Threat Actors Weaponize Expired 'Dropcatch' Domains for Scams and Malware
Cybercriminals are exploiting a widespread practice of re-registering expired domains, dubbed 'dropcatch domains,' to inherit legitimate website traffic and reputation. This tactic allows them to redirect unsuspecting users to sophisticated scams and malware distribution networks, posing a significant threat to IT security professionals and privacy-conscious users alike.
Threat actors are actively acquiring expired domains to weaponize their inherited website traffic and reputation, redirecting victims to scams and malware on a massive scale.
**Infoblox**, a leading DNS threat intelligence firm, has coined the term **dropcatch domains** for these re-registered expired domains. These domains, once again available for registration, are swiftly scooped up by malicious entities.
During the first half of 2026, an alarming 50,400 dropcatch domains were re-registered daily in generic top-level domains (gTLDs) like ".com" alone. This figure escalates to approximately 65,000 when country code top-level domains (ccTLDs) are included, representing nearly 20% of all daily gTLD and ccTLD registrations. Essentially, one out of every five newly registered domains is a dropcatch domain.
"These domains can be particularly interesting, even dangerous, because they inherit reputation and sometimes connections from their previous life," **Infoblox** stated in a comprehensive three-part report shared with The Hacker News. "Researchers, security products, and reputation-based algorithms may view it more favorably than a genuinely brand-new registration. Threat actors know this and take advantage of it."
**Infoblox**'s analysis indicates that .net and .xyz TLDs lead in dropcatch activity, surpassing .com, which ranks third. Other prominent TLDs include .org, .vip, .online, .store, .site, .app, and .shop. The majority of these domains are re-registered through registrars such as **GoDaddy**, **Namecheap**, and **DropCatch.com**, which account for median daily dropcatch domains of 5,246, 4,385, and 3,568, respectively.
While reasons for domain expiration vary, most gTLDs adhere to a registration recovery policy, offering existing registrants a renewal grace period. Once this period expires, the domain is released and becomes available for re-registration.
This is where specialized drop catching services like **DropCatch.com** become instrumental. They monitor domains approaching deletion and automatically attempt to register them on behalf of customers who have placed a backorder. In cases of multiple interested parties, domains often proceed to a public auction where the highest bidder secures the domain.
"Every day 60,000 - 85,000 .com and .net domain names become available on the 'Daily Drop,'" **DropCatch.com** notes on its website. "The Drop is an extremely competitive market where advanced computer algorithms have a remarkable advantage by detecting the precise millisecond a domain name becomes available for registration and issuing hundreds of consecutive purchase attempts at once."
In some scenarios, these auctions occur even before domains are released to the registry pool, allowing users to browse expiring domains, view current bids, and flag those with interest. This raises a critical question: who is catching them?
### Squirrels and Scavengers: When Trust Transfer Becomes a Security Issue
While cybersecurity defenders often proactively register expired domains as a precautionary measure to prevent future misuse, domain investors also engage in buying, holding, and reselling internet domain names for profit. However, this practice becomes a severe security concern when malicious actors gain control of a domain with a pre-existing history.
"For threat actors specifically, the inherited reputation isn't the only thing valuable about acquiring a dropped domain," **Infoblox** elaborated. "They also come with a variety of lingering connections: email intended for the original domain holder, cached search results, inherited web traffic, and in some cases, a ready-made platform for code injection on already compromised sites. Lingering DNS records can also create opportunities for threat actors."

One such threat actor, dubbed **Sable Squirrel**, is estimated to have spent nearly $7 million on expired domains to construct a criminal enterprise involved in illegal sports streaming, online gambling promotion, and malware infrastructure.
"That money buys aged registration history, backlinks, residual traffic, and the kind of reputation signals many defenses still treat as indications of trustworthiness," the threat intelligence firm added. Evidence points to Vietnam as the epicenter of this operation, sharing strong overlaps with **Xoi Lac TV**, an illegal streaming network dismantled by Vietnamese authorities in March.
**Sable Squirrel** (hence the squirrel moniker) hoards over 10,000 domains, many of which serve as the backbone for a large Asian sports piracy operation under brands like **Xoilac**, **Cakhia**, **90phut**, **Socolive**, and **MiTom**. According to **Infoblox**, these platforms act as acquisition channels to maintain "fan engagement" while simultaneously promoting betting services such as **VSBet**, **ColaScore**, and **8xbet**, which **Sable Squirrel** also operates.
The scheme involves promoting these brands across platforms like Facebook, Instagram, Reddit, Twitch, Amazon Podcasts, self-owned YouTube channels, and ads on compromised job-posting and community sites. Users in Vietnam, South Korea, Japan, Taiwan, Singapore, and Australia are selectively redirected to the illicit sports streaming sites via a traffic distribution system (TDS).
**Sable Squirrel** has also been found publishing Android applications for **ColaScore** and **VSBet** on the Google Play Store and through developer accounts suspected of being compromised. "This is not a one-off, we have found many variations of these compromised Play accounts distributing the same apps, and when Google suspends one, another appears to take its place," **Infoblox** reported.

Over 31,000 malware samples, including **Quasar RAT**, **AsyncRAT**, **DCRat**, **NanoCore**, **Remcos RAT**, **njRAT**, and artifacts bearing **HiddenTear** ransomware signatures, have been observed communicating with **Sable Squirrel**'s infrastructure. A subset of the streaming domains also function as malware command-and-control (C2) servers, even while continuing to deliver live streaming content to visitors.
The **Xoi Lac TV** brand emerged in 2016, but it wasn't until November 2025 that the first malware C2 configurations appeared on **Sable Squirrel** domains already serving streaming content, signaling a strategic pivot beyond illegal streaming and gambling. The threat actor is believed to have initiated the purchase of dropcatch domains as early as June 2023.
Interestingly, **Sable Squirrel** employs a two-track domain model: (1) acquiring expired domains through auctions via **DropCatch.com**, **GoDaddy**, **Namecheap**, and **Dynabot** to inherit their legitimacy, registration history, inbound traffic, and backlinks; and (2) utilizing freshly registered lookalike domains to operate its streaming fleet.
Some of the dropcatch domains acquired by **Sable Squirrel** for illegal sports-streaming include:
* healthymagination