovision DNS entries and notify downstream integrators when decommissioning a domain or cloud-hosted service
Weaknesses (CWE) in Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains
CWE-706
Timeline of Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains
- Stuffy Squirrel begins operating dropcatch/scavenger domain infrastructure (first of three infrastructure generations).
- Swiping Squirrel begins acquiring dropcatch domains to sell traffic into zero-click ad-fraud platforms.
- Sable Squirrel activity begins, epicentered in Vietnam and overlapping the Xoi Lac TV illegal sports-streaming network.
- Shady Squirrel begins operating Russian-speaking dropcatch/scavenger infrastructure feeding tech-support scams and SocGholish.
- Sable Squirrel begins early testing of Quasar RAT on dropcatch domain infrastructure.
- First AsyncRAT 0.5.8 sample observed communicating with Sable Squirrel C2 infrastructure; first C2 configurations appear on dropcatch domains.
- Mass C2 deployment wave: 86% of Sable Squirrel's identified malware-C2-configured domains go live.
- Xoi Lac TV flagship illegal-streaming properties frozen amid an organized-crime enforcement action in Vietnam.
- 30 suspects charged and roughly 300 billion VND (~$12M) in assets seized in the Xoi Lac TV crackdown; DCRat sample volume surges (7,610 samples) in the aftermath.
- Pre-World Cup spike: 12% of Sable Squirrel's dropcatch domain acquisitions concentrate ahead of the 2026 FIFA World Cup.
- Operation Endgame disrupts SocGholish infrastructure, seizing over 300 servers and 140 domains.
- Shady Squirrel registers advanceslibrary[.]com to rebuild SocGholish delivery capability roughly ten days after Operation Endgame.
- A live fake browser-update payload confirms Shady Squirrel's restored SocGholish delivery chain is operational.
- Infoblox publishes multi-part threat intelligence research documenting Sable, Stuffy, Shady and Swiping Squirrel dropcatch campaigns.
- Security Affairs and other outlets report on the Infoblox dropcatch domain research, surfacing it for SOC detection coverage.
Sources cited for Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains
- Crooks are buying your expired domains and using them to deliver malware
- Illegal Streaming Fronts a $7M Dropcatch Domain Operation
- Expired Malicious Domains Bring New Threats to Life
- The Second Life of Expired Domains
- Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
- Infoblox research finds 65,000 expired domains re-registered daily in first half of 2026
- Cybercriminals invest millions in expired domains for illicit activities
- Expired domains are a goldmine for hackers
Threats related to Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains
- Expired-Domain Resale Abuse Fuels Malware Delivery: Sable Squirrel and Scavenger Threat Clusters (Quasar RAT, AsyncRAT, DCRat, Remcos RAT, SocGholish)
- Malware Distribution Platform Exposed via Unsecured /install/install.php Setup Page (micronsoftwares[.]com / wetransfer[.]ICU SEO-Poisoning Operation)
- Fake Corepack.org Site Distributes OpenShield Infostealer/Proxyware to Developers; Secondary Malvertising Chain Delivers OperaGXSetup.exe Adware
Detection coverage for TL-2026-2022
As of 2026-08-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2022 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.