Expired-Domain Resale Abuse Fuels Malware Delivery: Sable Squirrel and Scavenger Threat Clusters (Quasar RAT, AsyncRAT, DCRat, Remcos RAT, SocGholish)

Expired-Domain Resale Abuse Fuels Malware Delivery (TL-2026-2033), also tracked as Dropcatch Domains Campaign, is a medium-severity malware campaign, first published 2026-08-16. It is attributed to Sable Squirrel with medium confidence, affects Domain Registrars / Backorder Marketplaces (GoDaddy, DropCatch.com, maps to 12 MITRE ATT&CK techniques (T1027, T1036.005, T1082), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-2033

Threat ID
TL-2026-2033
Also known as
Dropcatch Domains Campaign, Domain Reputation Hijacking Campaign
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
2026-08-16
Last reviewed
2026-08-16
Attribution
Sable Squirrel
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
news - media, entertainment, gambling, consumer, education, government administration, health, financial services, retail e-commerce, information technology
Target regions
vietnam, south korea, japan, australia, taiwan, singapore, indonesia, russia, united states of america
Detection rules
9
Indicators of compromise
24

Malware and tooling in Expired-Domain Resale Abuse Fuels Malware Delivery

Malware and tooling: AsyncRAT, DCRat, HiddenTear, NJRat, NanoCore, Quasar RAT, Remcos, SocGholish - S1124, DCRAT - S9017, Keitaro TDS

Infoblox Threat Intel documents four affiliated dropcatch-domain actors — Sable Squirrel (10,000+ domains, ~$7M spent) and the Scavenger cluster (Stuffy Squirrel, Shady Squirrel, Swiping Squirrel) — that systematically buy or backorder expired domains to inherit residual reputation, traffic, and DNS history for illegal-streaming malware delivery, SocGholish fake-update campaigns, and tech-support scams. Sable Squirrel's Xoilac/Cakhia/90phut/Socolive/MiTom streaming platforms double as C2 for Quasar RAT, AsyncRAT, DCRat, and Remcos RAT across Vietnam, South Korea, Japan, and Australia, while Shady Squirrel resupplied SocGholish with victim traffic within 10 days of Operation Endgame's June 2026 takedown.

How Expired-Domain Resale Abuse Fuels Malware Delivery works

Infoblox Threat Intel's three-part "Dropcatch Domains" research series (published 2026-08-13, syndicated by SecurityAffairs, The Hacker News, IT Pro, and SC Media on 2026-08-14/15) documents an industrial-scale abuse of expired-domain re-registration ("dropcatching"): roughly 65,000 expired domains are re-registered daily in H1 2026 — nearly 20% of all newly observed domains — because expired domains retain backlinks, search-engine trust, cached traffic, and DNS history that criminals can immediately weaponize instead of building reputation from scratch.

The report attributes the largest single dropcatch operation to Sable Squirrel, a well-funded, likely transnational actor with a Vietnamese operational focus. Sable Squirrel controls more than 10,000 domains and has an extrapolated spend exceeding $7 million (confirmed: 160+ purchases, $430K+ documented) through GoDaddy, DropCatch.com, Namecheap, and Dynadot. Median domain activation is 5 days post-purchase, with 24% live same-day, 76% within a week, and 94% within two weeks. Premium acquisitions included brand-name domains with residual trust (healthymagination[.]com — formerly a GE health initiative; krogeralbertsons[.]com — the Kroger-Albertsons merger domain; maxfactor-international[.]com; veinteractive[.]com), alongside disposable lookalike domains seeded from Vietnamese football/streaming terms (xoilac, cakhia, 90phut, socolive, mitom, vaoroi).

The resulting platforms — branded Xoilac, Cakhia, 90phut, Socolive, and MiTom (secondary: ColaTV, Vaoroi) — are WordPress-based illegal sports-streaming sites geo-targeting Vietnam, South Korea, Taiwan, Singapore, Japan, and Australia, monetized through gambling/betting redirects (VSBet, ColaScore, 8xbet, 6686) behind cloaking/traffic-distribution infrastructure (6789x[.]site and similar). A subset of the same streaming domains double as live command-and-control infrastructure: Infoblox counted 405 confirmed malware C2 domains overlapping with the streaming footprint (peak 386 simultaneously active in December 2025) and 31,000+ malware samples. The malware timeline runs from early Quasar RAT testing (October 2025), through the first C2 configurations appearing on streaming domains (November 2025), a mass-weaponization wave covering ~86% of C2 domains (December 2025), sustained AsyncRAT 0.5.8 deployment (November 2025-March 2026, mutex lM9F7Ezcu9e3), to a DCRat surge of 7,610 samples in March 2026 that coincided with a Vietnamese law-enforcement crackdown (Xoi Lac TV site freeze February 2026; 30 suspects charged and ~300 billion VND / ~$12M USD seized in March 2026). Malware samples are explicitly self-branded with Windows PE metadata matching the streaming platforms (CompanyName "socoLIVE", FileDescription "xoilac client", ProductName "xoilac", trademarks referencing "8xbet", a Windows startup persistence key named "xoilac"), and telemetry shows exposure across 24+ industries, led by education (~20% of C2 queries) and IT/consulting (~14%), with government, healthcare, and banking sectors also affected. The highest-impact single C2/streaming domain was colatv88xb[.]cc, accounting for roughly 70% of exposed-network DNS queries. Evidence links Sable Squirrel to a broader Asian streaming-gambling ecosystem: shared live-chat code with Chinese-language comments on Chinese sports-betting sites, a shared image-serving backend (TheSports[.]com) used across Vietnamese, Chinese, Indonesian, and Russian-language gambling platforms, and the AiScore mobile app (10M+ Google Play installs) distributed by Hong Kong/Singapore-registered entities. Two documented incidents show Sable Squirrel infrastructure itself getting hijacked by third parties: xemlaibongda[.]net (Balada Injector-infected WordPress redirecting to a Keitaro-tracked BroPush affiliate chain) and xoilacxys[.]top (registrar-account takeover redirecting to a Russian investment scam before going lame).

A separate but related "Scavenger" cluster of three actors — Stuffy Squirrel (500+ domains, active since 2020), Shady Squirrel (700+ domains, active since July 2023, assessed Russian-speaking), and Swiping Squirrel (3,000+ domains, active since 2022) — specialize in acquiring expired domains that were previously compromised by other threat actors (TA2726, Magecart, Balada Injector) and immediately inherit the pre-existing infection/injection traffic without needing to re-compromise the underlying site. Stuffy Squirrel's current primary domain (gsstats[.]ru, active since November 2025, formerly weatherplllatform[.]com under Balada) runs a two-checkpoint cloaking chain (URL-path decoy serving Raphaël.js, then a 1,225-character self-removing IIFE gated by an independent TDS click-check) monetized first via PushHouse/ExoClick (through January 2025) and then ExoClick plus a Russian popunder network (from March 2025). Shady Squirrel (blacksaltys[.]com — formerly TA2726 infrastructure; plus simplejscdn[.]com, cdnjslibraries[.]com, imhd[.]io, pausewatchings[.]com, pills-europe[.]com, wesq[.]me, advanceslibrary[.]com, brodirect3s[.]site) runs custom JS injections behind Keitaro TDS with referrer-gated payload delivery, downstream to 1Win Russian gambling, a Japan/US-targeted tech-support scam (April-July 2026: phone numbers +1-201-409-2894 Japan-only, +1-877-481-2126, +1-888-756-6605; ~10,000 Azure static-webhosting accounts created monthly across 9+ regions; a 1x1-pixel beacon geolocates victims by IP/user-agent to select the delivered phone number; payload sections are AES-encrypted and decrypted client-side using the URL fragment as the key), and — most notably — SocGholish. Within roughly 10 days of Operation Endgame's June 2026 disruption of SocGholish infrastructure (300+ servers, 140+ domains seized, €41M frozen), Shady Squirrel registered advanceslibrary[.]com (2026-06-27) and began serving confirmed SocGholish fake-browser-update lures by 2026-07-10 (the domain was independently leaked in a Facebook post); the actor went silent again in early July 2026. Keitaro injection chains across Stuffy and Shady Squirrel share consistent tracking cookies ("0c9c8", "208c9") also previously observed with TA2726, and the two-part Keitaro injection pattern (config-name parameter to a Keitaro server, then localStorage-based campaign/subid/token retrieval) traces to a documented technique first seen with Help TDS in September 2020. Swiping Squirrel (blackshelter[.]org, bluegaslamp[.]org, draggedline[.]org, getshopstar[.]com, jqueryapihelpers[.]com, lzdatheme[.]com, slurpslimes[.]org, webpixel[.]app, windowlight[.]org) runs a distinct multi-stage cloaking pipeline (client-side fingerprint script -> index.php cloaker returning {} or "fw" -> /s/index/ relay -> /f/index affiliate-bid endpoint -> meta-refresh) funneling traffic to ZeroPark (Team Internet), AliExpress, and Kelkoo affiliate offers, with ClickFix malware observed downstream via the AdventureFeeds affiliate chain from ZeroPark.

Collectively, the four clusters demonstrate that expired-domain resale is now an organized, well-capitalized initial-access and C2 vector operating in parallel with (and largely orthogonal to) traditional vulnerability exploitation: no CVE applies, the abused surface is domain-lifecycle policy at registrars/registries, and both operational-security weaknesses (reused registrant contact details, a bogus Ho Chi Minh City business address, self-branded malware) and law-enforcement pressure (Vietnamese 2026 crackdown, Operation Endgame) have so far only produced brief dips before the operations resumed and expanded, reportedly gearing up around the 2026 FIFA World Cup streaming demand.

MITRE ATT&CK techniques used in TL-2026-2033

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location

Discovery

T1082 System Information Discovery

Initial Access

T1190 Exploit Public-Facing Application

Execution

T1204.002 Malicious File

Command and Control

T1219 Remote Access Tools

Resource Development

T1583.001 Domains; T1583.006 Web Services; T1583.008 Malvertising; T1587.001 Malware; T1608.001 Upload Malware

command-and-control

T1665 Hide Infrastructure

Affected products and versions in Expired-Domain Resale Abuse Fuels Malware Delivery

  • Domain Registrars / Backorder Marketplaces (GoDaddy, DropCatch.com, Namecheap, Dynadot) — Expired Domain Auction and Backorder Services
    Vulnerable versions: Process gap: no verification or reputation-reset requirement when a domain with prior elevated trust/traffic is re-registered by a new, unrelated owner
    Fixed in: N/A - no vendor patch; requires registrar/registry policy changes such as reputation resets or extended dropcatch review holds
  • WordPress — Self-hosted WordPress sites (theme/plugin compromise exploited by Balada Injector, TA2726, and Magecart prior to domain expiration)
    Vulnerable versions: Outdated/unpatched WordPress core or plugin installs at time of original compromise
    Fixed in: Patched WordPress core + plugins with injected malicious code removed before domain lapse

Remediation for Expired-Domain Resale Abuse Fuels Malware Delivery

Immediate actions

  • Block/monitor the listed dropcatch and C2 domains at DNS/perimeter (colatv88xb.cc, xoilacxys.top, xemlaibongda.net, gsstats.ru, weatherplllatform.com, blacksaltys.com, advanceslibrary.com, pausewatchings.com, blackshelter.org, api-score.com, 6789x.site)
  • Alert on outbound traffic matching Quasar RAT / AsyncRAT / DCRat / Remcos RAT C2 patterns, including the AsyncRAT mutex lM9F7Ezcu9e3 and the 'xoilac' persistence startup key
  • Block user access to the unlicensed sports-streaming brand family (Xoilac, Cakhia, 90phut, Socolive, MiTom, ColaTV, Vaoroi) and their gambling redirect partners (VSBet, ColaScore, 8xbet, 6686) at the web proxy
  • Alert users to SocGholish-style fake browser-update prompts, especially any served from newly re-registered domains such as advanceslibrary.com or pausewatchings.com
  • Flag inbound calls/pop-ups referencing the identified tech-support-scam numbers (+1-201-409-2894, +1-877-481-2126, +1-888-756-6605)

Workarounds

  • Require a domain-reputation reset/review before trusting a re-registered domain that previously carried elevated reputation (prior health, finance, or well-known brand history)
  • Where feasible, favor registrar/registry policies or extended holding periods that flag domains with a documented history of malicious-content transfer to a new owner

Longer-term hardening

  • Deploy DNS threat-intel feeds that specifically flag dropcatch/expired-domain re-registration events (not just newly-observed domains), since ~20% of new registrations in H1 2026 are dropcatch and 94% activate maliciously within two weeks
  • Harden internet-facing WordPress deployments (core/plugin patching, WAF) to prevent Balada Injector/TA2726/Magecart-style compromise that later feeds Scavenger-cluster inherited traffic
  • Integrate registrant-detail and hosting-pattern correlation (reused contact info across thousands of domains) into brand-protection and domain-monitoring programs
  • Track Windows PE metadata branding (CompanyName/FileDescription/ProductName matching known streaming/gambling brands) as a detection signal for Sable Squirrel-linked malware families

Timeline of Expired-Domain Resale Abuse Fuels Malware Delivery

  • Stuffy Squirrel cluster begins operating, later growing to 500+ dropcatch domains acquired from prior Balada Injector/Magecart compromises.
  • Swiping Squirrel cluster begins operating, eventually amassing 3,000+ dropcatch domains feeding a multi-stage cloaking pipeline to affiliate/ClickFix payloads.
  • Sable Squirrel begins its expired-domain acquisition campaign, eventually amassing 10,000+ domains and an estimated $7M+ spend.
  • Shady Squirrel, assessed Russian-speaking, begins operating; grows to 700+ dropcatch domains feeding SocGholish, tech-support scams, and gambling redirects.
  • Stuffy Squirrel monetization Phase I (PushHouse and ExoClick ad networks) runs through January 2025.
  • Stuffy Squirrel Phase II begins: monetization shifts to ExoClick plus a Russian popunder network.
  • Earliest Quasar RAT samples appear on Sable Squirrel streaming-domain infrastructure (likely testing phase).
  • First malware C2 configurations appear live on Sable Squirrel streaming domains; AsyncRAT 0.5.8 deployment begins.
  • Mass weaponization wave: roughly 86% of Sable Squirrel C2 domains configured, peaking at 386 simultaneously active C2 domains.
  • Vietnamese authorities freeze the Xoi Lac TV streaming network without prior notice, part of an escalating enforcement campaign against the brand family Sable Squirrel overlaps with.
  • Vietnamese authorities dismantle Xoi Lac TV: 30 suspects charged and roughly 300 billion VND (~$12M USD) seized; DCRat surges to 7,610 samples during the same window as Sable Squirrel infrastructure proves resilient (only a one-month registration dip before recovery).
  • Shady Squirrel begins a Japan/US-targeted tech-support-scam campaign via its dropcatch domains, running through July 2026.
  • Operation Endgame law-enforcement action disrupts SocGholish infrastructure (300+ servers, 140+ domains seized, EUR 41M frozen).
  • Shady Squirrel registers advanceslibrary[.]com, within roughly 10 days used to resupply SocGholish with victim traffic after the Operation Endgame takedown.
  • Infoblox Threat Intel publishes Parts 2 and 3 of its 'Dropcatch Domains' research series detailing Sable Squirrel and the Scavenger cluster (Stuffy/Shady/Swiping Squirrel).

Sources cited for Expired-Domain Resale Abuse Fuels Malware Delivery

Threats related to Expired-Domain Resale Abuse Fuels Malware Delivery

Detection coverage for TL-2026-2033

As of 2026-08-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2033 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats