Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Illegal Streaming Fronts a $7M Dropcatch Domain Operation

0
Medium
Published: 08/13/2026 (08/13/2026, 16:05:49 UTC)
Source: AlienVault OTX General

Description

Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 11:33:55 UTC

Technical Analysis

The threat actor known as Sable Squirrel manages a vast criminal enterprise leveraging over 10,000 domains acquired via dropcatching expired domains to inherit their reputation and traffic. These domains host illegal Asian sports streaming services under brands such as Xoilac, Cakhia, and 90phut, which funnel users to gambling platforms like VSBet and 8xbet. Analysis identified over 31,000 malware samples connecting to Sable Squirrel infrastructure, including remote access trojans (Quasar RAT, AsyncRAT, DCRat) and ransomware variants. Notably, the same domains simultaneously serve streaming content and act as command-and-control servers for malware operations. Vietnamese law enforcement disrupted the operation in early 2026 with arrests and asset seizures, but the group rapidly recovered and expanded for the World Cup period by employing domain rotation and shared technical infrastructure across multiple Asian countries.

Potential Impact

The operation facilitates illegal streaming and gambling activities while simultaneously supporting a large-scale malware distribution infrastructure. The dual use of domains for both streaming and command-and-control increases the complexity of detection and takedown efforts. The presence of multiple malware families, including RATs and ransomware, indicates a broad and persistent threat to affected users and networks. The resilience and rapid recovery after law enforcement intervention suggest ongoing risk to the Asian market and potentially beyond.

Defensive Guidance

No official patch or fix applies as this is a criminal infrastructure operation rather than a software vulnerability. Mitigation focuses on monitoring and blocking known malicious domains and hashes associated with Sable Squirrel, as well as coordinating with law enforcement for takedown efforts. Organizations should update threat intelligence feeds with the provided indicators of compromise to detect and prevent connections to this infrastructure. Due to the operation's use of domain rotation and shared infrastructure, continuous monitoring and rapid response to new indicators are recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/"]
Adversary
Sable Squirrel
Pulse Id
6a7deb5d13e63e6a0ff237b2
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainxoilacz.com
domainbind.bestresulttostart.com
domaincolascore.com
domainstope40.org
domainxemlaibongda.net
domain6789x.site
domaincel-robox.com
domainsadd.io
domainhealthymagination.com
domain90phutyy.io
domainanimalrampage3d.io
domainbuffalomarket.com
domainkrogeralbertsons.com
domainmaxfactor-international.com
domainrefvsb.com
domainsamefacts.com
domainsnsystems.com
domainxoilacxys.top

Hash

ValueDescriptionCopy
hash0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216
hash3e79a671ca9a73063f21d0fbabd20baa
hash6e2d116a23d966da68a94675005a9029d92c0535

Threat ID: 6a7ef0ccbf8831d539e14484

Added to database: 08/14/2026, 10:41:16 UTC

Last enriched: 08/14/2026, 11:33:55 UTC

Last updated: 08/15/2026, 01:36:09 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses