{"id":14000,"date":"2026-08-13T05:58:48","date_gmt":"2026-08-13T12:58:48","guid":{"rendered":"https:\/\/www.infoblox.com\/blog\/?p=14000"},"modified":"2026-08-13T06:01:54","modified_gmt":"2026-08-13T13:01:54","slug":"dropcatch-scavengers-expired-malicious-domains-become-cash-cows","status":"publish","type":"post","link":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/","title":{"rendered":"Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows"},"content":{"rendered":"<p>Dropcatch actors inherit traffic from compromised websites by acquiring expired malicious domains and redirecting victims to scams and malware.<\/p>\n<p><strong>Infoblox Threat Intel | Dropcatch series | Part 3 of 3<\/strong><\/p>\n<h3>Executive Summary<\/h3>\n<p>Purchasing expired domains from legitimate companies is a well-known threat actor trick. By acquiring these domains, a practice called dropcatch, they gain the reputation of the original owner. In our companion blog, we introduced a threat actor who has spent massive amounts of money doing exactly this to prop up their malware and gambling operations. But there\u2019s another class of dropcatch actors who repurpose malicious domains. It\u2019s surprising at first, but it actually makes sense. Here\u2019s why.<\/p>\n<p>Every year, tens of thousands of websites are compromised, leading hapless visitors to a wide variety of scams and malware. Some of the most pernicious threat actors, like SocGholish and ClearFake, use these sites to steal user credentials and sell them to others for further exploitation. These compromised sites typically contact an actor-controlled domain for a routing decision of the potential victim. When those domains expire and go unclaimed, the requests do not stop; they simply go unanswered.<\/p>\n<p>Why let a good compromise go to waste? For the threat actors we describe in this blog, that gap\u2014the dropped domain\u2014is a business opportunity. Instead of compromising websites themselves, these actors acquire expired domains and immediately begin receiving traffic from the infection chains their predecessors left behind. Then they inject their own content. They are in effect, scavengers.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-catch-part-3-thumbnail.jpeg\"><\/p>\n<p>What you will learn here is that the nature of the scavenger varies. They all fraudulently acquire traffic and resell it to affiliate programs, but the way in which they do so, and the impact to users varies widely. There\u2019s nothing in plain sight. These financially motivated actors have gone unnoticed because they obfuscate their operations, both in their scripts and in server-side cloaking. One actor sells to a large global media commerce platform, another sells to advertising networks most people won\u2019t recognize, and the third sells traffic to big name cybercriminals like SocGholish.<\/p>\n<p>They co-exist on many compromised websites, operating in a race condition to grab the potential victim. Often domains pass from one of these actors to another over time. Between the three actors highlighted here, they own thousands of domains embedded in tens of thousands of compromised sites. Despite their widespread presence, to our knowledge, none of these have been discussed before.<\/p>\n<p>This blog covers three of the dropcatch actors we have been tracking via DNS, along with their ecosystem (Figure 1):<\/p>\n<ul class=\"list-spacing\">\n<li>Stuffy Squirrel is a specialist in stuffing their malicious activity into legitimate scripts<\/li>\n<li>Shady Squirrel partners with initial access brokers and enabled a large-scale return by SocGholish less than a month after <a href=\"https:\/\/www.europol.europa.eu\/media-press\/newsroom\/news\/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks\" target=\"_blank\"><strong>disruption by Operation Endgame<\/strong><\/a>. Research led to several discoveries, including a tech support actor, a previously unpublished two-part Keitaro injection chain, and an unusual Help TDS infection vector<\/li>\n<li>Swiping Squirrel, the most prolific of the bunch, sends their fraudulent traffic to zero click advertising platforms which is resold and often ends at scams or malware<\/li>\n<\/ul>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows-figure1.jpg\"><\/p>\n<p class=\"image-caption\">Figure 1. The dropcatch actors and ecosystem covered in this paper<\/p>\n<h3>The Scavenging Model<\/h3>\n<p>There is a surprising amount of dropcatch acquisition of \u201cknown bad\u201d domains. Security companies\u2014like us\u2014sometimes acquire malicious domains to collect telemetry about compromised hosts. But we have uncovered several actors who grab expired malicious domains so they can repurpose them. As far as we can tell, these actors monitor compromised websites, just like the security industry does, and when the domain expires, they swoop in to claim it. Once they own the domain, without hacking anything, they redirect users to their own scams or malware. A domain that is embedded in thousands of old sites can make the rounds through several threat actors all through dropcatch or variations of it.<\/p>\n<p>We originally referred to this class of actors as \u201cThieves\u2019 Thieves\u201d because they grab traffic from other criminals, but really, they are opportunistic scavengers. Aside from purchasing expired malicious domains, we have found that they often coexist on a compromised site. The result is a race to acquire victims: the same compromised domain may be redirected by different dropcatch actors depending on website visitor characteristics, timing, and other factors. We use squirrels for threat actors that are domain hoarders. The three actors we will describe here are full of mischief and thievery you expect from the clever animals you contend with in your own backyard. They are indeed scavengers.<\/p>\n<h3>Stuffy Squirrel<\/h3>\n<p>True to their name, Stuffy Squirrel is a specialist in hiding malicious activity inside legitimate scripts. The actor has been continuously active since at least 2020 and has operated a traffic distribution system (TDS) across three generations of dedicated infrastructure. They sell traffic to specific affiliate advertising networks. The website visitor may end at a scam, unwanted content, or a <a href=\"https:\/\/urlscan.io\/result\/019f6250-1ffa-74ca-aec9-a741e2d53966\/\" target=\"_blank\"><strong>decoy<\/strong><\/a>.<\/p>\n<p>They have maintained the same publisher account identifier across all of them\u2014evidence of a single, persistent operator. The infrastructure consists almost entirely of dropped domains that once served malicious infrastructure for various actors, including TA2726, and actors running Magecart and Balada injection campaigns. We have identified over 500 domains controlled by this actor.<\/p>\n<p><strong>Evading Detection<\/strong><\/p>\n<p>Stuffy Squirrel evades detection through two independent server-side checkpoints, either of which can stop the chain before any malicious activity is visible. These techniques have kept them in business for the last six years. See Figure 2 for a depiction of how this actor operates; details of these steps follow.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows-figure2.jpg\"><\/p>\n<p class=\"image-caption\">Figure 2. The event chain for Stuffy Squirrel<\/p>\n<p>The first check comes when a victim loads the compromised page. The live payload is served only when the incoming request matches the specific URL the original attacker left behind in the victim site&#8217;s code. Any other request\u2014a scanner probing the actor\u2019s dropcatch domain directly, a path that was never previously embedded in a victim page\u2014receives a decoy instead. The decoy is a legitimate and widely used Scalable Vector Graphics (SVG) mathematics library, <a href=\"https:\/\/dmitrybaranovskiy.github.io\/raphael\/\" target=\"_blank\"><strong>Rapha\u00ebl.js<\/strong><\/a>.<\/p>\n<p>The live payload is the same filename but with a 1,225 character Immediately Invoked Function Expression (IIFE) inserted that executes when the script loads and removes itself from the page when finished. To a scanner, both files look like Raphael.js. The difference is invisible until the IIFE runs.<\/p>\n<p>The second check occurs when the payload attempts to call the actor\u2019s popunder advertising gateway. Even when the browser passes the first check and the IIFE executes, the TDS evaluates each incoming request independently and doesn\u2019t always respond. We have seen instances where the payload executed and no popunders were served. This is due to a third layer of evasion that sits beyond both server-side checks: the popunder windows only open on a real user click. Even when both checks pass and the ad delivery platform loads successfully, nothing happens until the visitor interacts with the page. Automated scanners execute scripts but do not click, so the final delivery stage\u2014the popunder windows and everything downstream of them\u2014remains completely invisible to automated analysis even when the full chain is active.<\/p>\n<p>All three checks operate independently.<\/p>\n<p><strong>Inside the Injection<\/strong><\/p>\n<p>Stuffy Squirrel\u2019s presence on a compromised site is split into two components. The first is a script server: a dedicated domain hosting the actor\u2019s malicious JavaScript that loads when a user visits the site. The history of these domains illustrates the layers of the scavenging model. The domain <a href=\"https:\/\/blog.sucuri.net\/2023\/01\/massive-campaign-uses-hacked-wordpress-sites-as-platform-for-black-hat-ad-network.html\" target=\"_blank\"><strong>weatherplllatform[.]com was previously used<\/strong><\/a> as Balada injector infrastructure, infecting thousands of WordPress sites during the campaign&#8217;s peak and was <a href=\"https:\/\/blog.sucuri.net\/2023\/04\/balada-injector-synopsis-of-a-massive-ongoing-wordpress-malware-campaign.html\" target=\"_blank\"><strong>Sucuri\u2019s<\/strong><\/a> second most-blocklisted resource in 2022. The domain magesource[.]su was previously used as a <a href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/update-javascript-skimmer-enhancements\" target=\"_blank\"><strong>Magecart card-skimming<\/strong><\/a> domain targeting compromised Magento stores to steal payment card data. In both cases, Stuffy Squirrel inherited not just the domain but the entire well-established victim pool that came with it.<\/p>\n<p>The first script acts as a remote JavaScript loader dynamically building a script element and loading from another actor-controlled domain. This second domain coordinates the popunder delivery chain, routing victim traffic to an advertising exchange where it is auctioned in real time. Since November 2025, gsstats[.]ru has served as the actor\u2019s current primary entry point, replacing tofuturepubs[.]com, which was used throughout 2024 and 2025. The second part of the process is done over several calls to the same entry point. The victim\u2019s URL is encoded and passed it to the server, which then triggers the popunder delivery chain after user interaction, handing the visit to an ad exchange. The primary script also features an error-reporting mechanism: if the domain is unreachable within five seconds, the script uses a tracking pixel and sends an HTTP request back to the script server domain, notifying the operator. If downstream ad delivery fails, the server receives an immediate callback reporting the failure, allowing the actor to monitor its own delivery pipeline in real time.<\/p>\n<p><strong>Monetization Methods<\/strong><\/p>\n<p>Stuffy Squirrel has consistently monetized their operations through affiliate advertising platforms. These platforms operate in several verticals but are dominated by adult content. Other verticals we\u2019ve seen include e-commerce affiliate fraud and online gambling. We\u2019ve organized the actor\u2019s affiliate network activity into two phases based on observed shifts in platform preference.<\/p>\n<p>Phase I: PushHouse and ExoClick<\/p>\n<ul class=\"list-spacing\">\n<li>Through January 2025, the actor operated as a publisher in the PushHouse network, a company known for popunder and in-page push notification ad delivery. The actor also simultaneously ran ExoClick popunder ads, routed through actor-controlled TDS domains to ExoClick\u2019s delivery infrastructure.<\/li>\n<\/ul>\n<p>Phase II: ExoClick and an unknown Russian popunder network<\/p>\n<ul class=\"list-spacing\">\n<li>Since March 2025, the actor has continued to publish for ExoClick while migrating from PushHouse to a Russian popunder advertising network. It is likely that this is a commercial affiliate advertising network. This network has cycled through multiple backend domains, all white-label deployments of the same underlying ad platform sharing the actor&#8217;s persistent publisher ID. When triggered, the platform opens popunder windows which route visitor traffic through an advertising exchange and ultimately delivers it to the destination. ExoClick delivers its own popunders through a parallel channel simultaneously, confirming both systems remain active at the same time on the same compromised page.<\/li>\n<\/ul>\n<h3>Shady Squirrel<\/h3>\n<p>While the financial fraud of Stuffy Squirrel might not seem that serious, Shady Squirrel is a totally different matter. You aren\u2019t going to find this character showing their true colors via open-source scanning sites. Their malicious behavior is only triggered when the URL visited contains a specific referral record. Even then, victims must pass through a multi-step cloaking filter before any malicious content is served. The Russian-speaking actor operates a TDS grounded in domains that linger within compromised websites. They use custom JavaScript injections, as well as Keitaro, and server-side fingerprinting. If a bot or scanner is detected, <a href=\"https:\/\/urlscan.io\/result\/019ef812-2c92-7533-bd90-9669d33bbe06\" target=\"_blank\"><strong>the original page<\/strong><\/a> will be shown.<\/p>\n<p>For a long time, we tracked their activity but weren\u2019t sure of the purpose. That all changed in June when Randy McEoin saw that an old TA2726 domain was serving up tech support scams\u2014the nut cracked open. A few weeks later, Randy uncovered a real surprise: Shady Squirrel was sending traffic to the notorious threat actor SocGholish. Suddenly, Shady Squirrel went from \u201creally interesting\u201d to \u201ccrazy interesting.\u201d And this is why we believe collaboration is key to success in cybersecurity.<\/p>\n<p>Shady Squirrel has operated since at least July 2023. In 2026, they sent traffic to four downstream actors: a Russian gambling platform called 1Win; a tech support scam actor; the original fake update actor, SocGholish; and a Keitaro server. The Keitaro injections operate in an unusual manner; more about that later.<\/p>\n<p>To make it through the TDS gates to a final payload (aka \u201cmoney page\u201d or \u201cblack page\u201d), the URL must include a specific referrer string. In the <a href=\"https:\/\/urlscan.io\/result\/019f1abc-890c-723f-8d23-9420ff5f11d6\/\" target=\"_blank\"><strong>1Win case<\/strong><\/a>, an internal referral is used to load a sticky on-page gambling banner. The redirects in the tech support scams and SocGholish require the referrer to be a search engine. Even then, most visits will end up at the original website. Figure 3 shows an overview of payload routing.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows-figure3.jpg\"><\/p>\n<p class=\"image-caption\">Figure 3. Payload routing for Shady Squirrel; when the compromised page is scanned or visited directly, no action will occur<\/p>\n<p>We have identified over 700 domains acquired by Shady Squirrel since 2023. While they do freshly register some domains, their portfolio is primarily composed of dropcatch domains previously operated by other threat actors and left dormant on compromised sites before being reactivated for Shady Squirrel infrastructure. These include domains previously operated by malware actors like TA2726 as well as affiliate advertising platforms. In one high profile case, they snagged a legitimate domain that was used in cookie consent; a clever supply chain hijack. The domains they have purchased or otherwise acquired include:<\/p>\n<ul class=\"list-spacing\">\n<li><a href=\"https:\/\/urlscan.io\/result\/019f5b6b-7691-74f9-a41c-8feaf6202d20\" target=\"_blank\"><strong>blacksaltys[.]com<\/strong><\/a> (formerly TA2726)<\/li>\n<li><a href=\"https:\/\/urlscan.io\/result\/dec4110e-b1c2-4036-8f24-9b05131de71b\/\" target=\"_blank\"><strong>simplejscdn[.]com<\/strong><\/a> (formerly used by affiliate of commercial push notification service)<\/li>\n<li><a href=\"https:\/\/urlscan.io\/result\/53d5891a-815f-4c60-ac5d-2ca54a8a3ac5\/\" target=\"_blank\"><strong>brodirect3s[.]site<\/strong><\/a> (formerly commercial push notification service)<\/li>\n<li><a href=\"https:\/\/urlscan.io\/result\/019f40f6-fdca-771a-a795-63f34288320d\" target=\"_blank\"><strong>wesq[.]me<\/strong><\/a> (formerly commercial push notification service affiliate)<\/li>\n<li>imhd[.]io (formerly a legitimate CDN)<\/li>\n<\/ul>\n<p>Figure 4 depicts the actor\u2019s domain acquisition trends. The values are estimates based on the domains we have been able to confirm. Shady Squirrel\u2019s activity appears to be run-of-the-mill arbitrage until early 2025 when they begin injecting calls to a Keitaro server. Later in 2026, they use the same style to make custom injections.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows-figure4.jpg\"><\/p>\n<p class=\"image-caption\">Figure 4. Estimated cumulative growth of Shady Squirrel\u2019s domain stash. Each month indicates the number of actively controlled domains at that time.<\/p>\n<p>While Shady Squirrel primarily gains access to sites through existing compromises, we have seen direct injection of their scripts into several sites. In one <a href=\"https:\/\/urlscan.io\/result\/019f5bd4-ca23-708e-aade-ef47c282aa45\/\" target=\"_blank\"><strong>July 2026 example<\/strong><\/a>, we saw two different styles of injections, both belonging to the threat actor, appended to legitimate themes files used by the website. This would indicate that they are either in the WordPress exploitation game themselves or have affiliates using their scripts. In these cases, they are using newly registered domains instead of dropcatch ones.<\/p>\n<p>There are a few versions of their bespoke injection scripts. We believe the injections are primarily used to drive traffic to tech support scams, though in the past they also sent traffic to affiliate marketing networks. In some cases, a newly created domain is used for a Keitaro injection for some months and then begins serving the custom injection. The reason for this isn\u2019t clear. We\u2019ll start with their affiliation with initial access brokers and then come back to the Keitaro servers.<\/p>\n<p><strong>The Tech Support Scam Actor<\/strong><\/p>\n<p>Because Shady Squirrel is resistant to scanning, we confirmed the browser lock operation on a research machine and analyzed the resulting packet capture. Redirection only occurred when the site visit came from a search engine, and when the device was running the Windows operating system. A series of pop-up windows filled the screen with warnings that the machine had been hacked, and that the user needed to dial Microsoft support at a specific phone number; see Figure 5.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows-figure5.jpg\"><\/p>\n<p class=\"image-caption\">Figure 5. Screenshot of the false tech support alarm targets Japanese and U.S. residents<\/p>\n<p>While it is difficult to find evidence of Shady Squirrel redirections in open-source tools, there are <a href=\"https:\/\/urlscan.io\/result\/019f2ca9-0317-7041-a871-aed9083a9b9a\" target=\"_blank\"><strong>many scans for the tech support scam actor<\/strong><\/a>. The word scam here is misleading. These actors use live call centers to convince people to install remote access tools, giving them full control of the machine. It\u2019s a lot worse than buying an unnecessary antivirus subscription. From that point, the actor can steal credentials and sell them to others for a variety of uses, including enterprise data breaches. The campaigns we are tracking were first seen in April 2026. They only target victims in Japan and the United States.<\/p>\n<p>Figure 6 shows an overview of the complete attack from the compromised site injections to the tech support alerts. When the malicious site is reached, it quickly redirects to load a static HTML page with a random filename. A 1&#215;1 pixel image is fetched to capture the visitor\u2019s IP address and user agent information. The IP address is used to determine which phone number to display, and likely to credit the publishing affiliate for the visit as well.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows-figure6.jpg\"><\/p>\n<p class=\"image-caption\">Figure 6. The attack chain from Shady Squirrel to a Windows machine compromise through the affiliated tech support actor<\/p>\n<p>Figure 6 excludes a connection to a second domain, which returns the call center phone number. We probed this second set of domains from various locations and user agents to identify active call centers. Our experiment revealed three numbers, all routed to the United States:<\/p>\n<ul class=\"list-spacing\">\n<li>(201) 409-2894 (seen for Japanese targets only)<\/li>\n<li>(877) 481-2126 (toll free)<\/li>\n<li>(888) 756-6605 (toll free)<\/li>\n<\/ul>\n<p>A specific URL format identifies the affiliate. When we probed the domains directly, e.g., renpaste[.]top, it returned \u201cfuck you pig.\u201d In other <a href=\"https:\/\/urlscan.io\/result\/019f2733-3ba1-777a-9006-68d5d5dd3140\/\" target=\"_blank\"><strong>public scans<\/strong><\/a>, renpaste[.]top claims to be a \u201csnippet hosting service,\u201d i.e., a service to host configs via links. Indeed, that is what it does. Since April, we have observed nine phone number server domains.<\/p>\n<p>The HTML content is a bit of a mystery. It contains an AES-encrypted section that is decrypted client-side using the URL fragment as the key. However, we never captured a URL containing that fragment, and the scam content loads regardless of decryption. The payload page is reached via a client-side navigation triggered by an initial request to the parent directory. And that directory-level response is exactly the kind of fast, small reply that scanners are known to miss. Perhaps there is a fragment passed in some cases that would decrypt the blob; we just aren\u2019t sure.<\/p>\n<p>As of early July, that unknown technical support scam actor has gone silent. Before that, the thief abused Microsoft Azure static webhosting to serve lures, creating nearly 10k accounts a month across at least nine regions globally. Each site was short-lived. We suspect this actor had multiple affiliates but can&#8217;t confirm. From our observations, Shady Squirrel seemed to be their largest source of traffic. It makes sense: Shady Squirrel takes advantage of thousands of long-compromised websites to identify potential victims, whereas the other affiliates appear to be creating new traffic sources.<\/p>\n<p>Right when Shady Squirrel stopped sending traffic to the tech support scam actor (and in fact we saw no more activity related to that actor anywhere), we saw them begin to send traffic to SocGholish.<\/p>\n<p><strong>SocGholish<\/strong><\/p>\n<p>Our original plan was to trigger the tech support scam, call the number, and record the conversation. We could use the data captured during that experience to understand what technique they use to get into victims\u2019 machines. We started with a Google search result for a compromised domain (Figure 7). But this was before we uncovered the shift away from the tech support scam, so when we went to make the call, we were redirected to a fake update instead! See Figure 8. Not surprisingly, the update was <a href=\"https:\/\/www.virustotal.com\/gui\/file\/230aec2350a0eb778d51d277eb7bd95cf4c0246c32fbcbc0658a2e464ca45706\" target=\"_blank\"><strong>identified as malware<\/strong><\/a>. The next day, Randy McEoin validated the path as SocGholish.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows-figure7.jpg\"><\/p>\n<p class=\"image-caption\">Figure 7. Screenshot of the lure used to trigger the Shady Squirrel redirection to SocGholish found via Google search run in mid-July 2026<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows-figure8.jpg\"><\/p>\n<p class=\"image-caption\">Figure 8. Screenshot of a SocGholish fake update delivered via Shady Squirrel on July 10, 2026<\/p>\n<p>At that point, the Shady Squirrel story became even more interesting. SocGholish had been disrupted by <a href=\"https:\/\/www.operation-endgame.com\/\" target=\"_blank\"><strong>Operation Endgame<\/strong><\/a>, a joint law enforcement and industry action, less than a month earlier, in mid-June 2026. Over 300 servers and 140 domains were seized or cleaned during the event, and cryptocurrency assets totaling more than $41million Euro were frozen. Actions like these are impactful but unfortunately also temporary. The question is always how quickly the actor will recover and what will they do next? In this case, we now know they partnered with Shady Squirrel, regaining access to tens of thousands of compromised sites effortlessly about 10 days later.<\/p>\n<p>For example, Shady Squirrel registered the domain advanceslibrary[.]com on June 27th likely specifically for SocGholish. Shortly after registration, injections calling the domain started rolling in, but we did not have a confirmed fake update payload until July 10th.<\/p>\n<p>Both SocGholish and the unknown tech support scam actor are sent traffic via a custom injection, but most of the time Shady Squirrel relies on Keitaro injections\u2014so let\u2019s go there.<\/p>\n<p><strong>Keitaro Injections<\/strong><\/p>\n<p>The Keitaro injection seems banal at first. It constructs a URL for a Keitaro client with a handful of collected parameters and then calls it. In most of the cases we\u2019ve seen, the returned script has done nothing. We called it \u201cthe boring injection.\u201d Not only did the Shady Squirrel injection seem ordinary, but the Keitaro response itself never seemed to trigger any interesting payload. But in reviewing many publicly available scans, we realized the entire mechanism was more complicated and mysterious than we thought.<\/p>\n<p>We still don\u2019t fully understand this mechanism, but we know enough to realize it is interesting. Here\u2019s what happens in that obfuscated script:<\/p>\n<ul class=\"list-spacing\">\n<li>It creates a window configuration with a random-looking name, e.g., _1yp7C3MQfbZ7qNXv, that is hard-coded into the actor\u2019s script<\/li>\n<li>Within that config it sets three variables: unique, ttl, and R_PATH<\/li>\n<li>It collects or creates a series of parameters, and then constructs the final URL using R_PATH, the base of the Keitaro client<\/li>\n<li>It fetches the URL with an HTTP GET, passing the name=&lt;window.config&gt; value<\/li>\n<\/ul>\n<p>Not super exciting, right? Well, the next script makes it more intriguing. The Keitaro server responds with a script that incorporates the name parameter, e.g., _1yp7C3MQfbZ7qNXv, to inherit the window configuration when the script is run client side. The script:<\/p>\n<ul class=\"list-spacing\">\n<li>Reads the local storage state<\/li>\n<li>Receives the campaign config, subid, and token value for related cookies<\/li>\n<li>Either does nothing, uses a meta-refresh to redirect, or injects HTML directly<\/li>\n<\/ul>\n<p>The seemingly random window configuration variable is hard coded into the initial script and may be reused across injections. Figure 9 shows an example of this where Shady Squirrel is sandwiched between two calls to the same Keitaro server. In some cases, the Keitaro server itself is on a Shady Squirrel domain, and in other cases, like that in Figure 9, it is on different hosting that we can\u2019t confirm is related.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows-figure9.jpg\"><\/p>\n<p class=\"image-caption\">Figure 9. An overview of the two-part Keitaro sequence based on a <a href=\"https:\/\/urlscan.io\/result\/019637fd-223c-7190-a99c-4174fedff448\" target=\"_blank\"><strong>URLscan<\/strong><\/a> of an example indicator. The Shady Squirrel injection creates a window configuration that is consumed by the Keitaro that it subsequently calls.<\/p>\n<p>So, who owns the Keitaro server? Not sure. It could be a central service or a kit, even both. We suspect it is a service, and Shady Squirrel is a client. But proving that, or who really controls it, seems difficult. All the confirmed Shady Squirrel Keitaro injects set one of two server cookies, 0c9c8 or 208c9. But these same cookies are seen for seemingly unrelated actors, including TA2726. <a href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/patterns-pirates-and-provider-action-what-we-learned-working-with-keitaro\/\" target=\"_blank\"><strong>In March<\/strong><\/a>, we postulated that these were genuine, randomly occurring collisions in the cookie names. But now we are not so sure. For example, we have seen cdnjslibraries[.]com, a Shady Squirrel dropcatch domain, used both as the Keitaro domain and later for the custom injection, which does not make an external Keitaro call.<\/p>\n<p>Regardless of whether it is a kit, a service, or both, for sure it is a \u201cstyle.\u201d We can date the two-part Keitaro injection style to <a href=\"https:\/\/urlscan.io\/result\/af3b6aa0-eae5-45d0-a1f1-1df7087953c7\" target=\"_blank\"><strong>September 2020<\/strong><\/a>. In early versions of the handoff, the calling script was not obfuscated. Regardless, the response is always the same structure, utilizing the window configuration. Lo and behold, the earliest sample served a redirection! It went to <a href=\"https:\/\/www.godaddy.com\/resources\/news\/help-tds-malicious-plugins-redirect-tech-support-scams\" target=\"_blank\"><strong>the notorious Help TDS<\/strong><\/a> which then dumped out to an affiliate advertising platform smartlink. In this chain:<\/p>\n<ul class=\"list-spacing\">\n<li>The website contained widgets which loaded JavaScript from sport2news[.]com, which<\/li>\n<li>Constructed the window configuration and established both the Keitaro call and a postback link,<\/li>\n<li>Called the Keitaro server at ads-analytic[.]com, which returned JavaScript that<\/li>\n<li>Redirected to Help TDS for affiliate 7321600252413, which rejected the visitor and<\/li>\n<li>Called the TDS with affiliate id u=b1tk60t<\/li>\n<\/ul>\n<p>We believe this surfaces a new attack chain for Help TDS. Instead of insertion into a compromised site through malicious plugins, it is returned via the Keitaro server. The same server, around the same time, redirects to the same affiliate advertising platform for a <a href=\"https:\/\/urlscan.io\/result\/50851292-f738-4662-8402-4f4379091d69\/\" target=\"_blank\"><strong>seemingly unrelated affiliate<\/strong><\/a> (u=pgbk60a). This is one reason we lean toward a service of some kind\u2014though there could be kits and services combined! This same domain, ads-analytic[.]com was used for what appears to be an entirely different Keitaro server a few years later.<\/p>\n<p>The two-part Keitaro injection, whether it be Shady Squirrel or Help TDS affiliates leveraging it, is a complex weave of domains that change hosting, nameservers, and ownership over time. One thing that is consistent over time is the use of Keitaro to send users to affiliate advertising platforms.<\/p>\n<p><strong>Adtech Redirection<\/strong><\/p>\n<p>Until late-November 2024, the Keitaro servers redirected users to a single advertising TDS. The redirections paused and resumed a year later. We found examples recently where a Shady Squirrel injection led to a different affiliate advertising network. In April 2025, for example, there is a <a href=\"https:\/\/urlscan.io\/result\/019637fd-223c-7190-a99c-4174fedff448\/\" target=\"_blank\"><strong>scan on urlscan[.]io<\/strong><\/a> that starts with a Keitaro server and redirects to Shady Squirrel. We showed the relationship between the Keitaro server and Shady Squirrel earlier in Figure 9. In this instance, Shady Squirrel kicked off three events and one is a redirection to Propeller Ads\u2019 push monetization service, ProPush. Figure 10 depicts the calls and redirection chain. In mid-July, the domains pausewatchings[.]com and pills-europe[.]com also sent traffic to ProPush.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows-figure10.jpg\"><\/p>\n<p class=\"image-caption\">Figure 10. A Shady Squirrel chain observed in July 2026 triggers both the two-part Keitaro injection as well as a pop-up notification request for Propeller\u2019s ProPush service. It also incorporated a Binom tracker check.<\/p>\n<p>ProPush is a special project of Propeller Ads, as described in Figure 11 from their own website. We\u2019ve seen ProPush used more recently by Shady Squirrel as well. Whereas most of the time, scans with their injections will not trigger any payload, there are occasions where we\u2019ve seen the redirection to adtech.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows-figure11.jpg\"><\/p>\n<p class=\"image-caption\">Figure 11. Screenshot of Propeller Ads describing ProPush (propush[.]me) in a Quick Start Guide <a href=\"https:\/\/propellerads.com\/blog\/wp-content\/uploads\/2020\/04\/Propush.me-Quick-Start-Guide.pdf\" target=\"_blank\"><strong>available on their website<\/strong><\/a><\/p>\n<p>The domain pausewatchings[.]com was also leaked into a Facebook post on July 10th which seems a bit of an operational error by the actor. After remaining so stealthy for so long, a leak like this, as well as the adtech and SocGholish affiliations seem like a mighty big risk for Shady Squirrel.<\/p>\n<h3>Swiping Squirrel<\/h3>\n<p>Our final actor is another one involved in affiliate advertising. These dropcatch actors often co-exist on a single compromised website, just like the upstream threat actors they acquired the domains from. The one we see most often with Shady Squirrel is Swiping Squirrel. Indeed, we have seen them pick up domains from each other repeatedly, making it extra tricky to separate the activity without looking carefully at the scripts they deliver.<\/p>\n<p>Where Shady Squirrel is a hard core blackhat operator, Swiping Squirrel lives in a greyhat world. They acquire domains, mostly from compromised sites, and they sell the traffic through brokers similar to Stuffy Squirrel. The website visitor is still likely to encounter malicious content, but it doesn\u2019t come directly from Swiping Squirrel. As such they are at arm\u2019s length from real harm.<\/p>\n<p>According to our observations, Swiping Squirrel sells most of their traffic to Team Internet\u2019s ZeroPark. They also appear to be enrolled in an affiliate program for AliExpress and a handful of other commerce entities.<\/p>\n<p>Unlike Stuffy Squirrel, there are decent odds that a website visitor will land at malware through Swiping Squirrel due to the wide array of downstream advertisers from ZeroPark. We experienced a ClickFix attack this way: our click was sold by ZeroPark to AdventureFeeds, who in turn displayed the fake captcha, presumably through one of their own advertisers. AdventureFeeds has been reported multiple times as the source of malicious ads, including <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/feature\/Inside-Master134-Ad-networks-blind-eye-threatens-enterprises\" target=\"_blank\"><strong>connections with a notorious malvertiser<\/strong><\/a> called master134 and in <a href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/parked-domains-become-weapons-with-direct-search-advertising\/\" target=\"_blank\"><strong>our own reporting<\/strong><\/a> on the dangers of zero click parking. We have reported both Swiping Squirrel and AdventureFeeds activity to Team Internet.<\/p>\n<p>Figure 12 depicts how the upstream domain holders still drive traffic to affiliate programs through Swiping Squirrel.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows-figure12.jpg\"><\/p>\n<p class=\"image-caption\">Figure 12. Sample relationships between upstream actors and where the traffic is sold by Swiping Squirrel<\/p>\n<p>We have identified over 3k domains acquired by Swiping Squirrel since 2022. Even though this actor is selling traffic and not directly connected to malicious content distribution, they engage in deceptive tactics, beyond the use of compromised websites for their traffic source. The actor uses client-side JavaScript to fingerprint the user. This script is delivered via the lingering URL on the website. But the Swiping Squirrel server will only return this script when it is called from within the site; attempting to fetch it directly results in a <a href=\"https:\/\/urlscan.io\/result\/019f6301-5130-705f-874c-2e7fe20c55fa\" target=\"_blank\"><strong>\u201cnot found\u201d error<\/strong><\/a>. They then use the fingerprint results to cloak the domain. We consider all of this activity high risk to users and enterprises alike.<\/p>\n<p>The Swiping Squirrel affiliate advertising chain is mapped out in Figure 13. The steps from a user visit to an unwanted \u201cadvertisement\u201d are essentially a series of gates controlled by the actor:<\/p>\n<ul class=\"list-spacing\">\n<li>Using the URL that lingers on the website from the previous owner, Swiping Squirrel delivers a client-side fingerprint script. It does a basic anti-bot check and gathers information about the user, along with \u201ccampaign\u201d information.<\/li>\n<li>The fingerprint and campaign information is sent to the cloaker, which typically resides on the same domain, using index.php.<\/li>\n<li>The cloaking server will either return an empty set ({}) or an \u201cfw\u201d response that triggers the next step: a second connection using the path \/s\/index\/.<\/li>\n<li>The \/s\/index may return a meta-refresh response to a new domain, the relay server, using the path \/f\/index. It is this call that leads to a final bid for user traffic.<\/li>\n<li>The relay server sends an unconditional meta-refresh to the affiliate platform, e.g., ZeroPark, AliExpress, or Kelkoo.<\/li>\n<\/ul>\n<p><img decoding=\"async\" src=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows-figure13.jpg\"><\/p>\n<p class=\"image-caption\">Figure 13. The Swiping Squirrel affiliate advertising chain. The exact URL paths and parameters may vary.<\/p>\n<p>It\u2019s a roll of the dice from there\u2014the user might get malware, a scam, or an Alibaba shopping page as \u201cthey\u201d are sold to the highest bidder. Regardless of the path, content is delivered that the site visitor wasn\u2019t expecting, and their &#8220;click\u201d was gained fraudulently.<\/p>\n<h3>Parting Thoughts<\/h3>\n<p>We see around 65,000 new dropcatch domains every day. Some of them are legitimate registrations picking up domains people are going to use for commercial or personal use. But an awful lot are grabbed for grey to black purposes. Late last year, we covered the <a href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/parked-domains-become-weapons-with-direct-search-advertising\/\" target=\"_blank\"><strong>danger of zeroclick \u201cadvertising\u201d<\/strong><\/a> through parked domains. What we haven\u2019t talked about in this blog series on dropcatch is that a lot of the domains get parked in the same manner. In our companion report, we showed how one actor was using previously legitimate domains to prop up their malware and illegal gambling business. In this one, we saw how threat actors are repurposing expired malicious domains from website compromises. Any way you slice it, the risk posed by dropcatch domains is significant, arguably greater than that of newly registered domains.<\/p>\n<h3>Indicators<\/h3>\n<p>Indicators can also be found in our GitHub <a href=\"https:\/\/github.com\/infobloxopen\/threat-intelligence\" target=\"_blank\"><strong>repository<\/strong><\/a>.<\/p>\n<p><strong>Stuffy Squirrel<\/strong><\/p>\n<table border=\"1\" cellpadding=\"6\" cellspacing=\"0\">\n<thead>\n<tr>\n<th>Stuffy Squirrel Dropcatch Domains<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>blocksovetnik[.]ru<\/td>\n<\/tr>\n<tr>\n<td>checkoutbump[.]com<\/td>\n<\/tr>\n<tr>\n<td>hpmdnetwork[.]ru<\/td>\n<\/tr>\n<tr>\n<td>gsstats[.]ru<\/td>\n<\/tr>\n<tr>\n<td>magesource[.]su<\/td>\n<\/tr>\n<tr>\n<td>memtkh[.]com<\/td>\n<\/tr>\n<tr>\n<td>renteres[.]ru<\/td>\n<\/tr>\n<tr>\n<td>tofuturepubs[.]com<\/td>\n<\/tr>\n<tr>\n<td>weatherplllatform[.]com<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Shady Squirrel<\/strong><\/p>\n<table border=\"1\" cellpadding=\"6\" cellspacing=\"0\">\n<thead>\n<tr>\n<th>Shady Squirrel Dropcatch Domains<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>advanceslibrary[.]com<\/td>\n<\/tr>\n<tr>\n<td>blacksaltys[.]com<\/td>\n<\/tr>\n<tr>\n<td>brodirect3s[.]site<\/td>\n<\/tr>\n<tr>\n<td>cdnjslibraries[.]com<\/td>\n<\/tr>\n<tr>\n<td>imhd[.]io<\/td>\n<\/tr>\n<tr>\n<td>pausewatchings[.]com<\/td>\n<\/tr>\n<tr>\n<td>pills-europe[.]com<\/td>\n<\/tr>\n<tr>\n<td>simplejscdn[.]com<\/td>\n<\/tr>\n<tr>\n<td>wesq[.]me<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Swiping Squirrel<\/strong><\/p>\n<table border=\"1\" cellpadding=\"6\" cellspacing=\"0\">\n<thead>\n<tr>\n<th>Swiping Squirrel Dropcatch Domains<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>blackshelter[.]org<\/td>\n<\/tr>\n<tr>\n<td>bluegaslamp[.]org<\/td>\n<\/tr>\n<tr>\n<td>draggedline[.]org<\/td>\n<\/tr>\n<tr>\n<td>getshopstar[.]com<\/td>\n<\/tr>\n<tr>\n<td>jqueryapihelpers[.]com<\/td>\n<\/tr>\n<tr>\n<td>lzdatheme[.]com<\/td>\n<\/tr>\n<tr>\n<td>slurpslimes[.]org<\/td>\n<\/tr>\n<tr>\n<td>webpixel[.]app<\/td>\n<\/tr>\n<tr>\n<td>windowlight[.]org<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<style>\n.savy-seahorse-table {\nfont-size:14px;word-break: keep-all;}.savy-seahorse-table td:last-child, .savy-seahorse-table th:last-child {padding-right:10px;}.code-format {\/*font-family: 'Courier New';*\/}.image-caption {    font-size: 12px;margin-top:auto;}.list-spacing li{margin-bottom:20px}.img-container, .img-container-3-col {display: flex;flex-wrap: wrap;justify-content: space-between;}.img-container img {width: 49%;margin-bottom: 10px;}.img-container-3-col img {width: 30%;margin-bottom: 10px;object-fit: contain;}@media (max-width: 767px) {.img-container, .img-container-3-col {display: block;}.img-container img, .img-container-3-col img {width: 100%;}.grid-container {    grid-template-columns: 1fr!important;  }}@media (min-width: 767px) {.img-50{width:50%;}}.grid-container {  display: grid;  grid-template-columns: repeat(2, 1fr);  gap: 40px;  max-width: 800px;  margin: 0 auto;  align-items: stretch;margin-bottom: 20px;}.grid-item {   display: flex;  flex-direction: column;  justify-content: flex-start;}.grid-item img {  max-width: 100%;  height: auto;width: auto;}\n.youtube-responsive {\n  position: relative;\n  width: 100%;\n  padding-bottom: 56.25%; \/* 16:9 aspect ratio *\/\n  height: 0;\n  overflow: hidden;\n  margin-bottom: 20px;\n}\n.youtube-responsive iframe {\n  position: absolute;\n  top: 0;\n  left: 0;\n  width: 100%;\n  height: 100%;\n}\n.img-400{\nmax-width: 400px; width: 100%;\n}\n<\/style>\n<p><script>\njQuery('.single h1').html('<span class=\"gradient\">Dropcatch Scavengers<\/span>: Expired Malicious Domains Become Cash Cows');\n<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Dropcatch actors inherit traffic from compromised websites by acquiring expired malicious domains and redirecting victims to scams and malware. Infoblox Threat Intel | Dropcatch series | Part 3 of 3 Executive Summary Purchasing expired domains from legitimate companies is a well-known threat actor trick. By acquiring these domains, a practice called dropcatch, they gain the [&hellip;]<\/p>\n","protected":false},"author":397,"featured_media":13996,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[254],"tags":[1813,30,1843,1844,1845,913],"class_list":{"0":"post-14000","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threat-intelligence","8":"tag-dropcatch","9":"tag-dns","10":"tag-expired-domain","11":"tag-website-malware","12":"tag-wordpress-compromise","13":"tag-threat-actor","14":"entry"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Expired Malicious Domains Bring New Threats to Life<\/title>\n<meta name=\"description\" content=\"Dropcatch actors inherit traffic from compromised websites by acquiring expired malicious domains and redirecting victims to scams and malware.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Expired Malicious Domains Bring New Threats to Life\" \/>\n<meta property=\"og:description\" content=\"Dropcatch actors inherit traffic from compromised websites by acquiring expired malicious domains and redirecting victims to scams and malware.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/\" \/>\n<meta property=\"og:site_name\" content=\"Infoblox Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-13T12:58:48+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-13T13:01:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-catch-part-3-thumbnail.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"612\" \/>\n\t<meta property=\"og:image:height\" content=\"408\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Infoblox Threat Intel\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Expired Malicious Domains Bring New Threats to Life\" \/>\n<meta name=\"twitter:description\" content=\"Dropcatch actors inherit traffic from compromised websites by acquiring expired malicious domains and redirecting victims to scams and malware.\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Infoblox Threat Intel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"26 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\\\/\"},\"author\":{\"name\":\"Infoblox Threat Intel\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\"},\"headline\":\"Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows\",\"datePublished\":\"2026-08-13T12:58:48+00:00\",\"dateModified\":\"2026-08-13T13:01:54+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\\\/\"},\"wordCount\":5238,\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/drop-catch-part-3-thumbnail.jpeg\",\"keywords\":[\"dropcatch\",\"DNS\",\"expired domain\",\"website malware\",\"wordpress compromise\",\"threat actor\"],\"articleSection\":[\"Infoblox Threat Intel\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\\\/\",\"name\":\"Expired Malicious Domains Bring New Threats to Life\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/drop-catch-part-3-thumbnail.jpeg\",\"datePublished\":\"2026-08-13T12:58:48+00:00\",\"dateModified\":\"2026-08-13T13:01:54+00:00\",\"description\":\"Dropcatch actors inherit traffic from compromised websites by acquiring expired malicious domains and redirecting victims to scams and malware.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/drop-catch-part-3-thumbnail.jpeg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/drop-catch-part-3-thumbnail.jpeg\",\"width\":612,\"height\":408},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Infoblox Threat Intel\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/category\\\/threat-intelligence\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"name\":\"infoblox.com\\\/blog\\\/\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\",\"name\":\"Infoblox\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"width\":137,\"height\":30,\"caption\":\"Infoblox\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\",\"name\":\"Infoblox Threat Intel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"url\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"contentUrl\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"caption\":\"Infoblox Threat Intel\"},\"description\":\"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/author\\\/infoblox-threat-intel\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Expired Malicious Domains Bring New Threats to Life","description":"Dropcatch actors inherit traffic from compromised websites by acquiring expired malicious domains and redirecting victims to scams and malware.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/","og_locale":"en_US","og_type":"article","og_title":"Expired Malicious Domains Bring New Threats to Life","og_description":"Dropcatch actors inherit traffic from compromised websites by acquiring expired malicious domains and redirecting victims to scams and malware.","og_url":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/","og_site_name":"Infoblox Blog","article_published_time":"2026-08-13T12:58:48+00:00","article_modified_time":"2026-08-13T13:01:54+00:00","og_image":[{"width":612,"height":408,"url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-catch-part-3-thumbnail.jpeg","type":"image\/jpeg"}],"author":"Infoblox Threat Intel","twitter_card":"summary_large_image","twitter_title":"Expired Malicious Domains Bring New Threats to Life","twitter_description":"Dropcatch actors inherit traffic from compromised websites by acquiring expired malicious domains and redirecting victims to scams and malware.","twitter_misc":{"Written by":"Infoblox Threat Intel","Est. reading time":"26 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/#article","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/"},"author":{"name":"Infoblox Threat Intel","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae"},"headline":"Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows","datePublished":"2026-08-13T12:58:48+00:00","dateModified":"2026-08-13T13:01:54+00:00","mainEntityOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/"},"wordCount":5238,"publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-catch-part-3-thumbnail.jpeg","keywords":["dropcatch","DNS","expired domain","website malware","wordpress compromise","threat actor"],"articleSection":["Infoblox Threat Intel"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/","url":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/","name":"Expired Malicious Domains Bring New Threats to Life","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/#primaryimage"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-catch-part-3-thumbnail.jpeg","datePublished":"2026-08-13T12:58:48+00:00","dateModified":"2026-08-13T13:01:54+00:00","description":"Dropcatch actors inherit traffic from compromised websites by acquiring expired malicious domains and redirecting victims to scams and malware.","breadcrumb":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/#primaryimage","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-catch-part-3-thumbnail.jpeg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/drop-catch-part-3-thumbnail.jpeg","width":612,"height":408},{"@type":"BreadcrumbList","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/dropcatch-scavengers-expired-malicious-domains-become-cash-cows\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.infoblox.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Infoblox Threat Intel","item":"https:\/\/www.infoblox.com\/blog\/category\/threat-intelligence\/"},{"@type":"ListItem","position":3,"name":"Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows"}]},{"@type":"WebSite","@id":"https:\/\/www.infoblox.com\/blog\/#website","url":"https:\/\/www.infoblox.com\/blog\/","name":"infoblox.com\/blog\/","description":"","publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.infoblox.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.infoblox.com\/blog\/#organization","name":"Infoblox","url":"https:\/\/www.infoblox.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","width":137,"height":30,"caption":"Infoblox"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae","name":"Infoblox Threat Intel","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","url":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","contentUrl":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","caption":"Infoblox Threat Intel"},"description":"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.","url":"https:\/\/www.infoblox.com\/blog\/author\/infoblox-threat-intel\/"}]}},"_links":{"self":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/14000","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/users\/397"}],"replies":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/comments?post=14000"}],"version-history":[{"count":10,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/14000\/revisions"}],"predecessor-version":[{"id":14070,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/14000\/revisions\/14070"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media\/13996"}],"wp:attachment":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media?parent=14000"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/categories?post=14000"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/tags?post=14000"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}