{"id":917,"date":"2026-08-29T06:57:41","date_gmt":"2026-08-29T06:57:41","guid":{"rendered":"https:\/\/allcloudhost.net\/blogs\/?p=917"},"modified":"2026-08-18T01:28:32","modified_gmt":"2026-08-18T01:28:32","slug":"expired-domain-hijacking-sable-squirrel","status":"publish","type":"post","link":"https:\/\/allcloudhost.net\/blogs\/expired-domain-hijacking-sable-squirrel\/","title":{"rendered":"A Threat Actor Spent $7 Million Buying Expired Domains. Here&#8217;s the Business Model."},"content":{"rendered":"<h2>The moment your domain lapses, it becomes worth money to someone else<\/h2>\n<p>Every day, roughly 50,400 domains across generic top-level domains expire and get re-registered by someone other than the original owner, a figure that climbs to about 65,000 when country-code domains are included, according to threat intelligence research from Infoblox. That&#8217;s not a small edge case. It represents around one in five of all daily domain registrations across those TLDs. Most of those &#8220;dropcatch&#8221; domains are unremarkable, small sites or forgotten side projects nobody misses. Some of them used to belong to real companies, and a threat actor Infoblox tracks under the name Sable Squirrel has turned buying those specific ones into a $7 million business.<\/p>\n<h2>What you&#8217;re actually buying when you register an expired domain<\/h2>\n<p>The reason an expired domain is worth anything to a criminal operation isn&#8217;t the name itself. It&#8217;s everything the name accumulated while someone else owned it: search engine reputation built over years, residual traffic from old bookmarks and links, cached search results still pointing at it, backlinks from other sites that never got updated, and sometimes email still addressed to the previous owner. Infoblox describes this directly: a re-registered domain comes with &#8220;a variety of lingering connections,&#8221; inherited trust signals a brand-new domain could never buy at any price. Sable Squirrel&#8217;s operation controls more than 10,000 of these domains, wired into sports-piracy brands (Xoilac, Cakhia, 90phut, Socolive, MiTom) and betting platforms (VSBet, ColaScore, 8xbet) aimed primarily at audiences in Vietnam, South Korea, Japan, Taiwan, Singapore, and Australia.<\/p>\n<p>The domains Infoblox identified as part of this specific operation aren&#8217;t random strings. They include healthymagination[.]com, a former General Electric health initiative domain; maxfactor-international[.]com, once tied to Procter &#038; Gamble&#8217;s cosmetics brand; krogeralbertsons[.]com, connected to the grocery chains&#8217; merger; snsystems[.]com, formerly Sony PlayStation developer tooling; rezilion[.]com, a cybersecurity firm whose assets GitLab acquired; and cel-robox[.]com, a former 3D printer company&#8217;s domain now doing double duty as both a piracy streaming site and malware command-and-control infrastructure. Every one of those domains carried real, earned reputation from a legitimate business before it lapsed.<\/p>\n<h2>How fast it gets weaponized once it&#8217;s caught<\/h2>\n<p>Infoblox&#8217;s data shows this isn&#8217;t a slow process. Almost a quarter of re-registered domains, 24%, go live with new content the same day they&#8217;re caught. Three-quarters, 76%, are active within a week. Ninety-four percent are operational within two weeks. There&#8217;s essentially no window between a domain lapsing and someone putting it to use; automated &#8220;dropcatch&#8221; services and backordering systems exist specifically to compete for these domains the moment they free up, sometimes running competitive auctions among multiple interested buyers within hours of expiration.<\/p>\n<p>Once live, the redirection techniques are deliberately hard to spot from the outside. Traffic distribution systems route legitimate visitors toward betting platforms. Cloaking chains send unintended audiences to dead-end pages instead of the actual payload, so a casual check of the domain looks harmless. Some domains, like the one Infoblox calls &#8220;6789x[.]site,&#8221; route users differently depending on their geographic location, and serve different content to bots than to humans specifically to hide the operation from automated security scanners. Infoblox also found 31,000 distinct malware samples, including well-known remote-access trojans like Quasar RAT, AsyncRAT, DCRat, NanoCore, and Remcos RAT, that have communicated with infrastructure tied to these domain operations. Victims identified across education, IT consulting, government, healthcare, and banking sectors reached that malware infrastructure through what looked, on the surface, like an ordinary streaming or content site.<\/p>\n<h2>The registrars where this activity concentrates<\/h2>\n<p>Infoblox&#8217;s research names the registrars where the highest daily volume of dropcatch domains actually gets re-registered: GoDaddy (a median of 5,246 dropcatch domains daily), Namecheap (4,385 daily), and DropCatch.com itself (3,568 daily), a service purpose-built for competitively re-registering expiring domains through automated backordering. That volume reflects the overall size and market share of those registrars more than it implicates any of them individually in wrongdoing, but it&#8217;s a useful reminder that the mechanics enabling this, fast, automated, low-friction domain re-registration, are the same mechanics that make registering a new domain quick and easy for anyone.<\/p>\n<h2>What this means if you own a domain, not just if you&#8217;re buying one<\/h2>\n<p>The obvious lesson, don&#8217;t let your own domains expire by accident, is real but incomplete on its own. The less obvious one is that an old, retired domain your business no longer uses, an acquired brand, a discontinued product line, a rebrand&#8217;s former name, is exactly the kind of asset this research shows criminals specifically hunt for, precisely because it still carries reputation and inbound links your current site doesn&#8217;t have yet. Businesses often let those old domains lapse deliberately once they stop using them, without realizing that&#8217;s the moment they become someone else&#8217;s infrastructure instead of just disappearing.<\/p>\n<p>A few concrete habits follow directly from how this operation works. Keep every domain your business has ever used, current or retired, on auto-renewal with payment details that don&#8217;t go stale, rather than assuming an unused domain is safe to abandon. Enable registrar-level locking to prevent unauthorized transfers, and use multi-factor authentication on the registrar account itself, since account compromise is a faster path to hijacking than waiting for an expiration date. If a domain genuinely has no future use to your business, redirect it to your current site or park it with your registrar rather than letting registration lapse, since a domain you deliberately release is functionally identical, to a buyer like Sable Squirrel, to one you forgot about. If you&#8217;re registering a new domain for your business, using a straightforward <a href=\"https:\/\/allcloudhost.net\/cheap-domain-registration\/\">domain registration service<\/a> that makes auto-renewal and locking simple by default removes one of the easiest ways this kind of hijacking happens in the first place.<\/p>\n<h2>How this differs from typosquatting, and why the distinction matters<\/h2>\n<p>It&#8217;s worth separating this from a more familiar threat, typosquatting, where someone registers a misspelled variant of a live brand&#8217;s domain (like &#8220;amaz0n.com&#8221;) to catch mistyped traffic. Dropcatching is a different mechanism entirely: the domain isn&#8217;t a lookalike, it&#8217;s the real, previously legitimate domain, re-registered the moment the original owner stops paying for it. That means standard trademark-based defenses built for typosquatting, watching for confusingly similar new registrations, don&#8217;t catch this at all, because there&#8217;s nothing confusingly similar about a domain a company used to own outright. The only defense that actually works is not letting the domain lapse in the first place, or catching the re-registration within the same narrow window the criminals are working in.<\/p>\n<h2>A short checklist before registering any domain that isn&#8217;t brand-new<\/h2>\n<p>For a business picking up a domain with any prior history, whether it&#8217;s a rebrand target, an acquisition, or just a name that happened to be available, a few quick checks catch most of the obvious risk before it becomes your problem. Run the domain through the Wayback Machine to see what it was previously used for and by whom. Check current blocklist and reputation services to confirm it isn&#8217;t already flagged for spam or malware distribution, since that reputation, good or bad, transfers to whoever registers it next. Search the domain name alongside terms like &#8220;scam,&#8221; &#8220;phishing,&#8221; or &#8220;malware&#8221; to catch recent coverage a reputation checker might not have indexed yet. None of these take more than a few minutes, and all three would have flagged several of the domains in Infoblox&#8217;s report before a legitimate business risked building anything on top of them.<\/p>\n<p>The broader pattern behind all of this is that domain reputation is a real, transferable asset, valuable enough that a criminal operation will spend seven figures acquiring it deliberately. Treating an old, retired, or about-to-expire domain with the same care as an active one, rather than as something that quietly stops mattering once a business moves on, is the cheapest insurance against becoming raw material for someone else&#8217;s infrastructure.<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/08\/hackers-spend-nearly-7-million-on.html\" target=\"_blank\" rel=\"noopener\">Source: The Hacker News<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The moment your domain lapses, it becomes worth money to someone else Every day, roughly 50,400 domains across generic top-level domains expire\u2026<\/p>\n","protected":false},"author":2,"featured_media":916,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":0,"rank_math_title":"Expired Domain Hijacking: The $7M Business Model Behind It","rank_math_description":"A group called Sable Squirrel spent $7M buying expired domains to build scam and malware infrastructure. Here's how it works and how to protect your domain.","rank_math_focus_keyword":"expired domain hijacking, domain hijacking prevention, protect domain from expiring","rank_math_canonical_url":"","rank_math_robots":[],"footnotes":""},"categories":[9],"tags":[],"class_list":["post-917","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-domains"],"_links":{"self":[{"href":"https:\/\/allcloudhost.net\/blogs\/wp-json\/wp\/v2\/posts\/917","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/allcloudhost.net\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/allcloudhost.net\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/allcloudhost.net\/blogs\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/allcloudhost.net\/blogs\/wp-json\/wp\/v2\/comments?post=917"}],"version-history":[{"count":1,"href":"https:\/\/allcloudhost.net\/blogs\/wp-json\/wp\/v2\/posts\/917\/revisions"}],"predecessor-version":[{"id":961,"href":"https:\/\/allcloudhost.net\/blogs\/wp-json\/wp\/v2\/posts\/917\/revisions\/961"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/allcloudhost.net\/blogs\/wp-json\/wp\/v2\/media\/916"}],"wp:attachment":[{"href":"https:\/\/allcloudhost.net\/blogs\/wp-json\/wp\/v2\/media?parent=917"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/allcloudhost.net\/blogs\/wp-json\/wp\/v2\/categories?post=917"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/allcloudhost.net\/blogs\/wp-json\/wp\/v2\/tags?post=917"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}