Expired-Domain Resale Abuse Fuels Malware Delivery: Sable Squirrel and Scavenger Threat Clusters (Quasar RAT, AsyncRAT, DCRat, Remcos RAT, SocGholish)
Expired-Domain Resale Abuse Fuels Malware Delivery (TL-2026-2033), also tracked as Dropcatch Domains Campaign, is a medium-severity malware campaign, first published 2026-08-16. It is attributed to Sable Squirrel with medium confidence, affects Domain Registrars / Backorder Marketplaces (GoDaddy, DropCatch.com, maps to 12 MITRE ATT&CK techniques (T1027, T1036.005, T1082), and is covered by 9 detection rules and 24 indicators of compromise.
Key facts for TL-2026-2033
- Threat ID
- TL-2026-2033
- Also known as
- Dropcatch Domains Campaign, Domain Reputation Hijacking Campaign
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-08-16
- Last reviewed
- 2026-08-16
- Attribution
- Sable Squirrel
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- news - media, entertainment, gambling, consumer, education, government administration, health, financial services, retail e-commerce, information technology
- Target regions
- vietnam, south korea, japan, australia, taiwan, singapore, indonesia, russia, united states of america
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in Expired-Domain Resale Abuse Fuels Malware Delivery
Malware and tooling: AsyncRAT, DCRat, HiddenTear, NJRat, NanoCore, Quasar RAT, Remcos, SocGholish - S1124, DCRAT - S9017, Keitaro TDS
Infoblox Threat Intel documents four affiliated dropcatch-domain actors — Sable Squirrel (10,000+ domains, ~$7M spent) and the Scavenger cluster (Stuffy Squirrel, Shady Squirrel, Swiping Squirrel) — that systematically buy or backorder expired domains to inherit residual reputation, traffic, and DNS history for illegal-streaming malware delivery, SocGholish fake-update campaigns, and tech-support scams. Sable Squirrel's Xoilac/Cakhia/90phut/Socolive/MiTom streaming platforms double as C2 for Quasar RAT, AsyncRAT, DCRat, and Remcos RAT across Vietnam, South Korea, Japan, and Australia, while Shady Squirrel resupplied SocGholish with victim traffic within 10 days of Operation Endgame's June 2026 takedown.
How Expired-Domain Resale Abuse Fuels Malware Delivery works
Infoblox Threat Intel's three-part "Dropcatch Domains" research series (published 2026-08-13, syndicated by SecurityAffairs, The Hacker News, IT Pro, and SC Media on 2026-08-14/15) documents an industrial-scale abuse of expired-domain re-registration ("dropcatching"): roughly 65,000 expired domains are re-registered daily in H1 2026 — nearly 20% of all newly observed domains — because expired domains retain backlinks, search-engine trust, cached traffic, and DNS history that criminals can immediately weaponize instead of building reputation from scratch.
The report attributes the largest single dropcatch operation to Sable Squirrel, a well-funded, likely transnational actor with a Vietnamese operational focus. Sable Squirrel controls more than 10,000 domains and has an extrapolated spend exceeding $7 million (confirmed: 160+ purchases, $430K+ documented) through GoDaddy, DropCatch.com, Namecheap, and Dynadot. Median domain activation is 5 days post-purchase, with 24% live same-day, 76% within a week, and 94% within two weeks. Premium acquisitions included brand-name domains with residual trust (healthymagination[.]com — formerly a GE health initiative; krogeralbertsons[.]com — the Kroger-Albertsons merger domain; maxfactor-international[.]com; veinteractive[.]com), alongside disposable lookalike domains seeded from Vietnamese football/streaming terms (xoilac, cakhia, 90phut, socolive, mitom, vaoroi).
The resulting platforms — branded Xoilac, Cakhia, 90phut, Socolive, and MiTom (secondary: ColaTV, Vaoroi) — are WordPress-based illegal sports-streaming sites geo-targeting Vietnam, South Korea, Taiwan, Singapore, Japan, and Australia, monetized through gambling/betting redirects (VSBet, ColaScore, 8xbet, 6686) behind cloaking/traffic-distribution infrastructure (6789x[.]site and similar). A subset of the same streaming domains double as live command-and-control infrastructure: Infoblox counted 405 confirmed malware C2 domains overlapping with the streaming footprint (peak 386 simultaneously active in December 2025) and 31,000+ malware samples. The malware timeline runs from early Quasar RAT testing (October 2025), through the first C2 configurations appearing on streaming domains (November 2025), a mass-weaponization wave covering ~86% of C2 domains (December 2025), sustained AsyncRAT 0.5.8 deployment (November 2025-March 2026, mutex lM9F7Ezcu9e3), to a DCRat surge of 7,610 samples in March 2026 that coincided with a Vietnamese law-enforcement crackdown (Xoi Lac TV site freeze February 2026; 30 suspects charged and ~300 billion VND / ~$12M USD seized in March 2026). Malware samples are explicitly self-branded with Windows PE metadata matching the streaming platforms (CompanyName "socoLIVE", FileDescription "xoilac client", ProductName "xoilac", trademarks referencing "8xbet", a Windows startup persistence key named "xoilac"), and telemetry shows exposure across 24+ industries, led by education (~20% of C2 queries) and IT/consulting (~14%), with government, healthcare, and banking sectors also affected. The highest-impact single C2/streaming domain was colatv88xb[.]cc, accounting for roughly 70% of exposed-network DNS queries. Evidence links Sable Squirrel to a broader Asian streaming-gambling ecosystem: shared live-chat code with Chinese-language comments on Chinese sports-betting sites, a shared image-serving backend (TheSports[.]com) used across Vietnamese, Chinese, Indonesian, and Russian-language gambling platforms, and the AiScore mobile app (10M+ Google Play installs) distributed by Hong Kong/Singapore-registered entities. Two documented incidents show Sable Squirrel infrastructure itself getting hijacked by third parties: xemlaibongda[.]net (Balada Injector-infected WordPress redirecting to a Keitaro-tracked BroPush affiliate chain) and xoilacxys[.]top (registrar-account takeover redirecting to a Russian investment scam before going lame).
A separate but related "Scavenger" cluster of three actors — Stuffy Squirrel (500+ domains, active since 2020), Shady Squirrel (700+ domains, active since July 2023, assessed Russian-speaking), and Swiping Squirrel (3,000+ domains, active since 2022) — specialize in acquiring expired domains that were previously compromised by other threat actors (TA2726, Magecart, Balada Injector) and immediately inherit the pre-existing infection/injection traffic without needing to re-compromise the underlying site. Stuffy Squirrel's current primary domain (gsstats[.]ru, active since November 2025, formerly weatherplllatform[.]com under Balada) runs a two-checkpoint cloaking chain (URL-path decoy serving Raphaël.js, then a 1,225-character self-removing IIFE gated by an independent TDS click-check) monetized first via PushHouse/ExoClick (through January 2025) and then ExoClick plus a Russian popunder network (from March 2025). Shady Squirrel (blacksaltys[.]com — formerly TA2726 infrastructure; plus simplejscdn[.]com, cdnjslibraries[.]com, imhd[.]io, pausewatchings[.]com, pills-europe[.]com, wesq[.]me, advanceslibrary[.]com, brodirect3s[.]site) runs custom JS injections behind Keitaro TDS with referrer-gated payload delivery, downstream to 1Win Russian gambling, a Japan/US-targeted tech-support scam (April-July 2026: phone numbers +1-201-409-2894 Japan-only, +1-877-481-2126, +1-888-756-6605; ~10,000 Azure static-webhosting accounts created monthly across 9+ regions; a 1x1-pixel beacon geolocates victims by IP/user-agent to select the delivered phone number; payload sections are AES-encrypted and decrypted client-side using the URL fragment as the key), and — most notably — SocGholish. Within roughly 10 days of Operation Endgame's June 2026 disruption of SocGholish infrastructure (300+ servers, 140+ domains seized, €41M frozen), Shady Squirrel registered advanceslibrary[.]com (2026-06-27) and began serving confirmed SocGholish fake-browser-update lures by 2026-07-10 (the domain was independently leaked in a Facebook post); the actor went silent again in early July 2026. Keitaro injection chains across Stuffy and Shady Squirrel share consistent tracking cookies ("0c9c8", "208c9") also previously observed with TA2726, and the two-part Keitaro injection pattern (config-name parameter to a Keitaro server, then localStorage-based campaign/subid/token retrieval) traces to a documented technique first seen with Help TDS in September 2020. Swiping Squirrel (blackshelter[.]org, bluegaslamp[.]org, draggedline[.]org, getshopstar[.]com, jqueryapihelpers[.]com, lzdatheme[.]com, slurpslimes[.]org, webpixel[.]app, windowlight[.]org) runs a distinct multi-stage cloaking pipeline (client-side fingerprint script -> index.php cloaker returning {} or "fw" -> /s/index/ relay -> /f/index affiliate-bid endpoint -> meta-refresh) funneling traffic to ZeroPark (Team Internet), AliExpress, and Kelkoo affiliate offers, with ClickFix malware observed downstream via the AdventureFeeds affiliate chain from ZeroPark.
Collectively, the four clusters demonstrate that expired-domain resale is now an organized, well-capitalized initial-access and C2 vector operating in parallel with (and largely orthogonal to) traditional vulnerability exploitation: no CVE applies, the abused surface is domain-lifecycle policy at registrars/registries, and both operational-security weaknesses (reused registrant contact details, a bogus Ho Chi Minh City business address, self-branded malware) and law-enforcement pressure (Vietnamese 2026 crackdown, Operation Endgame) have so far only produced brief dips before the operations resumed and expanded, reportedly gearing up around the 2026 FIFA World Cup streaming demand.
MITRE ATT&CK techniques used in TL-2026-2033
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location
Discovery
T1082 System Information Discovery
Initial Access
T1190 Exploit Public-Facing Application
Execution
Command and Control
Resource Development
T1583.001 Domains; T1583.006 Web Services; T1583.008 Malvertising; T1587.001 Malware; T1608.001 Upload Malware
command-and-control
Affected products and versions in Expired-Domain Resale Abuse Fuels Malware Delivery
- Domain Registrars / Backorder Marketplaces (GoDaddy, DropCatch.com, Namecheap, Dynadot) — Expired Domain Auction and Backorder Services
Vulnerable versions: Process gap: no verification or reputation-reset requirement when a domain with prior elevated trust/traffic is re-registered by a new, unrelated owner
Fixed in: N/A - no vendor patch; requires registrar/registry policy changes such as reputation resets or extended dropcatch review holds - WordPress — Self-hosted WordPress sites (theme/plugin compromise exploited by Balada Injector, TA2726, and Magecart prior to domain expiration)
Vulnerable versions: Outdated/unpatched WordPress core or plugin installs at time of original compromise
Fixed in: Patched WordPress core + plugins with injected malicious code removed before domain lapse
Remediation for Expired-Domain Resale Abuse Fuels Malware Delivery
Immediate actions
- Block/monitor the listed dropcatch and C2 domains at DNS/perimeter (colatv88xb.cc, xoilacxys.top, xemlaibongda.net, gsstats.ru, weatherplllatform.com, blacksaltys.com, advanceslibrary.com, pausewatchings.com, blackshelter.org, api-score.com, 6789x.site)
- Alert on outbound traffic matching Quasar RAT / AsyncRAT / DCRat / Remcos RAT C2 patterns, including the AsyncRAT mutex lM9F7Ezcu9e3 and the 'xoilac' persistence startup key
- Block user access to the unlicensed sports-streaming brand family (Xoilac, Cakhia, 90phut, Socolive, MiTom, ColaTV, Vaoroi) and their gambling redirect partners (VSBet, ColaScore, 8xbet, 6686) at the web proxy
- Alert users to SocGholish-style fake browser-update prompts, especially any served from newly re-registered domains such as advanceslibrary.com or pausewatchings.com
- Flag inbound calls/pop-ups referencing the identified tech-support-scam numbers (+1-201-409-2894, +1-877-481-2126, +1-888-756-6605)
Workarounds
- Require a domain-reputation reset/review before trusting a re-registered domain that previously carried elevated reputation (prior health, finance, or well-known brand history)
- Where feasible, favor registrar/registry policies or extended holding periods that flag domains with a documented history of malicious-content transfer to a new owner
Longer-term hardening
- Deploy DNS threat-intel feeds that specifically flag dropcatch/expired-domain re-registration events (not just newly-observed domains), since ~20% of new registrations in H1 2026 are dropcatch and 94% activate maliciously within two weeks
- Harden internet-facing WordPress deployments (core/plugin patching, WAF) to prevent Balada Injector/TA2726/Magecart-style compromise that later feeds Scavenger-cluster inherited traffic
- Integrate registrant-detail and hosting-pattern correlation (reused contact info across thousands of domains) into brand-protection and domain-monitoring programs
- Track Windows PE metadata branding (CompanyName/FileDescription/ProductName matching known streaming/gambling brands) as a detection signal for Sable Squirrel-linked malware families
Timeline of Expired-Domain Resale Abuse Fuels Malware Delivery
- Stuffy Squirrel cluster begins operating, later growing to 500+ dropcatch domains acquired from prior Balada Injector/Magecart compromises.
- Swiping Squirrel cluster begins operating, eventually amassing 3,000+ dropcatch domains feeding a multi-stage cloaking pipeline to affiliate/ClickFix payloads.
- Sable Squirrel begins its expired-domain acquisition campaign, eventually amassing 10,000+ domains and an estimated $7M+ spend.
- Shady Squirrel, assessed Russian-speaking, begins operating; grows to 700+ dropcatch domains feeding SocGholish, tech-support scams, and gambling redirects.
- Stuffy Squirrel monetization Phase I (PushHouse and ExoClick ad networks) runs through January 2025.
- Stuffy Squirrel Phase II begins: monetization shifts to ExoClick plus a Russian popunder network.
- Earliest Quasar RAT samples appear on Sable Squirrel streaming-domain infrastructure (likely testing phase).
- First malware C2 configurations appear live on Sable Squirrel streaming domains; AsyncRAT 0.5.8 deployment begins.
- Mass weaponization wave: roughly 86% of Sable Squirrel C2 domains configured, peaking at 386 simultaneously active C2 domains.
- Vietnamese authorities freeze the Xoi Lac TV streaming network without prior notice, part of an escalating enforcement campaign against the brand family Sable Squirrel overlaps with.
- Vietnamese authorities dismantle Xoi Lac TV: 30 suspects charged and roughly 300 billion VND (~$12M USD) seized; DCRat surges to 7,610 samples during the same window as Sable Squirrel infrastructure proves resilient (only a one-month registration dip before recovery).
- Shady Squirrel begins a Japan/US-targeted tech-support-scam campaign via its dropcatch domains, running through July 2026.
- Operation Endgame law-enforcement action disrupts SocGholish infrastructure (300+ servers, 140+ domains seized, EUR 41M frozen).
- Shady Squirrel registers advanceslibrary[.]com, within roughly 10 days used to resupply SocGholish with victim traffic after the Operation Endgame takedown.
- Infoblox Threat Intel publishes Parts 2 and 3 of its 'Dropcatch Domains' research series detailing Sable Squirrel and the Scavenger cluster (Stuffy/Shady/Swiping Squirrel).
Sources cited for Expired-Domain Resale Abuse Fuels Malware Delivery
- Crooks are buying your expired domains and using them to deliver malware
- Illegal Streaming Fronts a $7M Dropcatch Domain Operation
- Expired Malicious Domains Bring New Threats to Life
- Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
- Infoblox research finds 65,000 expired domains re-registered daily in first half of 2026
- Expired domains are a goldmine for hackers - and some cyber crime groups are investing millions in 'dropcatch' scams to deliver malware
- Cybercriminals invest millions in expired domains for illicit activities
- Infoblox welcomes Operation Endgame action against SocGholish and urges organisations to remain vigilant
- Infoblox Threat Intel
Threats related to Expired-Domain Resale Abuse Fuels Malware Delivery
- Squirrel Threat Cluster Weaponizes Dropcatch/Expired Domains for RAT C2, SocGholish and Streaming-Gambling Fraud
- Fake OpenAI Codex Download Pages on Google Sites Deliver ClickFix macOS Stealer Tied to Atomic Stealer (AMOS) Infrastructure
- SourTrade Malvertising Campaign Assembles Windows Malware In-Browser via ServiceWorker/SharedWorker JavaScript Chain to Defeat Hash-Based Detection
- Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers, Backdoors and Malicious Browser Extensions
Detection coverage for TL-2026-2033
As of 2026-08-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2033 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.