Skip to content
Return to Infoblox Homepage

Infoblox Threat Intel

Shady Squirrel

Shady Squirrel is a Russian-speaking threat actor that teams up with others to deliver remote access trojans (RATs) and information stealers. They leverage dropcatch domains embedded in compromised websites to operate a traffic distribution system (TDS). This actor uses multi-step cloaking, server-side fingerprinting, and Keitaro and custom JavaScript injections to conceal their malicious content. Notably, Shady Squirrel is an affiliate of the notorious SocGholish actor. Prominent targets are the United States and Japan.

DNS analysis identified over 700 actor-controlled domains, including infrastructure formerly operated by TA2726 and a legitimate CDN. Referrer-gated fingerprinting and Keitaro cloaking make the actor nearly invisible to automated scanning.

  • Operating since: July 2023
  • Infoblox discovered: October 2025
  • Infoblox published: August 2026
  • Prevalence: Common

Threat actor resources

Blog

Infoblox Threat Intel
August 13, 2026

Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows

Dropcatch actors inherit traffic from compromised websites by acquiring expired malicious domains and redirecting victims to scams and malware.

Read more
Back To Top