Cybercriminals are increasingly targeting expired domains, leveraging their previous reputations to reroute unsuspecting visitors to malicious sites. This strategy has become a significant issue, as highlighted by DNS threat intelligence firm Infoblox. These domains, once expired, are quickly re-registered by threat actors in a practice known as ‘dropcatching’, which allows them to inherit the domain’s past traffic and credibility.
Understanding Dropcatch Domains
During early 2026, an average of 50,400 expired domains were re-registered daily across generic top-level domains (gTLDs) such as ‘.com’. This number rises to about 65,000 when including country code top-level domains (ccTLDs). These dropcatch domains represent nearly 20% of all new registrations, demonstrating the scale of this issue. Infoblox’s report reveals that domains like .net and .xyz lead in dropcatch activity, overshadowing even the ubiquitous .com.
Registrars such as GoDaddy, Namecheap, and DropCatch.com facilitate these re-registrations. They often make use of automated systems to quickly capture domains as soon as they become available again. This rapid re-registration process is crucial, as domains inherit any lingering reputation and connections from their previous existence, which can be manipulated by malicious actors.
Threat Actors and Their Methods
One prominent threat actor, known as Sable Squirrel, has reportedly spent nearly $7 million on acquiring expired domains. These domains are used to support illegal online activities, including sports streaming and gambling, as well as serving as infrastructure for malware distribution. The operations are largely centered in Vietnam, with connections to now-defunct networks like Xoi Lac TV.
Sable Squirrel’s strategic use of these domains includes integrating them into a dual-model system. This involves acquiring expired domains through auctions to leverage their established reputations while simultaneously registering new domains to expand their streaming network. This dual approach enables them to maintain a robust infrastructure for both legitimate-seeming operations and covert malicious activities.
Wider Implications and Future Outlook
Beyond Sable Squirrel, other malicious groups, dubbed ‘scavengers’ by Infoblox, also exploit expired domains. These actors, such as Stuffy Squirrel and Shady Squirrel, control thousands of domains, redirecting traffic to other cybercriminals or using them for fraudulent advertising. This activity highlights the ongoing challenges in domain security and the need for vigilant monitoring and defense strategies.
Infoblox’s findings underscore the importance of securing expired domains to prevent their misuse. As threat actors continue to refine their tactics, cybersecurity professionals must stay proactive in detecting and mitigating these risks. The future will likely see continued innovation in both cyber defense and cybercrime, necessitating constant vigilance and adaptation.
