Expired malicious domains let three actors redirect compromised-site visitors to scams and malware

· Original article ↗

Summary

Infoblox details three actors that acquire expired malicious domains still embedded in compromised websites, then route visitors to advertising, scams, or malware using cloaking and traffic-distribution systems.

Key points

  • The actors acquire expired domains previously used in malicious infrastructure, inheriting traffic from lingering injections on compromised websites without compromising those sites themselves.
  • Infoblox identified more than 500 domains linked to Stuffy Squirrel, over 700 to Shady Squirrel, and over 3,000 to Swiping Squirrel.
  • Stuffy Squirrel hides payloads behind URL-specific server checks and user-click requirements, then routes visitors through popunder advertising systems.
  • Shady Squirrel uses referral filters, fingerprinting, and cloaking to send selected visitors to gambling, tech-support scams, or SocGholish fake updates; it also uses two-part Keitaro injection chains.
  • About 10 days after Operation Endgame disrupted SocGholish infrastructure in June 2026, Shady Squirrel was routing traffic from compromised sites to SocGholish again.
  • Swiping Squirrel sells fingerprinted visitor traffic through advertising brokers, where downstream destinations can include scams, malware, or legitimate shopping pages.
  • Infoblox says the observed tech-support scam activity went silent by early July 2026 and provides actor-associated domain indicators in a GitHub repository.

Article Details

Attack Vectors
  • Acquiring expired malicious domains to inherit traffic from JavaScript references left on previously compromised websites.
  • Embedding malicious JavaScript inside an otherwise legitimate Raphaël.js file and dynamically loading additional actor-controlled scripts.
  • Using referrer checks, browser fingerprinting, server-side cloaking, and user-interaction requirements to selectively expose malicious redirects.
  • Injecting scripts into legitimate website theme files; the researchers could not determine whether Shady Squirrel performed the compromises directly or used affiliates.
  • Hijacking a formerly legitimate domain used for cookie consent to obtain traffic through an existing supply-chain dependency.
  • Routing search-engine visitors to browser-lock tech support scams targeting Windows users in Japan and the United States.
  • Delivering SocGholish fake updates through inherited website compromises.
  • Using two-part Keitaro injections to redirect visitors or inject HTML, including a historical chain leading to Help TDS.
  • Selling inherited visitor traffic through advertising intermediaries, with observed downstream delivery of a ClickFix fake CAPTCHA.
Defensive Notes
  • Directly probing the actors' domains may return legitimate decoys, original pages, or errors rather than the malicious scripts served through embedded website URLs.
  • Automated analysis without user interaction can miss Stuffy Squirrel's popunder delivery, even when its malicious script executes.
  • Shady Squirrel's routing depends on referral information and additional cloaking checks; most visits do not expose the final payload.
  • Expired malicious domains can remain dangerous because compromised websites continue requesting their resources after ownership changes.
  • The researchers reported Swiping Squirrel and AdventureFeeds activity to Team Internet.

Indicators of compromise

TypeIndicatorContext
DOMAINads-analytic[.]comKeitaro server that returned JavaScript redirecting visitors to Help TDS and affiliate advertising infrastructure.
DOMAINadvanceslibrary[.]comShady Squirrel domain registered on June 27, 2026, likely specifically for SocGholish; associated fake-update delivery was confirmed on July 10.
DOMAINblacksaltys[.]comShady Squirrel dropcatch domain formerly operated by TA2726.
DOMAINblackshelter[.]orgListed as a Swiping Squirrel dropcatch domain.
DOMAINblocksovetnik[.]ruListed as a Stuffy Squirrel dropcatch domain.
DOMAINbluegaslamp[.]orgListed as a Swiping Squirrel dropcatch domain.
DOMAINbrodirect3s[.]siteShady Squirrel dropcatch domain formerly used by a commercial push notification service.
DOMAINcdnjslibraries[.]comShady Squirrel dropcatch domain used for Keitaro delivery and subsequently for its custom injection.
DOMAINcheckoutbump[.]comListed as a Stuffy Squirrel dropcatch domain.
DOMAINdraggedline[.]orgListed as a Swiping Squirrel dropcatch domain.
DOMAINgetshopstar[.]comListed as a Swiping Squirrel dropcatch domain.
DOMAINgsstats[.]ruStuffy Squirrel's primary popunder delivery entry point since November 2025.
DOMAINhpmdnetwork[.]ruListed as a Stuffy Squirrel dropcatch domain.
DOMAINimhd[.]ioFormerly legitimate CDN domain acquired for Shady Squirrel infrastructure.
DOMAINjqueryapihelpers[.]comListed as a Swiping Squirrel dropcatch domain.
DOMAINlzdatheme[.]comListed as a Swiping Squirrel dropcatch domain.
DOMAINmagesource[.]suStuffy Squirrel script infrastructure previously used for Magecart payment-card skimming on compromised Magento stores.
DOMAINmemtkh[.]comListed as a Stuffy Squirrel dropcatch domain.
DOMAINpausewatchings[.]comShady Squirrel dropcatch domain observed sending traffic to ProPush in mid-July 2026.
DOMAINpills-europe[.]comShady Squirrel dropcatch domain observed sending traffic to ProPush in mid-July 2026.
DOMAINrenpaste[.]topTech support scam infrastructure supplying call-center phone numbers to scam pages.
DOMAINrenteres[.]ruListed as a Stuffy Squirrel dropcatch domain.
DOMAINsimplejscdn[.]comShady Squirrel dropcatch domain formerly used by an affiliate of a commercial push notification service.
DOMAINslurpslimes[.]orgListed as a Swiping Squirrel dropcatch domain.
DOMAINsport2news[.]comServed JavaScript that established a two-part Keitaro chain leading to Help TDS in a historical sample.
DOMAINtofuturepubs[.]comStuffy Squirrel popunder delivery entry point used during 2024 and 2025.
DOMAINweatherplllatform[.]comStuffy Squirrel script infrastructure previously used by Balada to infect thousands of WordPress sites.
DOMAINwebpixel[.]appListed as a Swiping Squirrel dropcatch domain.
DOMAINwesq[.]meShady Squirrel dropcatch domain formerly used by a commercial push notification service affiliate.
DOMAINwindowlight[.]orgListed as a Swiping Squirrel dropcatch domain.

MITRE ATT&CK

People

Threat Actors

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles