Sable Squirrel Uses Expired Domains for Streaming and Malware

Daniel Zimmermann
6 Min Read
A broken keyboard branches into a live sports stream, betting wheel, and malware network after an expired-domain auction.
Expired domains return as live streaming, betting, and malware infrastructure in the Sable Squirrel operation.

Infoblox says a group it tracks as Sable Squirrel bought more than 10,000 expired domains and turned them into infrastructure for illegal sports streams, betting redirects, and malware command-and-control. The researchers confirmed about $430,000 spent on roughly 160 individually priced domains and estimate the full portfolio cost more than $7 million.

The practical lesson is not that every visitor to a streaming page was infected. It is that an old domain, a valid HTTPS connection, and even a working video are not reliable safety signals after ownership changes. If the page opened redirects, requested notifications, or delivered a file or app, the response should match that interaction.

What Infoblox found

Finding Verified detail
Domain portfolio More than 10,000 expired or drop-caught domains linked to Sable Squirrel.
Acquisition cost About $430,000 confirmed across roughly 160 priced purchases; more than $7 million estimated for the wider portfolio.
Malware traffic More than 31,000 samples communicated with the domains, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, and files carrying HiddenTear signatures.
Speed of reuse 24% of domains were activated the same day, 76% within one week, and 94% within two weeks.

Some domains performed two jobs at once: they displayed live streaming pages to visitors while also receiving traffic associated with infected devices. That distinction matters. The report links malware samples to domain infrastructure; it does not say that merely watching a stream automatically installed malware.

Infoblox diagram showing promotion channels feeding illegal streaming and betting redirects while some of the same domains communicate with infected devices as malware command-and-control.
Infoblox maps the Sable Squirrel funnel from promotion and illegal streaming to betting redirects; a subset of the same domains also serves as malware command-and-control. Source: Infoblox Threat Intel.

Why expired domains are valuable to attackers

An expired domain can retain backlinks, search history, old bookmarks, direct traffic, and a reputation score earned by its previous owner. A buyer can register it through a drop-catching service and inherit those signals without inheriting the old organization. Forgotten email addresses, DNS records, and third-party accounts may add more opportunities.

Sable Squirrel used that residual trust as an acquisition channel. Social posts and messaging groups promoted free streams; the pages then exposed visitors to aggressive advertising, gambling destinations, or other redirects. The same domain portfolio could support malware traffic in the background, making a domain-age check useful context but never a verdict.

A working stream is not a safety verdict

A convincing player gives the operator time to monetize attention. Fake play buttons, overlays, pop-ups, and notification prompts can move a visitor away from the stream to a download or credential form. The same mechanics appear across free sports-streaming scams and movie-streaming scams.

Check the exact address before interacting. The Gridinsoft Website Reputation Checker can add domain-age, blacklist, and content signals, but a clean result cannot prove that the current owner is trustworthy.

What to do, based on what happened

What happened Next action
You only opened the page Close it and any redirects. A page view alone is not proof of infection. Check Downloads and browser notifications for anything the site added.
You allowed notifications Remove the site from the browser’s notification permissions. Do not click later alerts that claim an infection or prize.
You entered a password or card details Use the real service or bank app from a clean path. Change any reused password, revoke active sessions, and contact the card issuer if payment data was submitted.
A file downloaded but was not opened Delete or quarantine it without launching it. If you need to preserve it for work, hand it to your security team instead of testing it yourself.
You ran an app, APK, extension, or installer Stop sensitive activity on that device, remove the unwanted software or extension, and run a full security scan. On Android, verify that Google Play Protect is enabled. Change important credentials from a clean device if an information stealer is possible.

If a suspicious download appeared but you did not open it, use the narrower downloaded-file response checklist. Record the domain, time, redirect address, filename, and any permissions granted before clearing browser history.

What domain owners should check

  • Renew important domains before they enter auction or deletion, including campaign and redirect domains.
  • Inventory email aliases, DNS records, OAuth callbacks, mobile deep links, and vendor accounts that still reference retired domains.
  • Monitor newly registered lookalikes and recently dropped assets that retained traffic or backlinks.
  • Remove stale references before allowing a domain to expire, and warn users if an abandoned address has changed hands.

References

  1. Infoblox Threat Intel. “$7 Million in Expired Domains Fuel a Streaming Empire With a Malware Secret.” August 13, 2026. primary investigation.
  2. Infoblox Threat Intel. “Drop Something? Don’t Worry, Someone Caught It.” August 13, 2026. domain lifecycle research.
  3. Google. “Use Google Play Protect to help keep your apps safe and your data private.” Accessed August 14, 2026. official Android guidance.
Share This Article
With a strong background in consumer safety and fraud prevention, Daniel specializes in providing actionable tips and advice to users. His focus is on helping individuals understand the risks of interacting with fraudulent sites and services
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?