Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-16 ยท updated: 2026-08-16 ยท tags: [incident, infoblox, sable-squirrel, expired-domains, c2, rats, sports-streaming, gambling, vietnam] ยท confidence: high ยท affected_sectors: [retail, entertainment] ยท au_impact: true

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

  • Source: Infoblox
  • Date: 2026-08-14
  • Reliability: Tier 1/4 โ€” Official / first-party (vendor technical analysis)
  • Entity: "Sable Squirrel" operation, based in Vietnam

Summary

DNS intelligence firm Infoblox disclosed an operation it calls Sable Squirrel, based in Vietnam, which has spent nearly US$7 million acquiring expired ("dropcatch") domains to inherit their registration history, backlinks, residual traffic and reputation for criminal purposes. The infrastructure underlies a large Asian sports-piracy network and online gambling promotion while simultaneously operating as malware command-and-control.

Key Facts

  • ~US$7M spent on expired domains to weaponise inherited trust signals
  • Underlies sports-piracy brands: Xoilac, Cakhia, 90phut, Socolive, MiTom
  • Promotes gambling brands: VSBet, ColaScore, 8xbet
  • Functions as malware C2 for 31,000+ samples: Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT, HiddenTear-signature artifacts
  • Traffic-distribution system redirects users in Vietnam, S. Korea, Japan, Taiwan, Singapore and Australia
  • Android betting apps distributed via compromised Google Play developer accounts
  • Operator hoards 10,000+ domains; 94% weaponised within two weeks of acquisition
  • Confidence: Confirmed (vendor three-part technical analysis)

Impact

High relevance for Australian regulators and platform-enforcement teams: direct consumer-fraud exposure, abused distributed-trust channels, and blurred content-piracy/malware infrastructure.

Related Pages

Sources: Infoblox; raw/digests/Cyber-Digest-2026-08-16