Illegal Streaming Fronts a $7M Dropcatch Domain Operation
Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.
AI Analysis
Technical Summary
The threat actor known as Sable Squirrel manages a vast criminal enterprise leveraging over 10,000 domains acquired via dropcatching expired domains to inherit their reputation and traffic. These domains host illegal Asian sports streaming services under brands such as Xoilac, Cakhia, and 90phut, which funnel users to gambling platforms like VSBet and 8xbet. Analysis identified over 31,000 malware samples connecting to Sable Squirrel infrastructure, including remote access trojans (Quasar RAT, AsyncRAT, DCRat) and ransomware variants. Notably, the same domains simultaneously serve streaming content and act as command-and-control servers for malware operations. Vietnamese law enforcement disrupted the operation in early 2026 with arrests and asset seizures, but the group rapidly recovered and expanded for the World Cup period by employing domain rotation and shared technical infrastructure across multiple Asian countries.
Potential Impact
The operation facilitates illegal streaming and gambling activities while simultaneously supporting a large-scale malware distribution infrastructure. The dual use of domains for both streaming and command-and-control increases the complexity of detection and takedown efforts. The presence of multiple malware families, including RATs and ransomware, indicates a broad and persistent threat to affected users and networks. The resilience and rapid recovery after law enforcement intervention suggest ongoing risk to the Asian market and potentially beyond.
Mitigation Recommendations
No official patch or fix applies as this is a criminal infrastructure operation rather than a software vulnerability. Mitigation focuses on monitoring and blocking known malicious domains and hashes associated with Sable Squirrel, as well as coordinating with law enforcement for takedown efforts. Organizations should update threat intelligence feeds with the provided indicators of compromise to detect and prevent connections to this infrastructure. Due to the operation's use of domain rotation and shared infrastructure, continuous monitoring and rapid response to new indicators are recommended.
Indicators of Compromise
- domain: xoilacz.com
- domain: bind.bestresulttostart.com
- domain: colascore.com
- domain: stope40.org
- domain: xemlaibongda.net
- domain: 6789x.site
- domain: cel-robox.com
- domain: sadd.io
- hash: 0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216
- hash: 3e79a671ca9a73063f21d0fbabd20baa
- hash: 6e2d116a23d966da68a94675005a9029d92c0535
- domain: healthymagination.com
- domain: 90phutyy.io
- domain: animalrampage3d.io
- domain: buffalomarket.com
- domain: krogeralbertsons.com
- domain: maxfactor-international.com
- domain: refvsb.com
- domain: samefacts.com
- domain: snsystems.com
- domain: xoilacxys.top
Illegal Streaming Fronts a $7M Dropcatch Domain Operation
Description
Sable Squirrel operates a massive criminal enterprise controlling over 10,000 domains, spending an estimated $7 million acquiring expired domains to inherit their reputation and traffic. The actor runs illegal Asian sports streaming services under brands like Xoilac, Cakhia, and 90phut, which funnel viewers to gambling platforms including VSBet and 8xbet. Analysis reveals over 31,000 malware samples connecting to Sable Squirrel infrastructure, including Quasar RAT, AsyncRAT, DCRat, and ransomware variants, with the same domains simultaneously hosting streaming content and serving as command-and-control servers. Despite Vietnamese law enforcement actions in early 2026, including arrests and asset seizures, the operation quickly recovered and expanded for the World Cup, demonstrating resilience through domain rotation and shared technical infrastructure spanning multiple Asian markets.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The threat actor known as Sable Squirrel manages a vast criminal enterprise leveraging over 10,000 domains acquired via dropcatching expired domains to inherit their reputation and traffic. These domains host illegal Asian sports streaming services under brands such as Xoilac, Cakhia, and 90phut, which funnel users to gambling platforms like VSBet and 8xbet. Analysis identified over 31,000 malware samples connecting to Sable Squirrel infrastructure, including remote access trojans (Quasar RAT, AsyncRAT, DCRat) and ransomware variants. Notably, the same domains simultaneously serve streaming content and act as command-and-control servers for malware operations. Vietnamese law enforcement disrupted the operation in early 2026 with arrests and asset seizures, but the group rapidly recovered and expanded for the World Cup period by employing domain rotation and shared technical infrastructure across multiple Asian countries.
Potential Impact
The operation facilitates illegal streaming and gambling activities while simultaneously supporting a large-scale malware distribution infrastructure. The dual use of domains for both streaming and command-and-control increases the complexity of detection and takedown efforts. The presence of multiple malware families, including RATs and ransomware, indicates a broad and persistent threat to affected users and networks. The resilience and rapid recovery after law enforcement intervention suggest ongoing risk to the Asian market and potentially beyond.
Defensive Guidance
No official patch or fix applies as this is a criminal infrastructure operation rather than a software vulnerability. Mitigation focuses on monitoring and blocking known malicious domains and hashes associated with Sable Squirrel, as well as coordinating with law enforcement for takedown efforts. Organizations should update threat intelligence feeds with the provided indicators of compromise to detect and prevent connections to this infrastructure. Due to the operation's use of domain rotation and shared infrastructure, continuous monitoring and rapid response to new indicators are recommended.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/"]
- Adversary
- Sable Squirrel
- Pulse Id
- 6a7deb5d13e63e6a0ff237b2
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainxoilacz.com | — | |
domainbind.bestresulttostart.com | — | |
domaincolascore.com | — | |
domainstope40.org | — | |
domainxemlaibongda.net | — | |
domain6789x.site | — | |
domaincel-robox.com | — | |
domainsadd.io | — | |
domainhealthymagination.com | — | |
domain90phutyy.io | — | |
domainanimalrampage3d.io | — | |
domainbuffalomarket.com | — | |
domainkrogeralbertsons.com | — | |
domainmaxfactor-international.com | — | |
domainrefvsb.com | — | |
domainsamefacts.com | — | |
domainsnsystems.com | — | |
domainxoilacxys.top | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216 | — | |
hash3e79a671ca9a73063f21d0fbabd20baa | — | |
hash6e2d116a23d966da68a94675005a9029d92c0535 | — |
Threat ID: 6a7ef0ccbf8831d539e14484
Added to database: 08/14/2026, 10:41:16 UTC
Last enriched: 08/14/2026, 11:33:55 UTC
Last updated: 08/15/2026, 01:36:09 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.