Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
Threat actors are spending heavily – nearly $7 million – on expired domains to build a criminal enterprise focused on illegal sports streaming, online gambling promotion, and malware infrastructure. These ‘dropcatch’ domains, acquired through auctions and purchased directly, inherit reputation, connections, and traffic from their previous owners, allowing threat actors like Sable Squirrel to quickly deploy malicious services and evade security measures. Sable Squirrel, operating across Vietnam and beyond, utilizes these domains to distribute a wide range of malware, including Quasar RAT and AsyncRAT, while simultaneously directing users to gambling platforms. Multiple threat actors, including Stuffy Squirrel and Swiping Squirrel, engage in similar practices, scavenging traffic from compromised domains to fuel their own malicious operations.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
