Executive Summary
In the first half of 2026, cybercriminals have increasingly exploited expired domains, known as 'dropcatch' domains, to conduct large-scale scams and malware distribution. By re-registering these domains, threat actors inherit their previous reputation and traffic, enabling them to evade detection and effectively target victims. Notably, the group 'Sable Squirrel' invested over $7 million to acquire more than 10,000 such domains, which they utilized for illegal streaming, online gambling, and as command-and-control servers for various malware families, including Quasar RAT and AsyncRAT. This trend underscores a significant shift in cybercriminal tactics, leveraging the residual trust of expired domains to facilitate malicious activities. The prevalence of this method highlights the urgent need for organizations to monitor and manage their domain portfolios proactively, ensuring that expired domains are not left vulnerable to exploitation. Additionally, it emphasizes the importance of enhancing detection mechanisms to identify and mitigate threats originating from re-registered domains.
Why This Matters Now
The exploitation of expired domains by cybercriminals is escalating, with groups like 'Sable Squirrel' investing millions to acquire and misuse these domains for malicious purposes. This trend poses a significant threat to online security, as it allows attackers to leverage the residual trust and traffic of expired domains to conduct scams and distribute malware effectively. Organizations must prioritize monitoring and securing their domain portfolios to prevent such exploitation and enhance their detection mechanisms to identify threats from re-registered domains.
Attack Path Analysis
Threat actors acquired expired domains to inherit their reputation and residual traffic. They then redirected users to malicious sites, escalating privileges by exploiting trust in the domain. Lateral movement occurred as attackers used these domains to distribute malware across networks. Command and control were established through these domains, facilitating persistent access. Exfiltration involved siphoning sensitive data via the compromised domains. The impact included widespread malware infections and financial losses.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Threat actors acquired expired domains to inherit their reputation and residual traffic, enabling them to redirect users to malicious sites.
MITRE ATT&CK® Techniques
Compromise Infrastructure: Domains
Proxy: Domain Fronting
Browser Session Hijacking
Acquire Infrastructure: Domains
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Entertainment/Movie Production
Illegal sports streaming operations using expired domains directly target entertainment content, enabling piracy networks that undermine legitimate streaming revenue and intellectual property rights.
Gambling/Casinos
Threat actors exploit expired domains to funnel traffic to illegal gambling platforms, bypassing regulatory controls and creating unfair competition for licensed operators.
Financial Services
Banking sectors face elevated risks as malware C2 infrastructure on compromised domains targets financial institutions, threatening customer data and transaction security.
Higher Education/Acadamia
Educational institutions are specifically targeted by malware campaigns using expired domain infrastructure, compromising student data and academic network security across multiple institutions.
Sources
- Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malwarehttps://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.htmlVerified
- Expired domains are a goldmine for hackers – and some cyber crime groups are investing millions in 'dropcatch' scams to deliver malwarehttps://www.itpro.com/security/cyber-crime/expired-domains-are-a-goldmine-for-hackers-and-some-cyber-crime-groups-are-investing-millions-in-dropcatch-scams-to-deliver-malwareVerified
- Infoblox: 800,000 domains vulnerable to hijacking attackhttps://www.techtarget.com/searchsecurity/news/366615752/Infoblox-800000-domains-vulnerable-to-hijacking-attackVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to exploit trusted domains, thereby reducing the blast radius and constraining lateral movement within the network.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to leverage expired domains to redirect users to malicious sites would likely be constrained, reducing the initial compromise's effectiveness.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges by exploiting trusted domains would likely be constrained, reducing the scope of unauthorized access.
Control: East-West Traffic Security
Mitigation: The attacker's ability to distribute malware for lateral movement would likely be constrained, reducing the spread within the network.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels through malicious domains would likely be constrained, reducing persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data through compromised domains would likely be constrained, reducing data loss.
The overall impact of the attack, including malware infections and financial losses, would likely be reduced due to constrained attacker activities.
Impact at a Glance
Affected Business Functions
- Online Streaming Services
- Online Gambling Platforms
- Malware Command-and-Control Infrastructure
Estimated downtime: N/A
Estimated loss: $7,000,000
Potential exposure of user data through malicious redirects and malware distribution.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to limit the impact of compromised domains.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
- • Utilize Threat Detection & Anomaly Response to identify and respond to malicious activities promptly.
- • Apply Inline IPS (Suricata) to detect and block known exploit patterns and malicious payloads.
- • Ensure Secure Hybrid Connectivity (DCE) to protect data in transit and prevent unauthorized access.



