$7 Million in Expired Domains Fuel a Streaming Empire with a Malware Secret
Sable Squirrel is an Asian threat actor that has spent an estimated $7 million acquiring expired domains with legitimate histories to build a vertically integrated criminal operation spanning illegal sports streaming, online gambling, and malware C2. Over 31,000 malware samples across multiple RAT families and HiddenTear ransomware connect to Sable Squirrel domains, with a coordinated wave in late 2025 converting roughly 350 existing streaming domains into dual-use C2 infrastructure. The operation shares brands, infrastructure, and PE metadata across streaming, gambling, and malware components, indicating a single operator rather than loosely affiliated campaigns.
- domain6789x[.]siteActor-controlled traffic distribution system (TDS) and cloaking domain that routes real viewers to betting platforms while sending automated visitors to dead ends
- domain8x255[.]comActor-controlled gambling-related domain within the Sable Squirrel infrastructure
- domain90phutyy[.]ioSable Squirrel infrastructure domain used for streaming operations
- domainanimalrampage3d[.]ioDropcatch domain now serving Sable Squirrel streaming content and promoting COLATV99, VSBet, and ColaScore brands
- domainapi-score[.]comActor-controlled sports data and live odds feed service active since 2021, shared across all streaming brands
- domainbind[.]bestresulttostart[.]comBalada Injector TDS URL that Sable Squirrel's compromised streaming site redirected viewers to
- domainbuffalomarket[.]comDropcatch domain formerly belonging to a food and beverage distributor; now serves illegal streaming content
- domaincel-robox[.]comFormer 3D-printer company domain acquired via dropcatch, now serving as both an illegal streaming front end and Quasar RAT C2 controller
- domainchatboxn[.]comActor-controlled WebSocket chat backend service active since 2023, shared across all streaming brands
- domaincolascore[.]comActor-controlled gambling and live-score platform domain; mobile app distributed through compromised Google Play developer accounts
- domaincolatv88xb[.]ccMost active C2 domain accounting for nearly 70% of exposed customer networks querying Sable Squirrel malware infrastructure; also functions as a betting-tracker domain
- domaingene-chips[.]comDropcatch domain now serving Sable Squirrel illegal streaming content
- domaingvapi[.]ccActor-controlled proxy CDN domain that mirrors content from thesports.com; serves images across streaming sites
- domainhealthymagination[.]comDropcatch domain formerly belonging to General Electric's health initiative; now serves illegal streaming content
- domainimgts[.]comActor-controlled CDN domain serving images and page assets across streaming brands
- domaininstitutobancopalmas[.]orgDropcatch domain formerly belonging to a Brazilian community bank; now serves illegal streaming content
- domainjurasudfoot[.]comDropcatch domain formerly belonging to a French football club; now serves illegal streaming content
- domainkoepgd[.]appActor-controlled video delivery server domain for streaming content
- domainkrogeralbertsons[.]comDropcatch domain created for the planned Kroger and Albertsons merger; now serves illegal streaming content
- domainlfastcdn[.]comActor-controlled CDN domain serving page assets across streaming brands
- domainmaxfactor-international[.]comDropcatch domain tied to Procter & Gamble's Max Factor cosmetics brand; now serves illegal streaming content
- domainmeung[.]appActor-controlled video delivery server domain for streaming content
- domainmsdht[.]appActor-controlled video delivery server domain for streaming content
- domainmsrktz[.]appActor-controlled video delivery server domain for streaming content
- domainrefvsb[.]comActor-controlled redirection domain bridging streaming sites to betting platforms
- domainrezilion[.]comDropcatch domain formerly belonging to a cybersecurity company; now serves illegal streaming content
- domainsadd[.]ioDropcatch domain now serving Sable Squirrel illegal streaming content
- domainsamefacts[.]comDropcatch domain formerly a long-running policy blog; now serves illegal streaming content
- domainsnsystems[.]comDropcatch domain formerly belonging to Sony PlayStation developer tools company; now serves illegal streaming content
- domainsocoliveku[.]ccSable Squirrel infrastructure domain used for streaming operations
- domainsportliveapiz[.]comActor-controlled sports data feed domain for live scores and odds
- domainstope40[.]orgDropcatch domain now serving Sable Squirrel illegal streaming content
- domaintrackervsb[.]liveActor-controlled tracker domain monitoring visitors across the streaming fleet
- domainveinteractive[.]comDropcatch domain formerly belonging to British adtech company Ve Interactive; inherits residual third-party traffic calls; now serves illegal streaming content
- domainvsbet276[.]comActor-controlled gambling platform domain receiving traffic from the streaming funnel via the actor's own redirection layer
- domainws-xyz[.]comActor-controlled WebSocket service for in-match live chat
- domainxemlaibongda[.]netSable Squirrel streaming site independently compromised by Balada Injector, which injected code redirecting viewers to a separate TDS at bind.bestresulttostart.com
- domainxoilacxys[.]topSable Squirrel streaming lookalike domain that was taken over by unknown actors running Russian-language investment scams in early 2026; now a lame domain
- domainxoilacz[.]comSable Squirrel streaming domain tied to the actor cluster; appears in Vietnamese enforcement photographs
- mutexlM9F7Ezcu9e3Mutex used by AsyncRAT 0.5.8 samples deployed by Sable Squirrel from November 2025 to March 2026
- registry_keyHKCU\Software\Microsoft\Windows\CurrentVersion\Run\xoilacStartup registry key named xoilac used by Sable Squirrel malware samples for persistence
- sha2560464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216Representative Quasar RAT sample connecting to Sable Squirrel C2 infrastructure; PE metadata contains actor brand names socolive, xoilac, and 8xbet
- urlhxxps://bind[.]bestresulttostart[.]com/xf4mKQBalada Injector TDS redirect URL injected into the Sable Squirrel streaming site xemlaibongda.net, running Keitaro tracker software
Detection / Hunteropenrouter
What Happened
A criminal group called Sable Squirrel has bought thousands of expired website addresses that previously belonged to legitimate organizations like General Electric, Procter & Gamble, and a French football club. They use these trusted addresses to run illegal sports streaming websites that funnel viewers into online gambling platforms. A subset of these same websites also serve as control servers for malware, meaning a person watching a football stream and an infected computer can be connecting to the same web address. The group's malware carries their own brand names embedded inside the files, confirming they operate the streaming, gambling, and malware operations together. Organizations should check their networks for connections to the domains and malware indicators identified in this report, and consider blocking the listed infrastructure.
Key Takeaways
- Sable Squirrel controls 10,000+ domains and has spent an estimated $7 million on expired domain acquisitions to inherit aged reputation, backlinks, and residual traffic from legitimate prior owners.
- Over 31,000 malware samples connect to Sable Squirrel domains, spanning Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, and HiddenTear ransomware signatures.
- A subset of streaming domains operate as dual-use infrastructure: serving live sports content to human visitors while simultaneously functioning as malware C2 for infected devices.
- Malware samples embed the actor's own brand names (socolive, xoilac, 8xbet) in PE file metadata headers, directly linking the streaming operation to the malware campaign.
- A coordinated weaponization wave in late 2025 converted roughly 350 existing streaming domains into malware C2, with one domain (colatv88xb.cc) accounting for nearly 70% of customer network exposure.
Affected Systems
- Windows endpoints targeted by RAT malware families
- WordPress sites used as dual-use streaming and C2 infrastructure
- Android devices via compromised Google Play developer accounts distributing ColaScore and VSBet apps
- Networks across education, IT, government, healthcare, and banking sectors observed querying C2 domains
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Domain Acquisition: Actor purchases expired domains via dropcatch platforms (GoDaddy, DropCatch, Namecheap, Dynadot) to inherit aged registration history, backlinks, and residual traffic from legitimate prior owners
- Infrastructure Setup: Acquired domains configured as WordPress streaming sites serving illegal Vietnamese sports content; median five days from purchase to activation
- Monetization: Streaming sites funnel viewers to actor-controlled gambling platforms (VSBet, ColaScore, 8xbet) via actor-controlled TDS and redirection layer (6789x.site)
- Malware C2 Configuration: Subset of existing streaming domains configured as dual-use C2 infrastructure in a coordinated wave starting November 2025, peaking in December with roughly 350 domains weaponized
- Malware Deployment: RAT samples (Quasar, AsyncRAT, DCRat, njRAT, Remcos, NanoCore) distributed with actor brand names embedded in PE metadata; malware installs persistence via startup registry key named xoilac
- C2 Operations: Infected devices communicate with streaming domains serving live content to human visitors simultaneously; C2 domains queried by customer networks across two dozen industries
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Infoblox Threat Intelligence GitHub repository
The article references high-precision signatures developed by Infoblox and states that a fuller set of defanged indicators is published in the Infoblox Threat Intelligence GitHub repository. No rule bodies are included in the article itself.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | EDR can detect RAT executables, mutex creation (lM9F7Ezcu9e3 for AsyncRAT), and registry persistence keys named xoilac. However, the C2 domains also serve legitimate-looking streaming content, which may reduce behavioral suspicion. PE metadata containing brand names is a strong indicator if file analysis is available. |
| Network Visibility | High | DNS queries to Sable Squirrel C2 domains are the primary detection vector. The article identifies a recognizable DNS fingerprint unique to Sable Squirrel domains. Passive DNS analysis and network flow monitoring can identify connections to the listed C2 and infrastructure domains. |
| Detection Difficulty | Moderate | The domains have inherited reputation from legitimate prior owners, which may bypass reputation-based security controls. However, the specific DNS fingerprint, mutex values, PE metadata patterns, and known domain lists provide concrete detection anchors. The dual-use nature of domains requires correlation between malware analysis and DNS activity to confirm C2 behavior. |
Required Log Sources
- DNS query logs or passive DNS
- EDR process creation and file analysis telemetry
- Web proxy logs for HTTP/HTTPS connections
- Firewall logs for outbound C2 connections
- Certificate transparency logs for domain infrastructure
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Endpoints with outbound DNS queries to known Sable Squirrel C2 domains may be infected with RAT malware, as these domains serve dual-purpose streaming and C2 roles | DNS query logs, EDR network connection events, firewall logs | Command and Control | Medium - some domains may be visited by users seeking sports streaming content, requiring correlation with endpoint process activity to confirm malware C2 |
| Windows executables with PE metadata containing the strings socolive, xoilac, or 8xbet in CompanyName, ProductName, or LegalCopyright fields are likely Sable Squirrel malware samples | EDR file analysis, endpoint detection with PE header inspection | Execution | Low - these brand strings in PE metadata are highly specific to this threat actor and unlikely to appear in legitimate software |
| Processes creating a mutex named lM9F7Ezcu9e3 are running AsyncRAT 0.5.8 deployed by Sable Squirrel between November 2025 and March 2026 | EDR mutex creation events, process telemetry | Execution | Low - this specific mutex string is unique to the identified AsyncRAT build |
| Registry persistence keys named xoilac in startup locations indicate Sable Squirrel malware installation | EDR registry modification events, Sysmon Event ID 13 | Persistence | Low - the key name is actor-specific and not associated with legitimate software |
| Network connections to domains with the Sable Squirrel DNS fingerprint that also resolve to WordPress streaming sites may indicate dual-use C2 infrastructure | Passive DNS, web proxy logs, HTTP response headers and content analysis | Command and Control | Medium - distinguishing between a user visiting a streaming site and an infected device beaconing requires endpoint-to-network correlation |
Control Gaps
- Domain reputation systems that rely on registration age and historical ownership will fail to flag dropcatch domains acquired from legitimate organizations
- URL filtering based on content category may classify streaming domains as benign entertainment rather than malware C2
- Signature-based AV may miss commodity RAT samples with brand-specific metadata not in existing signature databases
- Network controls without DNS inspection will miss C2 traffic that reuses domains also serving legitimate web content
Key Behavioral Indicators
- PE metadata fields containing brand strings: socoLIVE, xoilac, 8xbet in CompanyName, FileDescription, ProductName, or LegalCopyright
- Registry startup key named xoilac
- Mutex lM9F7Ezcu9e3 for AsyncRAT 0.5.8 identification
- DNS queries to domains exhibiting the Sable Squirrel DNS fingerprint pattern
- Outbound connections to domains simultaneously serving WordPress streaming content and malware C2 on the same address
- Android packages published from developer accounts with unrelated business details (e.g., therapy practice publishing a sports score app)
False Positive Assessment
Medium - The dual-use nature of Sable Squirrel domains means that DNS queries to these domains may originate from users seeking sports streaming content rather than from infected devices. Correlation between DNS activity and endpoint process telemetry is needed to distinguish between user browsing and malware C2. The dropcatch domains inherited from legitimate organizations may also generate residual traffic from third-party websites that have not updated their references.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider blocking the listed Sable Squirrel C2 and infrastructure domains at DNS and web proxy layers, prioritizing colatv88xb.cc which accounts for the majority of observed customer exposure.
- If your EDR supports it, consider hunting for the mutex lM9F7Ezcu9e3, registry startup keys named xoilac, and PE files with metadata containing socolive, xoilac, or 8xbet brand strings.
- Evaluate whether any endpoints in your environment have communicated with the listed dropcatch or infrastructure domains, and if matches are found, consider isolating those hosts for investigation.
- If applicable, consider reviewing Google Play device management policies to block the package com.cullcoljdk.ihdiheiuhsuni and similar apps from compromised developer accounts.
Infrastructure Hardening
- Consider implementing DNS response policy zones (RPZ) or similar DNS firewall rules to block queries to known Sable Squirrel domains, particularly the C2 domains identified in the article.
- Evaluate whether your domain reputation or threat intelligence feeds account for dropcatch domain acquisitions where ownership has changed from legitimate organizations to threat actors.
- If your organization uses web content filtering, consider reviewing whether streaming and gambling domains in the Sable Squirrel infrastructure are categorized appropriately for blocking.
- Consider augmenting DNS monitoring with passive DNS analysis to detect domains exhibiting the Sable Squirrel DNS fingerprint pattern.
User Protection
- If your EDR supports host isolation, consider isolating any endpoints confirmed to have communicated with Sable Squirrel C2 domains.
- Evaluate whether your endpoint protection can detect the identified RAT families (Quasar, AsyncRAT, DCRat, njRAT, Remcos, NanoCore) by their behavioral patterns rather than relying solely on file signatures.
- Consider deploying additional monitoring for endpoints in the education, IT, government, healthcare, and banking sectors, which showed the highest query rates to Sable Squirrel C2 domains.
Security Awareness
- Consider incorporating awareness training about the risks of visiting illegal sports streaming sites, which may serve malware C2 on the same domains serving video content.
- If applicable to your organization, consider reminding users that expired domains previously belonging to trusted brands can be repurposed by threat actors and that domain history alone is not a guarantee of current safety.
- Consider adding guidance for users to report suspicious mobile apps, particularly those published by developer accounts with unrelated business profiles.
MITRE ATT&CK Mapping
Persistence
Stealth
Collection
Command and Control
Impact
Additional IOCs
- Domains:
veinteractive[.]com- Dropcatch domain formerly belonging to British adtech company Ve Interactive; inherits residual third-party traffic calls; now serves illegal streaming contenthealthymagination[.]com- Dropcatch domain formerly belonging to General Electric's health initiative; now serves illegal streaming contentkrogeralbertsons[.]com- Dropcatch domain created for the planned Kroger and Albertsons merger; now serves illegal streaming contentmaxfactor-international[.]com- Dropcatch domain tied to Procter & Gamble's Max Factor cosmetics brand; now serves illegal streaming contentanimalrampage3d[.]io- Dropcatch domain now serving Sable Squirrel streaming content and promoting COLATV99, VSBet, and ColaScore brandsgene-chips[.]com- Dropcatch domain now serving Sable Squirrel illegal streaming contentstope40[.]org- Dropcatch domain now serving Sable Squirrel illegal streaming contentsadd[.]io- Dropcatch domain now serving Sable Squirrel illegal streaming contentsnsystems[.]com- Dropcatch domain formerly belonging to Sony PlayStation developer tools company; now serves illegal streaming contentjurasudfoot[.]com- Dropcatch domain formerly belonging to a French football club; now serves illegal streaming contentrezilion[.]com- Dropcatch domain formerly belonging to a cybersecurity company; now serves illegal streaming contentinstitutobancopalmas[.]org- Dropcatch domain formerly belonging to a Brazilian community bank; now serves illegal streaming contentsamefacts[.]com- Dropcatch domain formerly a long-running policy blog; now serves illegal streaming contentbuffalomarket[.]com- Dropcatch domain formerly belonging to a food and beverage distributor; now serves illegal streaming contentsocoliveku[.]cc- Sable Squirrel infrastructure domain used for streaming operations90phutyy[.]io- Sable Squirrel infrastructure domain used for streaming operationsimgts[.]com- Actor-controlled CDN domain serving images and page assets across streaming brandstrackervsb[.]live- Actor-controlled tracker domain monitoring visitors across the streaming fleetrefvsb[.]com- Actor-controlled redirection domain bridging streaming sites to betting platforms8x255[.]com- Actor-controlled gambling-related domain within the Sable Squirrel infrastructurexoilacxys[.]top- Sable Squirrel streaming lookalike domain that was taken over by unknown actors running Russian-language investment scams in early 2026; now a lame domainxoilacz[.]com- Sable Squirrel streaming domain tied to the actor cluster; appears in Vietnamese enforcement photographsmsrktz[.]app- Actor-controlled video delivery server domain for streaming contentmeung[.]app- Actor-controlled video delivery server domain for streaming contentmsdht[.]app- Actor-controlled video delivery server domain for streaming contentkoepgd[.]app- Actor-controlled video delivery server domain for streaming contentws-xyz[.]com- Actor-controlled WebSocket service for in-match live chatlfastcdn[.]com- Actor-controlled CDN domain serving page assets across streaming brandsgvapi[.]cc- Actor-controlled proxy CDN domain that mirrors content from thesports.com; serves images across streaming sitessportliveapiz[.]com- Actor-controlled sports data feed domain for live scores and oddsbind[.]bestresulttostart[.]com- Balada Injector TDS URL that Sable Squirrel's compromised streaming site redirected viewers to
- Urls:
hxxps://bind[.]bestresulttostart[.]com/xf4mKQ- Balada Injector TDS redirect URL injected into the Sable Squirrel streaming site xemlaibongda.net, running Keitaro tracker software
- File Hashes:
0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216(SHA256) - Representative Quasar RAT sample with PE metadata containing actor brands: CompanyName socoLIVE, FileDescription xoilac client, OriginalFilename socolive.exe, ProductName xoilac, LegalCopyright 8xbet
- Registry Keys:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\xoilac- Startup registry key named xoilac used by Sable Squirrel malware samples for persistence
- Other:
com.cullcoljdk.ihdiheiuhsuni- Google Play package name for ColaScore app published under a compromised developer account tied to a marriage and family therapy business[email protected]- Contact email address displayed on Sable Squirrel streaming site footer alongside an unverified Ho Chi Minh City business address