Skip to content
Return to Infoblox Homepage

Infoblox Threat Intel

Swiping Squirrel

Swiping Squirrel operates the most prolific dropcatch affiliate fraud network Infoblox tracks, acquiring 3,000+ domains embedded in existing malicious infrastructure since at least 2022. Visitors are silently redirected to zero-click advertising platforms—primarily Team Internet’s ZeroPark—where their traffic is auctioned to buyers that may include scammers, malware distributors, and commercial advertisers. Client-side fingerprinting and cloaking filters bots and other non-targeted traffic. Confirmed downstream destinations include AliExpress affiliate links, Kelkoo price comparison, and ClickFix attacks.

  • Operating since: 2022
  • Infoblox discovered: March 2025
  • Infoblox published: August 2026
  • Prevalence: Common

Threat actor resources

Blog

Infoblox Threat Intel
August 13, 2026

Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows

Dropcatch actors inherit traffic from compromised websites by acquiring expired malicious domains and redirecting victims to scams and malware.

Read more
Back To Top