Securityaffairs.Co
Cybercriminals Exploit Expired Domains for Malware and Scams
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Cybercriminals are investing millions in acquiring expired domains, leveraging their existing trust and traffic for malicious activities. According to Infoblox Threat Intel, around 65,000 expired domains are registered daily, with actors like Sable Squirrel spending over $7 million on more than 10,000 domains for illegal streaming and malware distribution. These domains are often used to host seemingly legitimate sites while serving as command and control channels for malware such as Quasar RAT and HiddenTear ransomware. Another group, Shady Squirrel, is using these domains in conjunction with the SocGholish infrastructure to deliver malware through scareware tactics. The repurposing of these domains poses significant risks, potentially exceeding those associated with newly registered domains.
Key Points: • Cybercriminals are spending millions on expired domains for illicit activities. • Approximately 65,000 expired domains are registered daily, facilitating malware delivery. • Groups like Sable Squirrel and Shady Squirrel are identified as major players in this scheme.