About 65,000 expired domains are re-registered every day, and attackers are exploiting that churn to inherit reputation, residual traffic, and even email meant for the previous owner. Nearly one in five domains registered in the first half of 2026 had a prior life, Infoblox found.
The research tracks an actor called Sable Squirrel that has spent roughly $7M buying more than 10,000 expired domains. The domains power illegal sports streaming brands like Xoilac, Cakhia, and 90phut that steer users toward betting sites, while a subset double as command-and-control servers for Quasar RAT, AsyncRAT, DCRat, and Remcos RAT. Among its acquisitions are healthymagination.com, once a General Electric health initiative, and rezilion.com, a cybersecurity firm whose assets GitLab bought in 2024.
Three scavenger actors, Stuffy, Shady, and Swiping Squirrel, operate differently. They snap up expired domains that other attackers already compromised and inherit the existing infection traffic. Shady Squirrel, presumed Russian-speaking, points that inherited traffic at SocGholish and tech support fraud. Within days of law enforcement disrupting SocGholish, the scavenger had helped the fake-update campaign reclaim thousands of compromised sites.
Lingering DNS records also enable dangling CNAME hijacks, and 24% of Sable Squirrel’s domains go live the same day they are registered. The lesson for defenders: domain age and reputation are inputs worth questioning, not trusting.
