Infoblox Threat Intel
Stuffy Squirrel
Stuffy Squirrel operates a traffic distribution system (TDS) built on dropcatch domains previously embedded in compromised websites, routing their inherited visitors to popunder and push notification advertising networks. The malicious payload is concealed inside what appears to be a legitimate Raphael.js SVG library and only activates when an incoming request matches the exact URL the prior owner left behind, a server-side checkpoint that keeps the actor invisible to direct scans. Destinations span adult content, e-commerce affiliate fraud, and online gambling. Evidence points to a likely Russian or Eastern European origin.
- Operating since: 2020
- Infoblox discovered: October 2025
- Infoblox published: August 2026
- Prevalence: Common
