Urgent.News

What's breaking now, across thousands of outlets.

Editions

Tech

Even dead websites aren't safe — experts warn hackers are spending millions on expired domains to enable malware scams

Roughly 65,000 expired domains change hands every day, and researchers have found one crime group spending an estimated $7 million on them to inherit the trust that comes attached to them.

Even dead websites aren't safe — experts warn hackers are spending millions on expired domains to enable malware scams

Experts are sounding the alarm about the risks posed by expired domains, which could still be used for malware scams. Infoblox Threat Intel found that around 65,000 expired domains are re-registered each day in the first half of 2026, which is nearly one in five of all new registrations. One actor, dubbed Sable Squirrel, controls over 10,000 domains and has spent over $7 million buying expired names for their inherited traffic and authority.

Expired domains are valuable because they come with a history that can benefit new owners, such as age, inbound links, search visibility, and reputation. This history has become a commodity, with at least one criminal operation buying it in bulk. The study, published in three parts, focuses on dropcatch domains, which are names that lapsed, were released back to the registry, and were then re-registered by someone else.

Infoblox counted an average of 50,400 such re-registrations a day in the first half of 2026, rising to roughly 65,000 once country-code domains are included.

While some of these domains are likely small-scale operations, Infoblox identified an entity called Sable Squirrel that controls more than 10,000 domains. These domains support a large Vietnamese-language sports piracy operation under brands like Xoilac, Cakhia, and 90phut. Sable Squirrel is estimated to have spent around $7 million on expired domains, making it the largest domain acquisition budget identified for a single actor in the industry.

Infoblox also discovered that some of these streaming domains are used as malware command and control structures while still serving live football to human visitors. Over 31,000 samples identified were linked to Sable Squirrel's infrastructure, including malware such as Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, and njRAT, as well as ransomware signatures. The operator's carelessness made it easier to identify the malware, as many samples carry the actor's brand names in their Windows executable metadata.

Law enforcement has made some progress, freezing some of the flagship sites in February 2026 and charging 30 suspects in March. They also seized assets worth around $12 million. However, Sable Squirrel seems to have survived and continued to expand, acquiring and running World Cup-centric domains since June. This shows that while law enforcement is targeting these operations, they still manage to persist and grow, mainly due to the high value of domain authority.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

More from Friday 21 August →