Cybercriminals Turn Expired Domains Into Malware and Scam Infrastructure, Infoblox Finds

Cybercriminals Turn Expired Domains Into Malware and Scam Infrastructure, Infoblox Finds
Cybercriminals Turn Expired Domains Into Malware and Scam Infrastructure, Infoblox Finds

Expired internet domains are emerging as a valuable resource for cybercriminals seeking established trust, backlinks and web traffic, according to new research from Infoblox Threat Intel.

The research found that approximately 65,000 previously registered domains are being re-registered each day, based on observations from the first half of 2026. These so-called “dropcatch” domains account for nearly 20% of newly observed domains each day, highlighting the scale of the secondary market around expired web addresses.

Rather than simply registering new domains, threat actors can acquire expired domains with an existing online history and reputation. According to Infoblox, criminals are using these domains to support activities ranging from malware distribution and scams to illegal streaming and online gambling.

$7 Million Spent on More Than 10,000 Domains

One of the investigations identified a threat actor tracked as Sable Squirrel, which Infoblox researchers estimate has spent more than $7 million acquiring over 10,000 expired domains.

The domains have reportedly been used as infrastructure supporting a criminal ecosystem that includes illegal streaming, online gambling and malware distribution. Researchers also found command-and-control infrastructure for multiple remote access trojans (RATs) operating on the same infrastructure associated with illegal content.

The findings indicate that expired domains can provide more than a web address. Their previous reputation and traffic can give attackers an established starting point for malicious operations.

Criminals Also Reclaim Previously Malicious Domains

Infoblox said the threat is not limited to legitimate domains changing ownership.

The company identified three additional threat actors using expired domains that had previously been associated with malicious activity. Researchers found thousands of such dropcatch domains embedded across tens of thousands of compromised websites, where they continued to direct users toward malicious payloads.

One of the actors, tracked as Shady Squirrel, was found using techniques that directed potential victims toward SocGholish, a known “fake update” malware infrastructure. According to the research, Shady Squirrel delivered malware through scareware and call centers before partnering with SocGholish operator TA569 in July.

Expired Domains Become a Cybersecurity Risk

“Expired domains can be a shortcut to both trust and traffic,” said Dr. Renée Burton, VP of Infoblox Threat Intel, noting that the scale of spending and the ways criminals are repurposing expired domains were previously not well understood.

The findings suggest that organizations should consider the history of internet domains and their associated infrastructure as part of their broader cybersecurity risk assessment. A domain that appears legitimate today may have previously belonged to a different organization or may have been associated with malicious activity.

Infoblox Details Three-Part Investigation

Infoblox Threat Intel has published the research as a three-part series.

The first part examines how expired domains can retain trust, reputation and traffic after their original registration expires. The second focuses on the Sable Squirrel operation and its estimated $7 million investment in expired domains. The third profiles three additional threat actors — Stuffy Squirrel, Shady Squirrel and Swiping Squirrel — and examines how they acquire expired malicious domains to inherit traffic from previously compromised websites.

Together, the investigations show how cybercriminal groups can take advantage of infrastructure and online reputation created by previous domain owners — and, in some cases, even infrastructure previously used by other criminals.