Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows
Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.
AI Analysis
Technical Summary
This threat involves three financially motivated groups acquiring expired malicious domains via dropcatch services to capitalize on existing traffic from previously compromised sites. Stuffy Squirrel operates since 2020, embedding malicious activity within legitimate scripts and selling traffic to affiliate advertising networks. Shady Squirrel employs custom JavaScript and Keitaro injections with multi-step cloaking, collaborating with initial access brokers to deliver tech support scams and SocGholish malware, contributing to SocGholish's resurgence after Operation Endgame disruption. Swiping Squirrel sells fraudulent traffic to zero-click advertising platforms like ZeroPark, leading to malvertising and malware distribution. Collectively, these actors control thousands of domains, leveraging lingering infections without launching new compromises. The activity is linked to multiple tactics and techniques such as phishing, command and control communications, and obfuscation.
Potential Impact
The threat actors monetize expired malicious domains by inheriting traffic from previously compromised websites, enabling continued distribution of tech support scams, malvertising, affiliate fraud, and malware such as SocGholish. This results in sustained exposure of users to fraudulent and malicious content without new exploitation campaigns. The persistence of these domains facilitates ongoing financial gain for the actors and continued risk to users interacting with these domains. The threat is notable in the United States and Japan but is not limited to these regions.
Mitigation Recommendations
No direct patch or fix applies as this threat exploits expired domains rather than software vulnerabilities. Mitigation should focus on monitoring and blocking known malicious domains listed in threat intelligence feeds. Organizations should update domain blocklists to include the identified domains and educate users about risks associated with tech support scams and malvertising. Network defenders should leverage domain reputation services and DNS filtering to reduce exposure. Since the actors do not conduct new attacks but exploit residual infections, remediation of previously compromised assets remains critical.
Affected Countries
United States, Japan
Indicators of Compromise
- domain: magesource.su
- domain: hpmdnetwork.ru
- domain: sport2news.com
- domain: propush.me
- domain: imhd.io
- domain: weatherplllatform.com
- domain: bluegaslamp.org
- domain: draggedline.org
- domain: ads-analytic.com
- domain: checkoutbump.com
- domain: tofuturepubs.com
- domain: simplejscdn.com
- domain: jqueryapihelpers.com
- domain: blocksovetnik.ru
- domain: brodirect3s.site
- domain: cdnjslibraries.com
- domain: memtkh.com
- domain: pills-europe.com
- domain: renteres.ru
- domain: wesq.me
- domain: renpaste.top
Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows
Description
Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves three financially motivated groups acquiring expired malicious domains via dropcatch services to capitalize on existing traffic from previously compromised sites. Stuffy Squirrel operates since 2020, embedding malicious activity within legitimate scripts and selling traffic to affiliate advertising networks. Shady Squirrel employs custom JavaScript and Keitaro injections with multi-step cloaking, collaborating with initial access brokers to deliver tech support scams and SocGholish malware, contributing to SocGholish's resurgence after Operation Endgame disruption. Swiping Squirrel sells fraudulent traffic to zero-click advertising platforms like ZeroPark, leading to malvertising and malware distribution. Collectively, these actors control thousands of domains, leveraging lingering infections without launching new compromises. The activity is linked to multiple tactics and techniques such as phishing, command and control communications, and obfuscation.
Potential Impact
The threat actors monetize expired malicious domains by inheriting traffic from previously compromised websites, enabling continued distribution of tech support scams, malvertising, affiliate fraud, and malware such as SocGholish. This results in sustained exposure of users to fraudulent and malicious content without new exploitation campaigns. The persistence of these domains facilitates ongoing financial gain for the actors and continued risk to users interacting with these domains. The threat is notable in the United States and Japan but is not limited to these regions.
Defensive Guidance
No direct patch or fix applies as this threat exploits expired domains rather than software vulnerabilities. Mitigation should focus on monitoring and blocking known malicious domains listed in threat intelligence feeds. Organizations should update domain blocklists to include the identified domains and educate users about risks associated with tech support scams and malvertising. Network defenders should leverage domain reputation services and DNS filtering to reduce exposure. Since the actors do not conduct new attacks but exploit residual infections, remediation of previously compromised assets remains critical.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.infoblox.com/blog/threat-intelligence/dropcatch-scavengers-expired-malicious-domains-become-cash-cows/"]
- Adversary
- null
- Pulse Id
- 6a7ec3107e8b34f88b5d610e
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainmagesource.su | — | |
domainhpmdnetwork.ru | — | |
domainsport2news.com | — | |
domainpropush.me | — | |
domainimhd.io | — | |
domainweatherplllatform.com | — | |
domainbluegaslamp.org | — | |
domaindraggedline.org | — | |
domainads-analytic.com | — | |
domaincheckoutbump.com | — | |
domaintofuturepubs.com | — | |
domainsimplejscdn.com | — | |
domainjqueryapihelpers.com | — | |
domainblocksovetnik.ru | — | |
domainbrodirect3s.site | — | |
domaincdnjslibraries.com | — | |
domainmemtkh.com | — | |
domainpills-europe.com | — | |
domainrenteres.ru | — | |
domainwesq.me | — | |
domainrenpaste.top | — |
Threat ID: 6a7ef45ebf8831d539e6b858
Added to database: 08/14/2026, 10:56:30 UTC
Last enriched: 08/14/2026, 11:33:47 UTC
Last updated: 08/15/2026, 02:22:45 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.