A sophisticated cybercriminal operation has spent nearly $7 million acquiring expired domains to build a sprawling criminal enterprise spanning illegal sports streaming, online gambling promotion, and malware infrastructure, according to a comprehensive three-part report published by DNS threat intelligence firm Infoblox in August 2026. The report reveals that threat actors are purchasing expired domains on an industrial scale to inherit the website traffic and reputation of their predecessors, then redirecting victims to scams and malicious software. Infoblox has coined the term "dropcatch domains" for these recycled web addresses that get a second life when an expired domain becomes available for registration and is then snapped up by another party.

During the first half of 2026, 50,400 dropcatch domains were re-registered each day in generic top-level domains like ".com" alone, a figure that climbs to around 65,000 when country code top-level domains are included. These recycled domains account for nearly 20% of all daily gTLD and ccTLD registrations, meaning one out of five newly registered domains is a dropcatch domain. At the TLD level, .net and .xyz lead in dropcatch activity, surpassing .com, which ranks third. Other prominent TLDs include .org, .vip, .online, .store, .site, .app, and .shop. Most of these domains are re-registered via registrars like GoDaddy, Namecheap, and DropCatch.com, with each accounting for 5,246, 4,385, and 3,568 median daily dropcatch domains respectively. Once acquired, the dropcatch domains are swiftly weaponized: 24% go live the same day, 76% by seven days, and 94% by the end of two weeks.

"These domains can be particularly interesting, even dangerous, because they inherit reputation and sometimes connections from their previous life," Infoblox stated in the report. The threat intelligence firm explained that researchers, security products, and reputation-based algorithms may view recycled domains more favorably than a genuinely brand-new registration, and threat actors know this and take advantage of it. The report identifies a major threat actor called Sable Squirrel, assessed to have spent nearly $7 million so far on expired domains, controlling more than 10,000 domains that act as a backbone for a large Asian sports piracy operation under brands such as Xoilac, Cakhia, 90phut, Socolive, and MiTom. No less than 31,000 malware samples, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT, and artifacts bearing HiddenTear ransomware signatures, have communicated with Sable Squirrel's infrastructure.

The report explains that for threat actors specifically, the inherited reputation isn't the only thing valuable about acquiring a dropped domain. They also come with a variety of lingering connections: email intended for the original domain holder, cached search results, inherited web traffic, and in some cases, a ready-made platform for code injection on already compromised sites. Evidence points to Vietnam being the epicenter of the Sable Squirrel operation, sharing strong overlaps with Xoi Lac TV, an illegal streaming network that was dismantled by Vietnamese authorities in March 2026. The threat actor operates a two-track domain model: buying expired domains at auctions to inherit legitimacy, registration history, inbound traffic, and backlinks, along with freshly registered lookalikes used to run the streaming fleet. Among the dropcatch domains acquired are healthymagination.com, a health initiative launched by General Electric in 2009; maxfactor-international.com, a cosmetics brand owned by Procter & Gamble; krogeralbertsons.com, a domain created for the proposed Kroger and Albertsons merger in 2022; and rezilion.com, a now-defunct cybersecurity company whose core assets were purchased by GitLab in 2024.

Sable Squirrel is just one of many threat actors that acquire expired domains wholesale to run streaming-to-gambling businesses and malware operations simultaneously, the report notes. Infoblox is tracking three additional financially motivated scavengers who control thousands of domains and fraudulently acquire the traffic and resell it to other services: Stuffy Squirrel, active since at least 2020 and controlling over 500 domains; Shady Squirrel, a Russian-speaking threat actor active since at least July 2023 and controlling over 700 domains; and Swiping Squirrel, active since at least 2022 and controlling over 3,000 domains. "Instead of compromising websites themselves, these actors acquire expired domains and immediately begin receiving traffic from the infection chains their predecessors left behind," the report states. "Then they inject their own content. They are, in effect, scavengers." The cybersecurity firm notes that the same back-end services, sports data feeds, image infrastructure, and live chat components that power the Vietnamese streaming fleet also surface around Chinese-language betting brands and adjacent campaigns aimed at Indonesian and Russian-speaking audiences. Organizations that rely too heavily on domain age and historical reputation as trust signals may find themselves systematically bypassed by adversaries who've learned to purchase legitimacy rather than earn it.