Cyber criminals are buying up expired internet domains at scale and reusing them to host malware, illegal streaming services and online gambling platforms, according to new research by Infoblox Threat Intel.
Scale and investment
The analysis found that during the first half of this year roughly 65,000 expired domains were being registered each day, a rate that represents almost one-in-five of all newly observed domains in that period. The report highlights that such re-registered domains—often called "dropcatch" domains—can retain signals of trust, backlinks and existing web traffic that make them attractive to both security filters and users.
“The sheer volume of dropcatch domains is astounding. We’ve known that bad guys buy expired domains to repurpose them, but the way in which they were used, and the amount of money actors are willing to spend wasn’t well understood.” — Renée Burton, VP of Infoblox Threat Intel
Infoblox’s investigators identified a threat actor they named Sable Squirrel, which is estimated to have invested more than $7 million to acquire in excess of 10,000 expired domains. Those domains are reported to be used in support of illegal streaming operations, online gambling and malware distribution.
How criminals exploit expired domains
Researchers say the apparent commercial front of some sites—such as consumer-style streaming portals offering live sport with schedules and chat rooms—masks the real revenue drivers, notably gambling platforms that the operators control. In addition, a substantial number of the re-registered domains have been observed serving as command-and-control (C2) infrastructure for malware.
- Traffic and trust: Expired domains can inherit backlinks and reputation that make detection harder and give them quicker access to users.
- Monetisation: Illegal streaming is used to funnel users toward gambling and betting services controlled by the same operators.
- Technical abuse: Many domains act as C2 for malware, enabling remote control and further distribution of malicious software.
Infoblox reported identifying over 31,000 malware samples that connected to domains associated with Sable Squirrel, underscoring the operational role these assets play in cyber criminal campaigns.
| Metric | Reported figure |
|---|---|
| Expired domains registered per day (H1) | 65,000 |
| Share of newly observed domains | ~20% |
| Estimated investment by Sable Squirrel | $7m+ |
| Domains acquired by Sable Squirrel | 10,000+ |
| Malware samples observed | 31,000+ |
Implications for victims and defenders
Security professionals warn that using previously registered domains short-circuits some of the normal hurdles faced by newly created malicious sites. Reputation-based defences, search engines and threat intelligence products can be misled by historical signals attached to a domain name. That makes both detection and takedown more complicated and increases the risk to organisations and consumers who trust recognised web addresses.
For businesses, the practice raises concerns about brand impersonation and credential theft, while for internet users it increases the chance of exposure to malware or fraudulent betting platforms. The findings also draw attention to the financial sophistication of organised online actors that can deploy large sums to acquire and operate sizeable domain portfolios.
Law enforcement and industry actors commonly rely on a combination of takedown requests, registrar co‑operation and technical mitigation to disrupt abusive domains. The scale reported by Infoblox suggests those approaches may be under strain unless resource and co‑ordination increase.
What the research means going forward
The report underlines a need for greater vigilance around expired domain registration processes, enhanced sharing of reputation data between registries and security vendors, and targeted monitoring of domains with histories that make them attractive to criminals. Given the speed and volume at which dropcatch registrations occur, defenders may also need to invest in automation and threat-hunting capabilities tailored to this type of abuse.
The Infoblox findings do not attribute specific criminal prosecutions, but they offer a detailed picture of a prevalent tactic in contemporary cyber crime and the economic scale behind it. As investigators and businesses digest the data, the balance between domain market dynamics and online safety will be an area for closer scrutiny.