Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows
Three financially motivated threat actor groups acquire expired malicious domains to inherit traffic from existing website compromises, redirecting victims to scams, malware, and affiliate advertising networks. Stuffy Squirrel hides malicious JavaScript in legitimate scripts with multi-layered evasion. Shady Squirrel partners with initial access brokers and enabled SocGholish's return after law enforcement disruption. Swiping Squirrel sells fraudulent traffic to zero-click advertising platforms where victims encounter malware. Combined, these actors control thousands of domains embedded in tens of thousands of compromised sites.
- domain3tght76h[.]comFinal landing domain in Shady Squirrel chain.
- domain62ad[.]comCloudflare-fronted domain in Shady Squirrel ad chain.
- domainads-analytic[.]comKeitaro TDS server domain used in two-part Keitaro injection chain. Returns JavaScript that redirects to Help TDS and affiliate advertising platforms.
- domainadvanceslibrary[.]comShady Squirrel domain registered June 27, 2026, likely specifically for SocGholish fake update delivery after Operation Endgame disruption.
- domainbisairtoonep[.]netPropellerAds domain in Shady Squirrel chain.
- domainblacksaltys[.]comShady Squirrel dropcatch domain formerly operated by TA2726. Inherited existing victim pool from prior compromise infrastructure.
- domainblackshelter[.]orgSwiping Squirrel dropcatch domain.
- domainblocksovetnik[.]ruStuffy Squirrel dropcatch domain.
- domainbluegaslamp[.]orgSwiping Squirrel dropcatch domain.
- domainbrodirect3s[.]siteShady Squirrel dropcatch domain formerly used by commercial push notification service.
- domaincdnjslibraries[.]comShady Squirrel dropcatch domain used both as Keitaro domain and later for custom injection that does not make external Keitaro calls.
- domaincheckoutbump[.]comStuffy Squirrel dropcatch domain.
- domaindesenteir[.]comAd network domain in Shady Squirrel Keitaro chain.
- domaindraggedline[.]orgSwiping Squirrel relay layer domain.
- domainfastcapchaverify[.]comShady Squirrel injector domain observed in Keitaro injection chain. Creates window configuration consumed by downstream Keitaro server response.
- domaingetshopstar[.]comSwiping Squirrel dropcatch domain.
- domaingl0a7loeki02do[.]comRedirect domain in Shady Squirrel chain.
- domaingsstats[.]ruStuffy Squirrel primary C2 entry point since November 2025, replacing tofuturepubs.com. Coordinates popunder delivery chain routing victim traffic to advertising exchanges.
- domainhoksomuptak[.]netAd network domain in Shady Squirrel Keitaro chain.
- domainhpmdnetwork[.]ruStuffy Squirrel dropcatch domain.
- domainimhd[.]ioShady Squirrel dropcatch domain formerly a legitimate CDN. Supply chain hijack.
- domainjqueryapihelpers[.]comSwiping Squirrel dropcatch domain.
- domainlife4life[.]orgSwiping Squirrel relay layer domain.
- domainlinedloop[.]orgDropcatch domain associated with TA2726 upstream actor.
- domainlparket[.]comKeitaro front-end domain in two-part Keitaro injection chain.
- domainlzdatheme[.]comSwiping Squirrel dropcatch domain.
- domainmagesource[.]suStuffy Squirrel script server formerly used as Magecart card-skimming domain targeting compromised Magento stores.
- domainmemtkh[.]comStuffy Squirrel dropcatch domain.
- domainmomijoy[.]ruRetargeting domain in Stuffy Squirrel chain.
- domainnews-paxacu[.]comHistorical domain in Stuffy Squirrel 2025 chain.
- domainogeri[.]ruAd backend domain in Stuffy Squirrel chain.
- domainpausewatchings[.]comShady Squirrel domain observed sending traffic to ProPush. Leaked into a Facebook post on July 10, 2026.
- domainpie-recipes[.]comKeitaro client domain in two-part Keitaro injection chain.
- domainpills-europe[.]comShady Squirrel domain observed sending traffic to ProPush in mid-July 2026.
- domainrenpaste[.]topTech support scam phone number server domain. Returns hostile response to direct probing but serves scam content with specific referrer. Used since April 2026.
- domainrenteres[.]ruStuffy Squirrel dropcatch domain.
- domainsimplejscdn[.]comShady Squirrel dropcatch domain formerly used by affiliate of commercial push notification service.
- domainslurpslimes[.]orgSwiping Squirrel dropcatch domain.
- domainsport2news[.]comDomain loading JavaScript that constructs window configuration and establishes Keitaro call in early Help TDS chain.
- domaintofuturepubs[.]comStuffy Squirrel primary entry point used throughout 2024 and 2025, replaced by gsstats.ru in November 2025.
- domaintrend-radar[.]orgSwiping Squirrel relay layer domain.
- domainttdbty[.]ccDropcatch domain associated with TA2726 upstream actor.
- domainweatherplllatform[.]comStuffy Squirrel script server domain formerly used as Balada injector infrastructure. Was Sucuri's second most-blocklisted resource in 2022. Inherits victim pool from prior campaign.
- domainwebpixel[.]appSwiping Squirrel dropcatch domain.
- domainwesq[.]meShady Squirrel dropcatch domain formerly used by commercial push notification service affiliate.
- domainwindowlight[.]orgSwiping Squirrel dropcatch domain.
- ip104[.]18[.]38[.]34IP address for 62ad.com (Cloudflare-fronted domain in Shady Squirrel ad chain).
- ip104[.]21[.]80[.]1IP address for fastcapchaverify.com (Shady Squirrel injector), behind Cloudflare.
- ip139[.]45[.]197[.]119IP address for bisairtoonep.net (PropellerAds domain in Shady Squirrel chain).
- ip159[.]195[.]45[.]176C2 IP address for gsstats.ru (Stuffy Squirrel), hosted on netcup GmbH infrastructure.
- ip193[.]161[.]202[.]200Keitaro operator IP address observed in two-part Keitaro injection chain associated with Shady Squirrel.
- ip78[.]46[.]92[.]254IP address for gl0a7loeki02do.com and 3tght76h.com (redirect and final landing in Shady Squirrel chain).
Detection / Hunteropenrouter
What Happened
Criminals are buying up expired website domain names that were previously used for attacks. When the original attackers let their domains expire, these new actors purchase them and automatically receive traffic from websites that were already compromised. The victims who visit those compromised sites get redirected to scams, fake software updates, or malware. One group helped a known malware operation called SocGholish restart its activities just days after a major law enforcement takedown. Another group sells the stolen traffic to advertising networks where victims may encounter malicious ads. Organizations should block known malicious domains, monitor DNS traffic for connections to these domains, and ensure their websites have not been compromised with injected scripts.
Key Takeaways
- Three threat actor groups (Stuffy Squirrel, Shady Squirrel, Swiping Squirrel) acquire expired malicious domains to inherit traffic from previously compromised websites, redirecting victims to scams and malware without performing new compromises.
- Shady Squirrel partnered with SocGholish, enabling a large-scale return approximately 10 days after disruption by Operation Endgame in mid-June 2026, by providing access to tens of thousands of compromised sites.
- Stuffy Squirrel evades detection via three independent server-side checks: URL-specific payload delivery, TDS-level request evaluation, and user-click-gated popunder windows, rendering automated scanners ineffective.
- Swiping Squirrel controls over 3,000 domains and sells fraudulent traffic to Team Internet's ZeroPark, where victims may encounter ClickFix attacks and malware delivered through downstream advertisers like AdventureFeeds.
- A previously unpublished two-part Keitaro injection chain was identified, where a window configuration variable is passed from an injector script to a Keitaro server response, enabling conditional redirections to affiliate advertising platforms.
Affected Systems
- WordPress websites (compromised for script injection)
- Magento e-commerce sites (historically compromised for Magecart skimming)
- Windows endpoints (targeted by tech support scams and SocGholish fake updates)
- Web browsers (JavaScript execution for TDS routing and fingerprinting)
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Compromised websites contain embedded references to domains previously used by threat actors like TA2726, Balada, or Magecart
- Domain Acquisition: Dropcatch actors acquire expired malicious domains, inheriting traffic from existing website compromises without performing new intrusions
- Execution: When a victim visits a compromised page, the embedded reference loads JavaScript from the dropcatch domain, which serves a live payload or decoy based on server-side checks
- Defense Evasion: Multiple cloaking layers filter scanners: URL-specific payload delivery, TDS request evaluation, referrer checks, and user-click-gated popunders
- Traffic Distribution: TDS routes qualifying victims to affiliate advertising networks, tech support scams, Keitaro servers, or malware actors like SocGholish
- Impact: Victims receive fake browser updates (SocGholish), tech support scam popups with call center phone numbers, malicious ads (ClickFix), or unwanted content
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Infoblox GitHub repository
The article references a GitHub repository for indicators but does not include detection rules in the blog post itself. The indicators list consists of domain names across the three actor groups.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Low | The attack chain primarily operates through web browser JavaScript execution and DNS resolution. EDR products may not capture the server-side cloaking logic or the TDS routing decisions. The tech support scam component involving remote access tools like AnyDesk would be visible to EDR if installed on the endpoint. |
| Network Visibility | High | DNS queries to dropcatch domains and HTTP requests to TDS infrastructure are observable at the network layer. The article's analysis was conducted primarily through DNS monitoring. Redirect chains and meta-refresh navigation produce observable HTTP traffic. |
| Detection Difficulty | Hard | Server-side cloaking means direct probing of domains returns decoys or errors. Payload delivery is conditional on specific referrer strings, user interaction, and browser fingerprinting. Multiple evasion layers operate independently, requiring coordinated analysis across DNS, web proxy, and endpoint telemetry to reconstruct the full chain. |
Required Log Sources
- DNS query logs
- Web proxy logs
- HTTP/S request logs with full URL paths and referrer headers
- EDR process execution logs for AnyDesk or remote access tools
- Firewall logs for outbound connections to identified IPs
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for DNS queries to domains recently registered or transferred that were previously associated with known malicious infrastructure, indicating dropcatch acquisition. | DNS resolution logs correlated with threat intelligence feeds for historically malicious domains | Acquire Infrastructure (T1583.001) | Medium. Legitimate organizations may acquire expired domains for brand protection or rebranding purposes. |
| Consider hunting for web traffic where a compromised site loads JavaScript from a domain with no prior legitimate history, especially when the script filename matches known TDS patterns. | Web proxy logs with full URL paths and referrer headers | Execution (T1059.007) | Medium. Legitimate content delivery networks and advertising scripts may exhibit similar loading patterns. |
| Consider hunting for endpoints where AnyDesk or similar remote access tools were installed shortly after the user visited a website that triggered a tech support scam popup, indicating successful social engineering. | EDR process execution logs and installation events correlated with web browsing history | User Execution (T1204.002) | Low. Remote access tool installation following a web visit to a scam page is a strong indicator of compromise. |
| Consider hunting for meta-refresh redirect chains that pass through multiple domains in rapid succession, especially when intermediate domains are recently registered or have short TTL DNS records. | Web proxy logs and DNS query logs showing rapid sequential domain resolutions | Traffic Distribution | High. Legitimate advertising and analytics redirect chains can produce similar patterns. |
| Consider hunting for HTTP requests containing reversed base64-encoded parameters in URL paths, as observed in Stuffy Squirrel's C2 communication pattern. | Web proxy logs with full URL query strings | Command and Control (T1071.001) | Low. Reversed base64 encoding in URL parameters is unusual in legitimate web traffic. |
Control Gaps
- Web application firewalls may not detect injected JavaScript references to expired domains because the domains themselves are not newly registered and may have aged reputation scores.
- DNS filtering based on new domain registration age would miss these threats since dropcatch domains have prior registration dates.
- Automated web scanners cannot trigger the full payload chain due to server-side cloaking, referrer checks, and user-click-gated popunders.
- SSL inspection may be required to observe the full redirect chain if HTTPS is used at any stage of the TDS routing.
Key Behavioral Indicators
- JavaScript loaded from a domain with a prior malicious history but different nameservers or hosting provider than originally observed
- Script files that appear to be legitimate libraries (e.g., Raphael.js) but contain IIFE blocks significantly increasing file size
- HTTP requests with reversed base64-encoded parameters in URL paths (e.g., btoa string reversal pattern)
- Meta-refresh redirects through multiple domains with short intervals, particularly through index.php endpoints
- Popunder window creation following user click events on compromised pages
- DNS queries to domains previously associated with TA2726, Balada, or Magecart campaigns but resolving to new IP addresses
- Client-side fingerprinting scripts that check navigator.userAgent and call getHighEntropyValues() before serving content
False Positive Assessment
Medium. Several identified domains were previously used for legitimate purposes (e.g., imhd.io as a CDN) or by commercial advertising services before being acquired by threat actors. Domains associated with affiliate advertising networks like ExoClick and PropellerAds have legitimate uses, making blanket blocking of associated infrastructure risky. However, the specific domains listed as dropcatch infrastructure are directly tied to malicious activity.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Consider blocking the identified dropcatch domains at DNS resolution and web proxy layers, prioritizing gsstats.ru, advanceslibrary.com, blacksaltys.com, renpaste.top, and ads-analytic.com.
- Consider searching web proxy logs for historical connections to the identified domains to determine if any users have already been exposed to the tech support scam or SocGholish fake update payloads.
- If your EDR supports it, consider hunting for AnyDesk installations or other remote access tools that were installed following web browsing sessions, as this may indicate successful tech support scam social engineering.
Infrastructure Hardening
- Consider implementing DNS filtering that correlates domain registration history with threat intelligence feeds to flag domains that change ownership after being associated with malicious activity.
- Evaluate whether your web proxy can inspect and block JavaScript loaded from domains with known malicious prior registrations, even if the domains are not currently flagged as malicious.
- If applicable to your environment, consider implementing referrer-policy headers on your own websites to prevent referrer leakage that could be exploited by TDS cloaking mechanisms.
- Consider monitoring your organization's web properties for injected script references to external domains, particularly in WordPress theme files where Shady Squirrel injections were observed.
User Protection
- Consider deploying browser security extensions that block known malvertising domains and popunder scripts, if compatible with your endpoint management strategy.
- Consider blocking remote access tools commonly abused by tech support scammers (e.g., AnyDesk) unless explicitly approved through your organization's software management process.
- If supported by your endpoint tooling, consider alerting on browser processes spawning remote access tool installers or executables.
Security Awareness
- Consider incorporating tech support scam awareness into existing security training programs, emphasizing that legitimate Microsoft support will never display pop-up warnings with phone numbers.
- Consider reminding users that fake browser update prompts encountered on websites are a known malware delivery mechanism and should be reported rather than clicked.
- Where applicable, consider training help desk staff to recognize and escalate calls from users who may have been directed to install remote access tools by scammers.
MITRE ATT&CK Mapping
Resource Development
Collection
Command and Control
Additional IOCs
- Ips:
104[.]21[.]80[.]1- IP address for fastcapchaverify.com (Shady Squirrel injector), behind Cloudflare.139[.]45[.]197[.]119- IP address for bisairtoonep.net (PropellerAds domain in Shady Squirrel chain).104[.]18[.]38[.]34- IP address for 62ad.com (Cloudflare-fronted domain in Shady Squirrel ad chain).78[.]46[.]92[.]254- IP address for gl0a7loeki02do.com and 3tght76h.com (redirect and final landing in Shady Squirrel chain).
- Domains:
tofuturepubs[.]com- Stuffy Squirrel primary entry point used throughout 2024 and 2025, replaced by gsstats.ru in November 2025.magesource[.]su- Stuffy Squirrel script server formerly used as Magecart card-skimming domain targeting compromised Magento stores.blocksovetnik[.]ru- Stuffy Squirrel dropcatch domain.checkoutbump[.]com- Stuffy Squirrel dropcatch domain.hpmdnetwork[.]ru- Stuffy Squirrel dropcatch domain.memtkh[.]com- Stuffy Squirrel dropcatch domain.renteres[.]ru- Stuffy Squirrel dropcatch domain.simplejscdn[.]com- Shady Squirrel dropcatch domain formerly used by affiliate of commercial push notification service.brodirect3s[.]site- Shady Squirrel dropcatch domain formerly used by commercial push notification service.wesq[.]me- Shady Squirrel dropcatch domain formerly used by commercial push notification service affiliate.imhd[.]io- Shady Squirrel dropcatch domain formerly a legitimate CDN. Supply chain hijack.pausewatchings[.]com- Shady Squirrel domain observed sending traffic to ProPush. Leaked into a Facebook post on July 10, 2026.pills-europe[.]com- Shady Squirrel domain observed sending traffic to ProPush in mid-July 2026.lparket[.]com- Keitaro front-end domain in two-part Keitaro injection chain.pie-recipes[.]com- Keitaro client domain in two-part Keitaro injection chain.sport2news[.]com- Domain loading JavaScript that constructs window configuration and establishes Keitaro call in early Help TDS chain.ogeri[.]ru- Ad backend domain in Stuffy Squirrel chain.momijoy[.]ru- Retargeting domain in Stuffy Squirrel chain.news-paxacu[.]com- Historical domain in Stuffy Squirrel 2025 chain.hoksomuptak[.]net- Ad network domain in Shady Squirrel Keitaro chain.desenteir[.]com- Ad network domain in Shady Squirrel Keitaro chain.bisairtoonep[.]net- PropellerAds domain in Shady Squirrel chain.62ad[.]com- Cloudflare-fronted domain in Shady Squirrel ad chain.gl0a7loeki02do[.]com- Redirect domain in Shady Squirrel chain.3tght76h[.]com- Final landing domain in Shady Squirrel chain.blackshelter[.]org- Swiping Squirrel dropcatch domain.bluegaslamp[.]org- Swiping Squirrel dropcatch domain.draggedline[.]org- Swiping Squirrel relay layer domain.getshopstar[.]com- Swiping Squirrel dropcatch domain.jqueryapihelpers[.]com- Swiping Squirrel dropcatch domain.lzdatheme[.]com- Swiping Squirrel dropcatch domain.slurpslimes[.]org- Swiping Squirrel dropcatch domain.webpixel[.]app- Swiping Squirrel dropcatch domain.windowlight[.]org- Swiping Squirrel dropcatch domain.life4life[.]org- Swiping Squirrel relay layer domain.trend-radar[.]org- Swiping Squirrel relay layer domain.linedloop[.]org- Dropcatch domain associated with TA2726 upstream actor.ttdbty[.]cc- Dropcatch domain associated with TA2726 upstream actor.
- Urls:
iplog.co/1LYe15.jpg- Tracker pixel URL used by tech support scam actor to capture visitor IP address and user agent information.
- Other:
(201) 409-2894- Tech support scam call center phone number observed for Japanese targets only.(877) 481-2126- Tech support scam call center toll-free phone number routed to United States.(888) 756-6605- Tech support scam call center toll-free phone number routed to United States.