Sable Squirrel is an Asian threat actor that has spent an estimated $7 million acquiring expired domains with legitimate histories to build a vertically integrated criminal operation spanning illegal sports streaming, online gambling, and malware C2. Over 31,000 malware samples across multiple RAT families and HiddenTear ransomware connect to Sable Squirrel domains, with a coordinated wave in late 2025 converting roughly 350 existing streaming domains into dual-use C2 infrastructure. The operation shares brands, infrastructure, and PE metadata across streaming, gambling, and malware components, indicating a single operator rather than loosely affiliated campaigns.
Dropcatch Domains
2 posts
$7 Million in Expired Domains Fuel a Streaming Empire with a Malware Secret Drop Something? Don’t Worry, Someone Caught it Infoblox Threat Intel reports that nearly 20% of daily gTLD registrations are dropcatch domains—previously registered domains that expired and were re-registered. Threat actors exploit the inherited reputation and lingering connections of these domains to facilitate malware distribution, phishing, and infrastructure hijacking. Threat actors Shady Squirrel and Sable Squirrel are actively using this technique.