Expired-Domain Resale Abuse Fuels Malware Delivery: Sable Squirrel and Scavenger Threat Clusters (Quasar RAT, AsyncRAT, DCRat, Remcos RAT, SocGholish) — Threadlinqs Intelligence
As of 2026-08-16, Expired-Domain Resale Abuse Fuels Malware Delivery: Sable Squirrel and Scavenger Threat Clusters (Quasar RAT, AsyncRAT, DCRat, Remcos RAT, SocGholish) is a medium-severity malware threat attributed to Sable Squirrel, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-2033 · Severity: MEDIUM · Status: ACTIVE · Category: MALWARE
Attribution: Sable Squirrel · FINANCIAL
Infoblox Threat Intel documents four affiliated dropcatch-domain actors — Sable Squirrel (10,000+ domains, ~$7M spent) and the Scavenger cluster (Stuffy Squirrel, Shady Squirrel, Swiping Squirrel) —
Infoblox Threat Intel's three-part "Dropcatch Domains" research series (published 2026-08-13, syndicated by SecurityAffairs, The Hacker News, IT Pro, and SC Media on 2026-08-14/15) documents an industrial-scale abuse of expired-domain re-registration ("dropcatching"): roughly 65,000 expired domains are re-registered daily in H1 2026 — nearly 20% of all newly observed domains — because expired domains retain backlinks, search-engine trust, cached traffic, and DNS history that criminals can immediately weaponize instead of building reputation from scratch.
The report attributes the largest single dropcatch operation to Sable Squirrel, a well-funded, likely transnational actor with a Vietnamese operational focus. Sable Squirrel controls more than 10,000 domains and has an extrapolated spend exceeding $7 million (confirmed: 160+ purchases, $430K+ documented) through GoDaddy, DropCatch.com, Namecheap, and Dynadot. Median domain activation is 5 days post-purchase, with 24% live same-day, 76% within a week, and 94% within two weeks. Premium acquisitions included brand-name domains with residual trust (healthymagination[.]com — formerly a GE health initiative; krogeralbertsons[.]com — the Kroger-Albertsons merger domain; maxfactor-international[.]com; veinteractive[.]com), alongside disposable lookalike domains seeded from Vietnamese football/streaming terms (xoilac, cakhia, 90phut, socolive, mitom, vaoroi).
The resulting platforms — branded Xoilac, Cakhia, 90phut, Socolive, and MiTom (secondary: ColaTV, Vaoroi) — are WordPress-based illegal sports-streaming sites geo-targeting Vietnam, South Korea, Taiwan, Singapore, Japan, and Australia, monetized through gambling/betting redirects (VSBet, ColaScore, 8xbet, 6686) behind cloaking/traffic-distribution infrastructure (6789x[.]site and similar). A subset of the same streaming domains double as live command-and-control infrastructure: Infoblox counted 405 confirmed malware C2 domains overlapping with the streaming footprint (peak 386 simultaneously active in December 2025) and 31,000+ malware samples. The malware timeline runs from early Quasar RAT testing (October 2025), through the first C2 configurations appearing on streaming domains (November 2025), a mass-weaponization wave covering ~86% of C2 domains (December 2025), sustained AsyncRAT 0.5.8 deployment (November 2025-March 2026, mutex lM9F7Ezcu9e3), to a DCRat surge of 7,610 samples in March 2026 that coincided with a Vietnamese law-enforcement crackdown (Xoi Lac TV site freeze February 2026; 30 suspects charged and ~300 billion VND / ~$12M USD seized in March 2026). Malware samples are explicitly self-branded with Windows PE metadata matching the streaming platforms (CompanyName "socoLIVE", FileDescription "xoilac client", ProductName "xoilac", trademarks referencing "8xbet", a Windows startup persistence key named "xoilac"), and telemetry shows exposure across 24+ industries, led by education (~20% of C2 queries) and IT/consulting (~14%), with government, healthcare, and banking sectors also affected. The highest-impact single C2/streaming domain was colatv88xb[.]cc, accounting for roughly 70% of exposed-network DNS queries. Evidence links Sable Squirrel to a broader Asian streaming-gambling ecosystem: shared live-chat code with Chinese-language comments on Chinese sports-betting sites, a shared image-serving backend (TheSports[.]com) used across Vietnamese, Chinese, Indonesian, and Russian-language gambling platforms, and the AiScore mobile app (10M+ Google Play installs) distributed by Hong Kong/Singapore-registered entities. Two documented incidents show Sable Squirrel infrastructure itself getting hijacked by third parties: xemlaibongda[.]net (Balada Injector-infected WordPress redirecting to a Keitaro-tracked BroPush affiliate chain) and xoilacxys[.]top (registrar-account takeover redirecting to a Russian investment scam before going lame).
A separate but related "Scavenger" cluster of three actors — Stuffy Squirrel (500
Target sectors: news - media, entertainment, gambling, consumer, education, government administration, health, financial services, retail e-commerce, information technology
Target regions: vietnam, south korea, japan, australia, taiwan, singapore, indonesia, russia, united states of america
Timeline
- Stuffy Squirrel cluster begins operating, later growing to 500+ dropcatch domains acquired from prior Balada Injector/Magecart compromises.
- Swiping Squirrel cluster begins operating, eventually amassing 3,000+ dropcatch domains feeding a multi-stage cloaking pipeline to affiliate/ClickFix payloads.
- Sable Squirrel begins its expired-domain acquisition campaign, eventually amassing 10,000+ domains and an estimated $7M+ spend.
- Shady Squirrel, assessed Russian-speaking, begins operating; grows to 700+ dropcatch domains feeding SocGholish, tech-support scams, and gambling redirects.
- Stuffy Squirrel monetization Phase I (PushHouse and ExoClick ad networks) runs through January 2025.
- Stuffy Squirrel Phase II begins: monetization shifts to ExoClick plus a Russian popunder network.
- Earliest Quasar RAT samples appear on Sable Squirrel streaming-domain infrastructure (likely testing phase).
- First malware C2 configurations appear live on Sable Squirrel streaming domains; AsyncRAT 0.5.8 deployment begins.
- Mass weaponization wave: roughly 86% of Sable Squirrel C2 domains configured, peaking at 386 simultaneously active C2 domains.
- Vietnamese authorities freeze the Xoi Lac TV streaming network without prior notice, part of an escalating enforcement campaign against the brand family Sable Squirrel overlaps with.
- Vietnamese authorities dismantle Xoi Lac TV: 30 suspects charged and roughly 300 billion VND (~$12M USD) seized; DCRat surges to 7,610 samples during the same window as Sable Squirrel infrastructure proves resilient (only a one-month registration dip before recovery).
- Shady Squirrel begins a Japan/US-targeted tech-support-scam campaign via its dropcatch domains, running through July 2026.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, MEDIUM, threat intelligence, cybersecurity, T1583.001, T1583.006, T1583.008, T1587.001, T1608.001, T1190, T1204.002, T1036.005, T1027, T1665