Cybercriminals Exploit Expired Domains for Malware and Scams

Cybercriminals Exploit Expired Domains for Malware and Scams

First seen 15 Aug 2026, 18:49 UTC ScworldSecurityaffairs.Cowww.itpro.com 83% similarity 66.5

Article Content

Browse articles
ThreatCluster

Cybercriminals are investing millions in acquiring expired domains, leveraging their existing trust and traffic for malicious activities. According to Infoblox Threat Intel, around 65,000 expired domains are registered daily, with actors like Sable Squirrel spending over $7 million on more than 10,000 domains for illegal streaming and malware distribution. These domains are often used to host seemingly legitimate sites while serving as command and control channels for malware such as Quasar RAT and HiddenTear ransomware. Another group, Shady Squirrel, is using these domains in conjunction with the SocGholish infrastructure to deliver malware through scareware tactics. The repurposing of these domains poses significant risks, potentially exceeding those associated with newly registered domains.

Key Points: • Cybercriminals are spending millions on expired domains for illicit activities. • Approximately 65,000 expired domains are registered daily, facilitating malware delivery. • Groups like Sable Squirrel and Shady Squirrel are identified as major players in this scheme.

ThreatCluster AI How this analysis works

Timeline

Recent
Cybercriminals invest in expired domains
Cybercriminals are acquiring expired domains to exploit their trust and traffic for malware and scams.
Scworld
Recent
Sable Squirrel identified
An investigation revealed that Sable Squirrel spent over $7 million on 10,000 expired domains for illegal activities.
Scworld
Recent
Shady Squirrel's operations linked to SocGholish
Shady Squirrel is using expired domains in collaboration with the SocGholish infrastructure to deliver malware.
Scworld

Community

Browse all →

Tracked Entities in This Story