Expired Domains Have a Criminal Afterlife, and the Price Tag Runs to Millions

Every day, roughly 65,000 internet domains are re-registered the moment they expire. New research from Infoblox Threat Intel traces a mature criminal market in which threat actors spend millions acquiring the inherited trust, backlinks, and traffic of those addresses — and immediately redirecting them to malware, illegal streaming, scams, and online gambling.

The scale of the problem has been visible in aggregate for years. What the three-part research series published this week adds is operational detail. Dropcatch domains — those captured within seconds of expiration — represented nearly 20 per cent of all newly observed domains in the first half of 2026. Many arrive already embedded in backlink networks, indexed by search engines, and trusted by spam filters their original owners never thought to cancel.

One threat actor, tracked internally as Sable Squirrel, spent more than $7 million acquiring over 10,000 such domains to build an ecosystem spanning illegal streaming services, online gambling operations, and malware distribution. The same infrastructure runs command-and-control nodes for multiple remote access trojans, a consolidation that shows how far this business model has moved beyond opportunistic domain parking.

"The sheer volume of dropcatch domains is astounding. We've known that bad guys buy expired domains to repurpose them, but the way in which they were used, and the amount of money actors are willing to spend wasn't well understood," said Dr. Renée Burton, VP of Infoblox Threat Intel. "Expired domains can be a shortcut to both trust and traffic, making dropcatch domains a higher risk than the average newly registered domain."

Three additional actors work a different angle. Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel acquire domains that were previously malicious, inheriting the victim traffic already flowing to those addresses from compromised websites. Shady Squirrel was delivering malware through scareware and call centres before partnering in July 2026 with TA569, the operator of SocGholish — the fake-update framework that was the target of Operation Endgame in June.

The research covers the full ecosystem across three instalments: mechanics of how expired domains retain SEO value and trust signals; the Sable Squirrel investigation; and the three actors exploiting previously malicious infrastructure. Indicators of compromise are published on GitHub and feed directly into Infoblox's DNS Detection and Response product. Infoblox counts the majority of Fortune 100 companies among its 5,700-plus customers.

To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter

More News