Written by 3:14 pm Security Views: 0

Hackers Spend More Than $7 Million on Expired Domains to Redirect Users to Scams and Malware

Expired domain scams used by hackers to redirect users to malware

Expired domain scams are becoming a growing cybersecurity threat as hackers spend millions buying expired domains to gain old traffic, backlinks and online trust. According to Infoblox Threat Intel, one threat actor known as Sable Squirrel is estimated to have spent more than $7 million on expired domains.

Hackers Are Buying Expired Domains for Their Old Trust

An expired domain is a web address that was previously registered but was not renewed by its owner. Once the registration period ends, the domain can become available for someone else to register.

Cybercriminals are interested in these domains because they may already have website traffic, backlinks, search history and a good reputation.

Infoblox calls these newly registered expired domains “dropcatch domains.” During the first half of 2026, about 50,400 dropcatch domains were re-registered every day across generic top-level domains (gTLDs). When country-code domains are included, the number reached about 65,000 per day.

Therefore, expired domains have become more than a domain-investment opportunity. They can also become a security risk when criminals use their old reputation to reach new victims.

Sable Squirrel Built a $7 Million Domain Operation

One of the largest examples identified by Infoblox is Sable Squirrel. The threat actor controls more than 10,000 domains and has built a large operation around sports streaming, gambling promotion and malware.

Infoblox confirmed more than $430,000 in purchases across roughly 160 expired domains that could be individually priced. Based on the wider domain inventory, researchers estimate that Sable Squirrel’s total spending on expired domains is more than $7 million.

The group uses expired domains to gain old registration history, backlinks and remaining web traffic. It also uses newly registered lookalike domains to support its streaming network.

More importantly, some of these domains have been used as malware command-and-control (C2) servers. Infoblox identified more than 31,000 malware samples communicating with Sable Squirrel infrastructure, including malware families such as Quasar RAT, AsyncRAT, DCRat, NanoCore and Remcos.

How Expired Domains Become a Security Threat

The danger begins when a criminal registers a domain that still has visitors or links pointing to it.

For example, someone may click an old link expecting to reach a legitimate website. Instead, the domain could redirect the visitor to a scam, unwanted advertising, gambling service or malicious website.

In addition, some expired domains may still have old DNS records, email connections or links from other websites. These leftover connections can provide criminals with useful paths to attract traffic.

Infoblox also identified other threat actors that use expired domains to collect traffic left behind by previously compromised websites. These groups include Stuffy Squirrel, Shady Squirrel and Swiping Squirrel.

The problem can develop quickly. Infoblox found that 24% of dropcatch domains became active on the same day they were registered, 76% became active within seven days and 94% were active within two weeks.

How Businesses Can Protect Expired Domains

Businesses should treat old domains as part of their cybersecurity strategy, even after a website or online project has been closed.

First, companies should keep important domains registered if they still have backlinks, traffic, email connections or brand value. Otherwise, attackers may register them after they expire.

Organizations should also review their domain portfolios regularly and identify domains that are no longer needed. Before allowing a domain to expire, security teams should check its DNS records, email services and links.

In addition, businesses should monitor old domains after a project ends. If a former domain suddenly hosts suspicious content, redirects visitors or appears in malware reports, the organization can take action quickly.

For website owners, the lesson is clear: an expired domain does not always mean an abandoned risk.

Conclusion

The growing use of expired domains shows how cybercriminals can turn old web trust into a security advantage. Sable Squirrel’s estimated $7 million investment demonstrates the scale of the problem.

As a result, domain management is becoming an important part of cybersecurity. Companies should carefully manage their unused domains and avoid letting valuable web addresses fall into the hands of attackers.

Last modified: August 31, 2026

Close