Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows

0
Medium
Published: 08/14/2026 (08/14/2026, 07:26:08 UTC)
Source: AlienVault OTX General

Description

Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 11:33:47 UTC

Technical Analysis

This threat involves three financially motivated groups acquiring expired malicious domains via dropcatch services to capitalize on existing traffic from previously compromised sites. Stuffy Squirrel operates since 2020, embedding malicious activity within legitimate scripts and selling traffic to affiliate advertising networks. Shady Squirrel employs custom JavaScript and Keitaro injections with multi-step cloaking, collaborating with initial access brokers to deliver tech support scams and SocGholish malware, contributing to SocGholish's resurgence after Operation Endgame disruption. Swiping Squirrel sells fraudulent traffic to zero-click advertising platforms like ZeroPark, leading to malvertising and malware distribution. Collectively, these actors control thousands of domains, leveraging lingering infections without launching new compromises. The activity is linked to multiple tactics and techniques such as phishing, command and control communications, and obfuscation.

Potential Impact

The threat actors monetize expired malicious domains by inheriting traffic from previously compromised websites, enabling continued distribution of tech support scams, malvertising, affiliate fraud, and malware such as SocGholish. This results in sustained exposure of users to fraudulent and malicious content without new exploitation campaigns. The persistence of these domains facilitates ongoing financial gain for the actors and continued risk to users interacting with these domains. The threat is notable in the United States and Japan but is not limited to these regions.

Defensive Guidance

No direct patch or fix applies as this threat exploits expired domains rather than software vulnerabilities. Mitigation should focus on monitoring and blocking known malicious domains listed in threat intelligence feeds. Organizations should update domain blocklists to include the identified domains and educate users about risks associated with tech support scams and malvertising. Network defenders should leverage domain reputation services and DNS filtering to reduce exposure. Since the actors do not conduct new attacks but exploit residual infections, remediation of previously compromised assets remains critical.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.infoblox.com/blog/threat-intelligence/dropcatch-scavengers-expired-malicious-domains-become-cash-cows/"]
Adversary
null
Pulse Id
6a7ec3107e8b34f88b5d610e
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainmagesource.su
domainhpmdnetwork.ru
domainsport2news.com
domainpropush.me
domainimhd.io
domainweatherplllatform.com
domainbluegaslamp.org
domaindraggedline.org
domainads-analytic.com
domaincheckoutbump.com
domaintofuturepubs.com
domainsimplejscdn.com
domainjqueryapihelpers.com
domainblocksovetnik.ru
domainbrodirect3s.site
domaincdnjslibraries.com
domainmemtkh.com
domainpills-europe.com
domainrenteres.ru
domainwesq.me
domainrenpaste.top

Threat ID: 6a7ef45ebf8831d539e6b858

Added to database: 08/14/2026, 10:56:30 UTC

Last enriched: 08/14/2026, 11:33:47 UTC

Last updated: 08/15/2026, 02:22:45 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses