Infoblox Links Sable Squirrel’s $7M Expired-Domain Operation to Streaming, Gambling and Malware

· Original article ↗

Summary

Infoblox reports that Sable Squirrel uses more than 10,000 domains for illegal streaming, gambling promotion and malware command-and-control, including expired domains it estimates cost over $7 million.

Key points

  • Infoblox attributes more than 10,000 domains to Sable Squirrel and estimates the actor has spent over $7 million acquiring expired domains to inherit their history, traffic and reputation.
  • A subset of the same domains served streaming sites and malware C2; Infoblox identified 405 C2 domains and more than 31,000 connecting malware samples.
  • The samples include Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos and njRAT. Some carried HiddenTear ransomware signatures, but tested samples did not encrypt files, so ransomware execution was not confirmed.
  • Infoblox observed a coordinated C2 configuration wave in late 2025, with most of the 405 domains weaponized in December; the operator shifted from AsyncRAT to DCRat in March 2026.
  • The operation funnels streaming audiences toward gambling platforms and shares infrastructure across streaming, redirection, tracking and malware activity.
  • Vietnamese enforcement actions in February and March 2026—including site freezes, charges and asset seizures—briefly slowed registrations but did not stop the operation’s recovery and expansion.

Article Details

Attack Vectors
  • Sable Squirrel buys expired domains to inherit registration history, backlinks and residual traffic, then uses them for illegal streaming and, in some cases, malware C2.
  • The actor registers disposable lookalike domains for its streaming brands and sporting events.
  • Streaming sites route viewers through actor-controlled redirection and cloaking infrastructure to betting platforms; automated visitors and visitors outside the target audience can be sent to dead ends.
  • A subset of streaming domains simultaneously serve consumer-facing WordPress sites and act as malware C2.
  • ColaScore and VSBet apps are distributed through Google Play developer accounts that the researchers assess appear to be compromised.
  • In a separate incident, Balada Injector compromised a Sable Squirrel WordPress site and injected code redirecting viewers through its own traffic-distribution system.
  • Another Sable Squirrel domain hosted an investment scam targeting Russian-speaking users after an apparent takeover; the researchers describe registrar-account compromise as a possibility, not a confirmed cause.
Defensive Notes
  • Historical domain age and reputation are unreliable trust signals for these dropcatch domains: Sable Squirrel typically activates acquired domains within days.
  • A live streaming site does not rule out C2 activity on the same domain.
  • The researchers identified a distinctive DNS fingerprint on confirmed Sable Squirrel streaming domains configured as malware C2.

Indicators of compromise

TypeIndicatorContext
DOMAIN6789x[.]siteSable Squirrel-controlled redirection and cloaking domain routing viewers toward betting platforms.
DOMAIN90phutyy[.]ioListed by the researchers as a Sable Squirrel infrastructure-domain indicator.
DOMAINanimalrampage3d[.]ioListed by the researchers as a Sable Squirrel dropcatch-domain indicator.
DOMAINapi-score[.]comSable Squirrel-controlled service supplying live sports scores and odds to its streaming sites.
DOMAINbuffalomarket[.]comFormer distributor domain acquired by Sable Squirrel and repurposed for illegal sports streaming.
DOMAINcel-robox[.]comSable Squirrel dropcatch domain serving an illegal streaming site while configured as Quasar RAT C2.
DOMAINchatboxn[.]comLive-chat back-end domain used by Sable Squirrel streaming sites.
DOMAINcolascore[.]comDomain of a betting platform the researchers assess with high confidence Sable Squirrel owns or controls.
DOMAINcolatv88xb[.]ccSable Squirrel C2 and betting-tracker domain queried by nearly 70% of exposed customer networks in the researchers' set.
DOMAINgene-chips[.]comListed by the researchers as a Sable Squirrel dropcatch-domain indicator.
DOMAINgvapi[.]ccSable Squirrel-operated proxy content-delivery domain used across its streaming sites.
DOMAINhealthymagination[.]comExpired domain acquired by Sable Squirrel and repurposed for illegal sports streaming.
DOMAINimgts[.]comSable Squirrel-controlled server supplying images and page assets across its streaming brands.
DOMAINinstitutobancopalmas[.]orgFormer community-bank domain acquired by Sable Squirrel and repurposed for illegal sports streaming.
DOMAINjurasudfoot[.]comFormer football-club domain acquired by Sable Squirrel and repurposed for illegal sports streaming.
DOMAINkoepgd[.]appStreaming video-delivery server used by Sable Squirrel sites.
DOMAINkrogeralbertsons[.]comExpired domain acquired by Sable Squirrel and repurposed for illegal sports streaming.
DOMAINlfastcdn[.]comSable Squirrel-controlled server supplying images and page assets across its streaming brands.
DOMAINmaxfactor-international[.]comPreviously established domain acquired by Sable Squirrel and repurposed for illegal sports streaming.
DOMAINmeung[.]appStreaming video-delivery server used by Sable Squirrel sites.
DOMAINmsdht[.]appStreaming video-delivery server used by Sable Squirrel sites.
DOMAINmsrktz[.]appStreaming video-delivery server used by Sable Squirrel sites.
DOMAINrefvsb[.]comListed by the researchers as a Sable Squirrel infrastructure-domain indicator.
DOMAINrezilion[.]comFormer cybersecurity-company domain acquired by Sable Squirrel and repurposed for illegal sports streaming.
DOMAINsadd[.]ioListed by the researchers as a Sable Squirrel dropcatch-domain indicator.
DOMAINsamefacts[.]comFormer policy-blog domain acquired by Sable Squirrel and repurposed for illegal sports streaming.
DOMAINsnsystems[.]comFormer company domain acquired by Sable Squirrel and repurposed for illegal sports streaming.
DOMAINsocoliveku[.]ccListed by the researchers as a Sable Squirrel infrastructure-domain indicator.
DOMAINsportliveapiz[.]comSable Squirrel-controlled sports-data feed used by its streaming sites.
DOMAINstope40[.]orgListed by the researchers as a Sable Squirrel dropcatch-domain indicator.
DOMAINtrackervsb[.]liveListed by the researchers as a Sable Squirrel infrastructure-domain indicator.
DOMAINveinteractive[.]comFormer company domain acquired by Sable Squirrel for illegal sports streaming, inheriting residual traffic.
DOMAINvsbet276[.]comDomain of a betting platform the researchers assess with high confidence Sable Squirrel owns or controls.
DOMAINws-xyz[.]comLive-chat WebSocket service used by Sable Squirrel streaming sites.
DOMAINxemlaibongda[.]netSable Squirrel streaming site compromised by Balada Injector to redirect its viewers.
DOMAINxoilacxys[.]topSable Squirrel streaming lookalike that hosted an investment scam after an apparent takeover by another actor.
DOMAINxoilacz[.]comSable Squirrel streaming domain also visible in a Vietnamese enforcement photograph.
SHA2560464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216Hash listed under Quasar RAT Sample in the article's indicators.
URLhxxps[:]//bind[.]bestresulttostart[.]com/xf4mKQBalada Injector traffic-distribution URL receiving visitors redirected from a compromised streaming site.

MITRE ATT&CK

Threat Actors

Malware

AsyncRATWe identified over 31,000 malware samples connecting to Sable Squirrel domains, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, and samples carrying HiddenTear ransomware signatures.Balada InjectorIn one instance, the streaming site xemlaibongda[.]net was compromised by the Balada Injector, a mass WordPress-compromise operation that injects malicious code into vulnerable sites.DCRatWe identified over 31,000 malware samples connecting to Sable Squirrel domains, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, and samples carrying HiddenTear ransomware signatures.HiddenTearWe identified over 31,000 malware samples connecting to Sable Squirrel domains, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, and samples carrying HiddenTear ransomware signatures.NanoCoreWe identified over 31,000 malware samples connecting to Sable Squirrel domains, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, and samples carrying HiddenTear ransomware signatures.njRATWe identified over 31,000 malware samples connecting to Sable Squirrel domains, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, and samples carrying HiddenTear ransomware signatures.Quasar RATWe identified over 31,000 malware samples connecting to Sable Squirrel domains, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, and samples carrying HiddenTear ransomware signatures.Remcos RATWe identified over 31,000 malware samples connecting to Sable Squirrel domains, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, and samples carrying HiddenTear ransomware signatures.

Vendors

Products

Tools

Countries

Industries

Related Articles