logo

Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows

ID: e8b693ba-01c3-5bfa-8a50-1ff6d16d9da8

STIX ID: report--e8b693ba-01c3-5bfa-8a50-1ff6d16d9da8

Feed Name: Infoblox Threat Intel Blog

Threat Score
75/100

Date Published: 2026-08-13

Date Updated: 2026-08-13

Author: Infoblox Threat Intel

...
...

This report analyzes a class of financially motivated 'dropcatch' actors that purchase expired malicious domains left in compromised websites and repurpose the inherited traffic to serve scams, malware, and affiliate/ad-fraud. It profiles three operators — Stuffy Squirrel (hides payloads in legitimate scripts and uses popunders), Shady Squirrel (highly cloaked TDS that has routed traffic to tech support scams and SocGholish via Keitaro injections), and Swiping Squirrel (sells traffic to ad brokers like ZeroPark) — describes their multi-layered evasion and distribution chains, quantifies their scale (hundreds to thousands of domains), and provides domain IOCs used by each actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.