Hackers Exploit Expired Domains, Spending Millions to Redirect Traffic to Scams and Malware
Cybercriminals are acquiring expired domain names, known as 'dropcatch domains,' to leverage their existing reputation and traffic for malicious purposes, with one actor spending nearly $7 million.

Threat actors are increasingly exploiting a tactic known as 'dropcatching' to acquire expired domain names, aiming to inherit their established reputation and existing traffic to redirect unsuspecting users towards scams and malware. DNS threat intelligence firm Infoblox has identified this practice, where domains that were once legitimate are re-registered by malicious actors to serve their nefarious purposes.
During the first half of 2026, a staggering 50,400 dropcatch domains were re-registered daily across generic top-level domains (gTLDs) like .com. When country-code top-level domains (ccTLDs) are included, this figure rises to approximately 65,000 daily registrations. This means that one in every five newly registered domains is a dropcatch domain, highlighting the scale of this emerging threat.
These domains are particularly attractive to attackers because they often retain a degree of trust from search engines, security products, and reputation-based algorithms. "Researchers, security products, and reputation-based algorithms may view it more favorably than a genuinely brand-new registration. Threat actors know this and take advantage of it," Infoblox noted in its analysis. This inherited trust allows malicious campaigns to appear more legitimate, increasing their chances of success.
The analysis by Infoblox reveals that .net and .xyz TLDs are seeing the highest volume of dropcatch activity, surpassing the more common .com. Other popular TLDs include .org, .vip, .online, .store, .site, .app, and .shop. Major domain registrars such as GoDaddy, Namecheap, and DropCatch.com are frequently used for these re-registrations, with each handling thousands of median daily dropcatch domains.
Domain expiration and subsequent re-registration follow specific policies. After a domain expires, there is typically a grace period during which the original registrant can renew it. If this period passes without renewal, the domain becomes available for public registration. Services like DropCatch.com specialize in tracking these expiring domains and automatically attempting to register them for clients who have placed backorders. In competitive scenarios where multiple parties are interested, domains can go to auction.
While defenders may intentionally acquire expired domains to prevent misuse, the practice becomes a significant security concern when malicious actors gain control. Beyond inherited reputation, these domains can come with lingering connections such as active email forwarding, cached search results, residual web traffic, and even existing code injection vulnerabilities on previously compromised sites. Lingering DNS records can also present opportunities for attackers.
One notable threat actor, identified as Sable Squirrel, has reportedly spent nearly $7 million on expired domains to build a criminal enterprise. This operation spans illegal sports streaming, online gambling promotion, and malware infrastructure. The acquired domains provide aged registration history, backlinks, residual traffic, and reputation signals that are often trusted by security defenses.
Evidence suggests Vietnam is a central hub for Sable Squirrel's operations, with strong ties to illegal streaming networks like Xoi Lac TV. The threat actor controls over 10,000 domains, primarily used to promote sports piracy under brands such as Xoilac and Cakhia, while simultaneously pushing betting services like VSBet and 8xbet. These platforms are promoted across social media and compromised websites, redirecting users to illicit streaming sites via a traffic distribution system (TDS). The operation also extends to publishing malicious Android apps on the Google Play Store, with attackers repeatedly creating new developer accounts as old ones are suspended.