type: incident ยท created: 2026-08-16 ยท updated: 2026-08-16 ยท tags: [incident, infoblox, sable-squirrel, expired-domains, c2, rats, sports-streaming, gambling, vietnam] ยท confidence: high ยท affected_sectors: [retail, entertainment] ยท au_impact: true
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
- Source: Infoblox
- Date: 2026-08-14
- Reliability: Tier 1/4 โ Official / first-party (vendor technical analysis)
- Entity: "Sable Squirrel" operation, based in Vietnam
Summary
DNS intelligence firm Infoblox disclosed an operation it calls Sable Squirrel, based in Vietnam, which has spent nearly US$7 million acquiring expired ("dropcatch") domains to inherit their registration history, backlinks, residual traffic and reputation for criminal purposes. The infrastructure underlies a large Asian sports-piracy network and online gambling promotion while simultaneously operating as malware command-and-control.
Key Facts
- ~US$7M spent on expired domains to weaponise inherited trust signals
- Underlies sports-piracy brands: Xoilac, Cakhia, 90phut, Socolive, MiTom
- Promotes gambling brands: VSBet, ColaScore, 8xbet
- Functions as malware C2 for 31,000+ samples: Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT, HiddenTear-signature artifacts
- Traffic-distribution system redirects users in Vietnam, S. Korea, Japan, Taiwan, Singapore and Australia
- Android betting apps distributed via compromised Google Play developer accounts
- Operator hoards 10,000+ domains; 94% weaponised within two weeks of acquisition
- Confidence: Confirmed (vendor three-part technical analysis)
Impact
High relevance for Australian regulators and platform-enforcement teams: direct consumer-fraud exposure, abused distributed-trust channels, and blurred content-piracy/malware infrastructure.
Related Pages
- German Banking Hack Arrests โ related fraud/financial-crime context
Sources: Infoblox; raw/digests/Cyber-Digest-2026-08-16