Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-16 ยท updated: 2026-08-16 ยท tags: [] ยท confidence: high ยท affected_sectors: [retail, telecommunications, technology, media] ยท au_impact: true

Hackers Spend ~$7M on Expired Domains to Redirect Traffic to Scams and Malware

Summary

DNS intelligence firm Infoblox detailed an operation it calls Sable Squirrel, based in Vietnam, that has spent nearly US$7 million acquiring expired ("dropcatch") domains so their inherited reputation, traffic and backlinks could be repurposed for illegal sports streaming, online gambling promotion and, in parallel, as malware command-and-control for 31,000+ samples.

Key Details

  • Date: 2026-08-14
  • Source: Infoblox
  • Reliability: Tier 1/4 โ€” Official / first-party (vendor technical analysis)
  • Status: Confirmed (vendor three-part technical analysis with named infrastructure)
  • Model: Inherit domain reputation/backlinks/traffic for criminal use
  • Fronts: Asian sports-piracy brands (Xoilac, Cakhia, 90phut, Socolive, MiTom); gambling brands (VSBet, ColaScore, 8xbet)
  • Malware C2: 31,000+ samples including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT; HiddenTear-signature artifacts
  • Scale: 10,000+ domains hoarded; 94% weaponised within two weeks of acquisition
  • Distribution: Traffic-distribution system targeting Vietnam, South Korea, Japan, Taiwan, Singapore and Australia; Android apps via compromised Google Play developer accounts

Significance

Sable Squirrel weaponises expired-domain reputation and trusted distribution channels (Google Play, social media) to funnel traffic to scams while masking malware C2 behind legal-looking streaming/gambling front-ends โ€” an example of adversaries commoditising trust signals. Directly targets Australian users, making it relevant to ACSC and platform-enforcement teams.

Related