Infoblox Threat Intel
Shady Squirrel
Shady Squirrel is a Russian-speaking threat actor that teams up with others to deliver remote access trojans (RATs) and information stealers. They leverage dropcatch domains embedded in compromised websites to operate a traffic distribution system (TDS). This actor uses multi-step cloaking, server-side fingerprinting, and Keitaro and custom JavaScript injections to conceal their malicious content. Notably, Shady Squirrel is an affiliate of the notorious SocGholish actor. Prominent targets are the United States and Japan.
DNS analysis identified over 700 actor-controlled domains, including infrastructure formerly operated by TA2726 and a legitimate CDN. Referrer-gated fingerprinting and Keitaro cloaking make the actor nearly invisible to automated scanning.
- Operating since: July 2023
- Infoblox discovered: October 2025
- Infoblox published: August 2026
- Prevalence: Common
