Ethical Hacking News
Threat actors have been spending nearly $7 million on expired domains to redirect traffic to scams and malware. This trend, dubbed "dropcatching," has become a significant concern for cybersecurity experts, as it allows threat actors to inherit the reputation and connections of previously registered domains, making it easier for them to carry out their malicious activities. Read the full story to learn more about the threat actors' exploitation of expired domains and the implications for cybersecurity.
Threat actors are spending nearly $7 million on expired domains to carry out malicious activities. Dropcatching allows threat actors to inherit the reputation and connections of previously registered domains. 50,400 dropcatch domains are registered daily, accounting for nearly 20% of all newly registered domains. Threat actors use dropcatch domains to inherit legitimacy, registration history, inbound traffic, and backlinks. Infoblox has identified three financially motivated scavengers controlling thousands of domains. The exploitation of expired domains poses significant implications for cybersecurity and requires vigilant experts to develop strategies to combat these threats.
Threat actors have been utilizing expired domains as a means to redirect traffic to scams and malware, with nearly $7 million spent on these domains in the first half of 2026 alone. This trend, dubbed "dropcatching," has become a significant concern for cybersecurity experts, as it allows threat actors to inherit the reputation and connections of previously registered domains, making it easier for them to evade security checks and carry out their malicious activities.
The phenomenon of dropcatching has gained significant traction in the generic top-level domains (gTLDs) and country code top-level domains (ccTLDs), with 50,400 dropcatch domains registered daily in the first half of 2026. This number jumps to around 65,000 when ccTLDs are considered, indicating that nearly 20% of all newly registered domains are dropcatch domains. Infoblox, a DNS threat intelligence firm, has given the name "dropcatch domains" to these expired domains, which become available for registration after their original owners fail to renew them.
The acquisition of dropcatch domains by threat actors allows them to inherit the reputation and connections of the original domain holders, making it easier for them to carry out their malicious activities. According to Infoblox, threat actors know that researchers, security products, and reputation-based algorithms view dropcatch domains more favorably than genuine brand-new registrations. This knowledge enables threat actors to take advantage of the inherited reputation and connections to carry out their malicious activities.
One notable example of a threat actor that has been utilizing dropcatch domains is Sable Squirrel, which has spent nearly $7 million on expired domains to build a criminal enterprise spanning illegal sports streaming, online gambling promotion, and malware infrastructure. Sable Squirrel's operation involves purchasing dropcatch domains at auctions through registrars like GoDaddy, Namecheap, and DropCatch.com, and then using these domains to inherit the legitimacy of their predecessors, as well as their registration history, inbound traffic, and backlinks.
The threat actor's operation also involves using freshly registered lookalikes to run the streaming fleet, in addition to the dropcatch domains. This two-track domain model allows Sable Squirrel to acquire and utilize both the inherited reputation and connections of the original domain holders, as well as the freshly registered lookalikes, to carry out its malicious activities.
Infoblox has identified three financially motivated scavengers that control thousands of domains and hijack residual traffic from expired, previously compromised domains to power scam and malware ecosystems. These threat actors, known as Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel, operate a race to acquire victims, redirecting the same compromised domain to different dropcatch actors depending on the website visitor characteristics, timing, and other factors.
The threat actors' ability to acquire and utilize dropcatch domains has significant implications for cybersecurity. As dropcatch domains become increasingly popular, threat actors will continue to find new ways to exploit them, making it essential for cybersecurity experts to stay vigilant and develop strategies to combat these threats.
In conclusion, the exploitation of expired domains by threat actors has become a significant concern in the war on cybersecurity. The nearly $7 million spent on dropcatch domains in the first half of 2026 alone highlights the severity of this issue, and the need for cybersecurity experts to develop strategies to combat these threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Threat-Actors-Exploitation-of-Expired-Domains-A-New-Front-in-the-War-on-Cybersecurity-ehn.shtml
https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html
Published: Mon Aug 17 07:18:57 2026 by llama3.2 3B Q4_K_M