BlackTree Security · Infrastructure · Automation · AI

The Domain Expired. The Trust Did Not.

Infoblox says nearly one in five newly observed domain registrations in 2026 had a previous life. Its Sable Squirrel research shows why that matters: when a domain expires, its ownership can change immediately while reputation, backlinks, traffic and forgotten technical dependencies continue to trust the old name.

Dropcatch is not an edge case

Domain expiry is often treated as an administrative failure with a familiar consequence: the website stops resolving or someone else buys the name.

The scale of the market makes that framing obsolete.

In the first half of 2026, Infoblox observed an average of 50,400 re-registered expired domains each day across generic top-level domains. Including the country-code domains visible to its telemetry raised the estimate to around 65,000 a day. Nearly 20 per cent of observed generic top-level-domain registrations were dropcatch registrations.

In other words, approximately one in five newly registered domains was not new. It carried history.

That history can include benign value such as search ranking, backlinks and brand recognition. It can also include allow-list decisions, embedded scripts, old DNS references, hard-coded application calls and infected systems that continue to contact the name.

The registration changes. The dependencies do not receive the memo.

Sable Squirrel buys the history

Infoblox uses the name Sable Squirrel for an actor it assesses to control more than 10,000 domains supporting illegal sports streaming, gambling promotion, traffic redirection, mobile-app distribution and malware command-and-control infrastructure.

The actor builds that inventory in two ways. It cheaply registers lookalike domains around its own brands, and it pays a premium for expired domains with real history.

In the second report in its dropcatch series, Infoblox said it individually priced about 160 acquisitions and confirmed more than $430,000 in purchases. Extrapolating from that researched sample to the wider inventory, the company estimates Sable Squirrel’s total dropcatch spending exceeds $7 million.

That distinction is important. The $430,000 figure is based on individually confirmed prices. The figure above $7 million is a researcher estimate, not a confirmed accounting total.

The investment buys aged registration history, residual traffic, existing inbound links and reputation signals that many security products and users still interpret as evidence of legitimacy.

The domain can serve two audiences

Infoblox identified more than 31,000 malware samples communicating with Sable Squirrel domains. The families included Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos and njRAT, as well as samples carrying HiddenTear ransomware signatures.

Some of the same domains continued to present functioning sports-streaming sites to human visitors while infected devices used them as command-and-control channels. Infoblox said a late-2025 wave configured hundreds of existing domains for that dual purpose.

This is operationally useful to an attacker because reputation systems often prefer simple labels. A domain is considered old or new, benign or malicious, active or abandoned.

Sable Squirrel demonstrates that those categories can coexist. The visible service can be real, popular and continuously used while a less visible path supports malware.

Age does not establish intent. Human-facing content does not establish exclusive use.

Residual trust can be more valuable than the name

The acquired names do not need to resemble the actor’s streaming brands. Their value comes from their previous owners.

Infoblox documented former domains tied to a General Electric health initiative, the Max Factor brand, a planned Kroger and Albertsons merger, a Sony PlayStation developer-tools company, a French football club, a cybersecurity company and a Brazilian community bank.

One example, veinteractive.com, belonged to a British advertising-technology company that collapsed in 2017. Infoblox says thousands of third-party websites still call the domain each day. The new owner inherits that traffic without having to compromise every calling site.

This is the central security property of dropcatch abuse. The actor does not always need to create trust. It can acquire a namespace that other systems already trust.

Expiry is a change of control

Asset registers commonly track domain renewal dates as an availability concern. Security programmes should treat expiry as a transfer of control over an internet identity.

Once the name leaves the organisation, the former owner cannot determine what content, certificates, email services or network endpoints the new registrant places behind it. Any remaining reference can become a path from a trusted system to an unknown operator.

The risk is broader than the public website:

  • Old JavaScript and content-delivery references can remain embedded in third-party pages.
  • Mobile and desktop applications can contain hard-coded API or update endpoints.
  • Email addresses on the domain can still appear in account-recovery workflows.
  • Security products may retain allow-list or reputation decisions linked to the name.
  • Partners may keep DNS, webhook, single sign-on or file-transfer configurations long after a contract ends.
  • Malware installed during an earlier campaign may continue querying an abandoned command-and-control domain.

A domain can therefore be absent from the current architecture and still be present in the effective attack surface.

Domain retirement needs an owner and a runbook

Organisations usually have a process for registering and renewing domains. Fewer have a disciplined retirement process.

The decision to let a domain expire should require evidence that trust has been removed. That work may take longer than the commercial purpose of the name itself.

Security and infrastructure teams should use a retirement runbook that includes:

  • Identify the business and technical owner before changing renewal status.
  • Search source code, application packages, configuration management, DNS logs, web logs and certificate records for references to the name.
  • Check email, identity, account-recovery, webhook and federation dependencies.
  • Notify partners and acquired or divested business units that may retain hard-coded references.
  • Redirect and monitor the domain during a quarantine period rather than allowing immediate expiry.
  • Review passive DNS, backlink and certificate-transparency data for evidence of continuing use.
  • Remove allow-list entries and reputation exceptions associated with the domain.
  • Document legal, brand and security reasons for defensive registration when residual trust cannot be removed.
  • Set a future review date instead of renewing unused names indefinitely without scrutiny.

The goal is not to retain every domain forever. It is to make expiry a verified security decision rather than the accidental result of a missed invoice or completed marketing campaign.

Detection must account for ownership change

Security controls that score a domain by age can be actively misleading after a dropcatch event.

Detection should combine historical reputation with current registration data, DNS infrastructure, certificate changes, hosting shifts and content behaviour. A long-lived domain that was re-registered five days ago should not receive the same trust as a continuously controlled domain of the same age.

Resolvers and network-monitoring systems can also look for queries to domains that have recently changed registration state, especially when the calling process is unexpected or the destination suddenly moves to unrelated infrastructure.

This is one reason DNS telemetry matters. It can expose the persistent relationship between an internal system and a name even when the public website looks ordinary.

Takedowns remove properties, not the acquisition model

Infoblox assesses that Sable Squirrel overlaps strongly with the prosecuted Vietnamese Xoi Lac TV network, but it does not claim definitive identity. The company says enforcement actions in early 2026 caused a short drop in new registrations before the operation recovered and expanded around the 2026 World Cup.

That assessment fits the economics. A domain-heavy operation is designed to replace individual properties. Blocking or seizing names raises cost, but the dropcatch market continually supplies new inventory with existing traffic and trust.

Defenders therefore need to address both the actor and the dependency that gives the actor value. Removing one malicious domain does not fix the forgotten script, application endpoint or allow-list rule that will point to the next owner.

The domain expired. The trust did not.

Sable Squirrel is notable for its scale, spending and combination of streaming, gambling and malware infrastructure. The broader lesson applies to every organisation that has launched a campaign, acquired a company, retired a product or abandoned an old internet name.

Domain ownership is temporary. References to a domain can be effectively permanent unless someone removes them.

An expiry date should therefore trigger more than a renewal decision. It should trigger a search for all the places where the organisation, its customers, its partners and their software still believe the name belongs to the old owner.

The registration record can change in a day. Trust decays only when defenders deliberately remove it.

Sources and further reading

Leave a Reply

Your email address will not be published. Required fields are marked *