SecurityBrief India - Technology news for CISOs & cybersecurity decision-makers
India
Cyber criminals spend USD $7 million on expired domains

Cyber criminals spend USD $7 million on expired domains

Mon, 17th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Infoblox Threat Intel has identified a cybercriminal market in expired internet domains. One actor, it found, spent more than USD $7 million acquiring more than 10,000 of them.

About 65,000 expired domains were re-registered each day in the first half of 2026, accounting for nearly 20% of newly observed domains on a typical day.

These so-called dropcatch domains are internet addresses that lapse and then return to the market. Criminals buy them to inherit web traffic, backlinks and a degree of trust built up under previous owners, then redirect that value into malware delivery, scams, illegal streaming and online gambling.

One of the main cases in the research centres on an actor Infoblox tracks as Sable Squirrel. Investigators estimate the group has spent more than USD $7 million on a portfolio of more than 10,000 expired domains that support a broader online criminal operation.

The infrastructure linked to Sable Squirrel spans illegal streaming services, gambling sites and malware distribution. The actor also runs command-and-control nodes for multiple remote access trojans on the same infrastructure as illegal content, directly linking domain speculation to malware operations.

Inherited trust

The study suggests expired domains now play a larger role in cybercrime than simple one-off redirects or throwaway scam sites. A lapsed domain with a long history can retain search engine standing, inbound links from legitimate websites and direct visits from users who still recognise the address or reach it through old references.

That gives attackers a ready-made audience and a veneer of legitimacy that a newly created domain would not usually have. Security researchers have long tracked malicious new registrations, but the report argues that re-registered expired domains deserve closer scrutiny because their prior reputation can lower suspicion among both users and automated systems.

The trade is not limited to domains that were once legitimate. Researchers also found a secondary market in domains already associated with malicious activity, particularly those previously embedded in compromised websites and still receiving traffic from old infections or planted links.

Across three additional actors identified in the research, Infoblox found thousands of dropcatch domains embedded in tens of thousands of compromised websites. Those sites continued to send victims to malicious software, scams and other harmful content even after the original domains had expired and changed hands.

Several actors

Among those actors was a group tracked as Shady Squirrel. Infoblox said the actor used expired malicious domains to route victims into scareware schemes and call centre fraud before later working with the operator behind SocGholish, the fake browser update malware framework widely used in cybercrime campaigns.

The findings point to a layered ecosystem in which one criminal group can profit from infrastructure created by another. Rather than building traffic from scratch, buyers of expired domains can step into an existing stream of visitors, links and compromised web pages, shortening the path to monetisation.

That model also appears to support different forms of abuse at once. In the Sable Squirrel case, the same domain portfolio was used for both consumer-facing illegal content and more covert malware management systems, showing how domains can serve several criminal functions depending on their history and traffic profile.

Researchers named two other actors, Stuffy Squirrel and Swiping Squirrel, as part of the wider investigation into dropped malicious domains. The groups used re-registered domains to capture residual traffic from compromised websites and redirect it to scams, malware or advertising fraud.

The work adds to growing concern that parts of the domain name system are becoming a market for recycled trust. Security teams often focus on whether a site is newly registered, but an expired domain may carry more risk precisely because it looks established and may still be referenced by legitimate pages across the web.

Dr Renée Burton outlined the scale of the market in a statement accompanying the research. "The sheer volume of dropcatch domains is astounding. We've known that bad guys buy expired domains to repurpose them, but the way in which they were used, and the amount of money actors are willing to spend wasn't well understood," said Dr Renée Burton, VP of Infoblox Threat Intel.

Burton also described why older web addresses can be attractive to attackers. "Expired domains can be a shortcut to both trust and traffic, making dropcatch domains a higher risk than the average newly registered domain," she said.