Every day, tens of thousands of domain names expire and re-enter the market. While most fade into obscurity, a sophisticated underground economy has emerged around “dropcatching”—the practice of acquiring these previously owned domains. Infoblox Threat Intel’s three-part investigation reveals how threat actors spend millions to inherit reputation, residual traffic, and trust signals.

In the first half of 2026, Infoblox Threat Intelligence observed an average of more than 50,000 dropcatch domains re-registered daily across generic top-level domains (gTLDs), rising to roughly 65,000 when country-code TLDs are included. Nearly one in five newly registered domains had lived a previous life. These second-life domains do not arrive empty-handed: they often carry historical reputation, backlinks, residual traffic, and the residual trust that security products and algorithms still associate with longevity. Threat actors have noticed—and they are paying handsomely for the privilege.

Domain names expire for ordinary reasons: failed businesses, forgotten renewal notices, mergers that leave ownership unclear, temporary campaigns that outlive their purpose, or bulk registrations abandoned by the same criminals who later scavenge the leftovers. Once the grace and redemption periods pass, the names become available again. Auctions and specialized services such as DropCatch.com facilitate rapid acquisition. The result is a steady stream of aged assets re-entering the namespace under new ownership.

Infoblox’s research demonstrates that this market is neither fringe nor trivial. Approximately 92 percent of observed gTLD dropcatch activity concentrates in just 15 TLDs, following a classic long-tail distribution. Measuring the phenomenon at scale is itself challenging. Creation-date data is inconsistently available—especially among many ccTLDs—and distinguishing a true drop-and-re-registration from a simple transfer requires long historical observation. Infoblox maintains multi-year domain histories precisely to make that distinction.

The commercial logic is clear. A brand-new domain starts with zero reputation. An aged domain may still appear in search indexes, retain inbound links, and benefit from the heuristic bias many defenses apply to older registrations. That inherited legitimacy is valuable. In the second installment of the series, Infoblox attributes the largest documented dropcatch investment budget—estimated north of $7 million—to a single actor cluster the researchers call Sable Squirrel.

Sable Squirrel controls more than 10,000 domains. The majority support a large Asian sports-piracy operation under brands including Xoilac, Cakhia, 90phut, Socolive, and MiTom. These sites present polished live-football streaming experiences complete with schedules, chat rooms, and mobile promotion. Streaming, however, functions primarily as the acquisition funnel. Behind it sit gambling platforms (VSBet, ColaScore, 8xbet and related brands) that the actor appears to control or closely align with. Vietnam forms a clear center of gravity, yet shared back-end services, sports data feeds, image infrastructure, and live-chat components surface around Chinese-language betting brands and campaigns targeting Indonesian and Russian-speaking audiences, suggesting a broader transnational supply chain.

The same inventory is dual-purposed. A subset of these domains also serves as malware command-and-control. Infoblox identified more than 31,000 malware samples—Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, and samples carrying HiddenTear ransomware signatures—connecting to Sable Squirrel infrastructure. In some cases a human visitor sees a live streaming site while an infected endpoint uses the identical domain as a control channel. File properties inside the Windows executables sometimes embed the actor’s own brand names, an unusually brazen signature. A coordinated weaponization wave in late 2025 configured hundreds of existing domains as C2; roughly 12 percent of Infoblox Threat Defense Cloud customer networks subsequently queried those domains, spanning approximately two dozen industries.

Vietnamese enforcement actions in early 2026—including a February site freeze and March charges and seizures—produced only temporary disruption. The operation recovered within a month and expanded coverage around the 2026 World Cup. Domains, not content, proved the resilient asset.

A third class of actors takes the scavenging model further by targeting previously malicious domains rather than merely aged legitimate ones. Infoblox tracks three such “scavenger” clusters—Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel—that acquire expired domains once used in infection chains. Compromised websites often continue to reach out to those domains long after the original operators abandon them. By purchasing the expired names, the scavengers inherit residual victim traffic without needing to compromise new sites themselves.

Stuffy Squirrel specializes in stuffing malicious payloads inside legitimate-looking scripts and has maintained continuous activity since at least 2020 across three generations of traffic-distribution infrastructure, controlling more than 500 domains. Shady Squirrel partners with initial-access brokers and helped enable a rapid SocGholish resurgence after a major disruption operation. Swiping Squirrel, the most prolific of the three, funnels traffic toward zero-click advertising platforms that frequently terminate in scams or malware. Between them, the three actors own thousands of domains embedded across tens of thousands of compromised sites and often coexist on the same victim pages, racing for the visitor.

Collectively, the Dropcatch series illustrates a mature secondary market in digital reputation and residual traffic. Legitimate organizations that lose control of domains through simple operational failures can find themselves effectively held to ransom—Infoblox itself encountered asking prices exceeding $50,000 for a formerly internal name. At the criminal end of the spectrum, the same market supplies aged trust signals, free traffic, and dual-use infrastructure at industrial scale.

Defenders face a structural challenge: reputation systems that still overweight domain age can be gamed, and residual connections from old compromises create persistent attack surface long after the original operators have moved on. Continuous DNS visibility, historical domain tracking, and rapid detection of anomalous re-registration patterns become essential. The domains themselves may be disposable; the economic logic that makes them valuable is not.

By Jakob Jung

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM. Contact via Mail: jakob.jung@security-storage-und-channel-germany.de

Leave a Reply

Your email address will not be published. Required fields are marked *

WordPress Cookie Notice by Real Cookie Banner