Executive Summary

In the first half of 2026, cybercriminals have increasingly exploited expired domains, known as 'dropcatch' domains, to conduct large-scale scams and malware distribution. By re-registering these domains, threat actors inherit their previous reputation and traffic, enabling them to evade detection and effectively target victims. Notably, the group 'Sable Squirrel' invested over $7 million to acquire more than 10,000 such domains, which they utilized for illegal streaming, online gambling, and as command-and-control servers for various malware families, including Quasar RAT and AsyncRAT. This trend underscores a significant shift in cybercriminal tactics, leveraging the residual trust of expired domains to facilitate malicious activities. The prevalence of this method highlights the urgent need for organizations to monitor and manage their domain portfolios proactively, ensuring that expired domains are not left vulnerable to exploitation. Additionally, it emphasizes the importance of enhancing detection mechanisms to identify and mitigate threats originating from re-registered domains.

Why This Matters Now

The exploitation of expired domains by cybercriminals is escalating, with groups like 'Sable Squirrel' investing millions to acquire and misuse these domains for malicious purposes. This trend poses a significant threat to online security, as it allows attackers to leverage the residual trust and traffic of expired domains to conduct scams and distribute malware effectively. Organizations must prioritize monitoring and securing their domain portfolios to prevent such exploitation and enhance their detection mechanisms to identify threats from re-registered domains.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Dropcatch domains are expired domains that have been re-registered by new owners, often to exploit the residual trust and traffic associated with the original domain.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to exploit trusted domains, thereby reducing the blast radius and constraining lateral movement within the network.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to leverage expired domains to redirect users to malicious sites would likely be constrained, reducing the initial compromise's effectiveness.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges by exploiting trusted domains would likely be constrained, reducing the scope of unauthorized access.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's ability to distribute malware for lateral movement would likely be constrained, reducing the spread within the network.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to establish command and control channels through malicious domains would likely be constrained, reducing persistent access.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate sensitive data through compromised domains would likely be constrained, reducing data loss.

Impact (Mitigations)

The overall impact of the attack, including malware infections and financial losses, would likely be reduced due to constrained attacker activities.

Impact at a Glance

Affected Business Functions

  • Online Streaming Services
  • Online Gambling Platforms
  • Malware Command-and-Control Infrastructure
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: $7,000,000

Data Exposure

Potential exposure of user data through malicious redirects and malware distribution.

Recommended Actions

  • Implement Zero Trust Segmentation to limit the impact of compromised domains.
  • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.
  • Utilize Threat Detection & Anomaly Response to identify and respond to malicious activities promptly.
  • Apply Inline IPS (Suricata) to detect and block known exploit patterns and malicious payloads.
  • Ensure Secure Hybrid Connectivity (DCE) to protect data in transit and prevent unauthorized access.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image