Attackers are buying expired domains to inherit trust and traffic
Expired domains are no longer just an SEO market. According to The Hacker News coverage of Infoblox research, threat actors are buying old domains because they inherit traffic, reputation, backlinks, and leftover trust from previous owners.
How the domain market becomes attack infrastructure
Infoblox calls these re-registered domains “dropcatch domains”: names that expired, passed through a recovery window, and were registered again by someone else. In the first half of 2026, Infoblox saw about 50,400 such domains re-registered daily in generic TLDs like .com, and around 65,000 per day when country-code TLDs were included.
That flow is large enough to matter for defenders. Infoblox says roughly one in five newly registered gTLD and ccTLD domains is a dropcatch domain. The most active TLDs in the dataset included .net and .xyz ahead of .com, with other active zones including .org, .vip, .online, .store, .site, .app and .shop.

Sable Squirrel and the two-track model
The report tracks the main operation as Sable Squirrel. Infoblox assesses that it has spent nearly $7 million on expired domains and hoards more than 10,000 domains. The infrastructure is tied to illegal sports streaming, online gambling promotion, and malware command-and-control.

The operation appears to use two tracks at once: buying expired domains through services and registrars such as DropCatch.com, GoDaddy, Namecheap, and Dynabot, while also registering fresh lookalike domains for the streaming fleet. The old domains bring reputation and traffic; the new domains help scale the brand network.
Infoblox linked the operation to sports piracy brands such as Xoilac, Cakhia, 90phut, Socolive and MiTom, with betting services including VSBet, ColaScore and 8xbet. Users in Vietnam, South Korea, Japan, Taiwan, Singapore and Australia were selectively redirected through a traffic distribution system.
Where malware enters the story
This is not only traffic arbitrage. The same infrastructure has been connected to at least 31,000 malware samples, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT and artifacts with HiddenTear ransomware signatures. Some streaming domains also acted as C2 servers while still showing streaming content to visitors.
One example is cel-robox[.]com, previously associated with a desktop 3D printer company. Infoblox says Sable Squirrel later used it as both an illegal streaming site and a Quasar RAT C2 server. Other acquired domains had histories tied to GE, Procter & Gamble, Sony PlayStation tooling, a failed Kroger-Albertsons merger domain, and a defunct cybersecurity company.
What defenders should track
- Ownership changes on domains that still receive real traffic.
- Sudden DNS, hosting, content or redirect-chain changes.
- Old domains that become active immediately after re-registration.
- Traffic distribution systems that show different content to users and scanners.
- Security rules that rely too heavily on domain age or reputation.
Infoblox also tracks other “scavenger” actors that buy expired or previously compromised domains and resell the traffic into scam, malware, or affiliate ecosystems. The pattern is clear: attackers are not only registering throwaway domains. They are buying history.