Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Expired Domains for Scams and Malware

Hackers Exploit Expired Domains for Scams and Malware

Posted on August 17, 2026 By CWS

Cybercriminals are increasingly targeting expired domains, leveraging their previous reputations to reroute unsuspecting visitors to malicious sites. This strategy has become a significant issue, as highlighted by DNS threat intelligence firm Infoblox. These domains, once expired, are quickly re-registered by threat actors in a practice known as ‘dropcatching’, which allows them to inherit the domain’s past traffic and credibility.

Understanding Dropcatch Domains

During early 2026, an average of 50,400 expired domains were re-registered daily across generic top-level domains (gTLDs) such as ‘.com’. This number rises to about 65,000 when including country code top-level domains (ccTLDs). These dropcatch domains represent nearly 20% of all new registrations, demonstrating the scale of this issue. Infoblox’s report reveals that domains like .net and .xyz lead in dropcatch activity, overshadowing even the ubiquitous .com.

Registrars such as GoDaddy, Namecheap, and DropCatch.com facilitate these re-registrations. They often make use of automated systems to quickly capture domains as soon as they become available again. This rapid re-registration process is crucial, as domains inherit any lingering reputation and connections from their previous existence, which can be manipulated by malicious actors.

Threat Actors and Their Methods

One prominent threat actor, known as Sable Squirrel, has reportedly spent nearly $7 million on acquiring expired domains. These domains are used to support illegal online activities, including sports streaming and gambling, as well as serving as infrastructure for malware distribution. The operations are largely centered in Vietnam, with connections to now-defunct networks like Xoi Lac TV.

Sable Squirrel’s strategic use of these domains includes integrating them into a dual-model system. This involves acquiring expired domains through auctions to leverage their established reputations while simultaneously registering new domains to expand their streaming network. This dual approach enables them to maintain a robust infrastructure for both legitimate-seeming operations and covert malicious activities.

Wider Implications and Future Outlook

Beyond Sable Squirrel, other malicious groups, dubbed ‘scavengers’ by Infoblox, also exploit expired domains. These actors, such as Stuffy Squirrel and Shady Squirrel, control thousands of domains, redirecting traffic to other cybercriminals or using them for fraudulent advertising. This activity highlights the ongoing challenges in domain security and the need for vigilant monitoring and defense strategies.

Infoblox’s findings underscore the importance of securing expired domains to prevent their misuse. As threat actors continue to refine their tactics, cybersecurity professionals must stay proactive in detecting and mitigating these risks. The future will likely see continued innovation in both cyber defense and cybercrime, necessitating constant vigilance and adaptation.

The Hacker News Tags:cyber threats, Cybersecurity, DNS security, domain auctions, domain hijacking, domain reputation, dropcatch domains, expired domains, Infoblox, internet safety, Malware, online security, Sable Squirrel, Scams, threat intelligence

Post navigation

Previous Post: GitHub Service Disruption Affects Developers Globally
Next Post: Achieving IAM Compliance: Essential Guidelines

Related Posts

Kimwolf Botnet Hijacks 1.8 Million Android TVs, Launches Large-Scale DDoS Attacks Kimwolf Botnet Hijacks 1.8 Million Android TVs, Launches Large-Scale DDoS Attacks The Hacker News
Agentic AI’s Role in Defense Hinges on Secure Infrastructure Agentic AI’s Role in Defense Hinges on Secure Infrastructure The Hacker News
Critical Metabase Flaw Exploited, Urgent Patch Released Critical Metabase Flaw Exploited, Urgent Patch Released The Hacker News
Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly Google Uncovers PROMPTFLUX Malware That Uses Gemini AI to Rewrite Its Code Hourly The Hacker News
Google Mandates Developer Verification for Android in Four Nations Google Mandates Developer Verification for Android in Four Nations The Hacker News
SharePoint Vulnerability Abused After PoC Emerges SharePoint Vulnerability Abused After PoC Emerges The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Snowflake GitHub Actions Vulnerability Exposes Jira Credentials
  • OpenMatter Highlights Verification at Belgrade Blockchain
  • Achieving IAM Compliance: Essential Guidelines
  • Hackers Exploit Expired Domains for Scams and Malware
  • GitHub Service Disruption Affects Developers Globally

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Snowflake GitHub Actions Vulnerability Exposes Jira Credentials
  • OpenMatter Highlights Verification at Belgrade Blockchain
  • Achieving IAM Compliance: Essential Guidelines
  • Hackers Exploit Expired Domains for Scams and Malware
  • GitHub Service Disruption Affects Developers Globally

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark