Techitup Middle East
Cybersecurity

Infoblox Exposes Threats Hidden in Expired Domains

⏱️ 4 min read

Thousands of internet domains expire and are re-registered every day. Infoblox Threat Intel observed around 65,000 re-registered, or “dropcatch,” domains daily in the first half of 2026—accounting for nearly 20% of newly observed domains.

According to Infoblox, threat actors can use these domains to inherit the trust, backlinks and traffic built by their previous owners. The market also extends to domains with a known malicious history. New Infoblox research examines how expired domains are repurposed and identifies several previously unknown malicious actors.

How Cybercriminals Use Expired Domains

One investigation by Infoblox uncovered a threat actor dubbed Sable Squirrel. Infoblox researchers estimate that the group has spent more than $7 million acquiring over 10,000 expired domains. The domains support a criminal network involved in illegal streaming, online gambling and malware distribution, showing how expired domains have become valuable infrastructure for cybercriminals.

Infoblox also found that Sable Squirrel operates command-and-control (C2) servers for multiple remote access trojans (RATs) on the same infrastructure used for illegal content.

Join the Techitup Executive Network

    While Sable Squirrel acquires legitimate domains to benefit from their existing reputation, Infoblox found that other threat actors take over previously compromised domains with a known malicious history.

    Across three other newly identified threat actors, Infoblox Threat Intel identified thousands of dropcatch domains embedded in tens of thousands of compromised websites, continuing to redirect victims to malicious content and malware.

    Most notably, the research uncovered one actor who uses tactics to deliver potential victims to SocGholish, the notorious “fake update” infrastructure which was the target of Operation Endgame in June 2026. This threat actor, tracked as Shady Squirrel by Infoblox Threat Intel, delivered malware through scareware and call centers before partnering up with SocGholish’s operator TA569 in July.

    “The sheer volume of dropcatch domains is astounding. We’ve known that bad guys buy expired domains to repurpose them, but the way in which they were used, and the amount of money actors are willing to spend wasn’t well understood.” said Dr. Renée Burton, VP of Infoblox Threat Intel. “Expired domains can be a shortcut to both trust and traffic, making dropcatch domains a higher risk than the average newly registered domain.”


    Related posts