Expired malicious domains let three actors redirect compromised-site visitors to scams and malware

Summary
Infoblox details three actors that acquire expired malicious domains still embedded in compromised websites, then route visitors to advertising, scams, or malware using cloaking and traffic-distribution systems.
Key points
- The actors acquire expired domains previously used in malicious infrastructure, inheriting traffic from lingering injections on compromised websites without compromising those sites themselves.
- Infoblox identified more than 500 domains linked to Stuffy Squirrel, over 700 to Shady Squirrel, and over 3,000 to Swiping Squirrel.
- Stuffy Squirrel hides payloads behind URL-specific server checks and user-click requirements, then routes visitors through popunder advertising systems.
- Shady Squirrel uses referral filters, fingerprinting, and cloaking to send selected visitors to gambling, tech-support scams, or SocGholish fake updates; it also uses two-part Keitaro injection chains.
- About 10 days after Operation Endgame disrupted SocGholish infrastructure in June 2026, Shady Squirrel was routing traffic from compromised sites to SocGholish again.
- Swiping Squirrel sells fingerprinted visitor traffic through advertising brokers, where downstream destinations can include scams, malware, or legitimate shopping pages.
- Infoblox says the observed tech-support scam activity went silent by early July 2026 and provides actor-associated domain indicators in a GitHub repository.
Article Details
- Attack Vectors
- Acquiring expired malicious domains to inherit traffic from JavaScript references left on previously compromised websites.
- Embedding malicious JavaScript inside an otherwise legitimate Raphaël.js file and dynamically loading additional actor-controlled scripts.
- Using referrer checks, browser fingerprinting, server-side cloaking, and user-interaction requirements to selectively expose malicious redirects.
- Injecting scripts into legitimate website theme files; the researchers could not determine whether Shady Squirrel performed the compromises directly or used affiliates.
- Hijacking a formerly legitimate domain used for cookie consent to obtain traffic through an existing supply-chain dependency.
- Routing search-engine visitors to browser-lock tech support scams targeting Windows users in Japan and the United States.
- Delivering SocGholish fake updates through inherited website compromises.
- Using two-part Keitaro injections to redirect visitors or inject HTML, including a historical chain leading to Help TDS.
- Selling inherited visitor traffic through advertising intermediaries, with observed downstream delivery of a ClickFix fake CAPTCHA.
- Defensive Notes
- Directly probing the actors' domains may return legitimate decoys, original pages, or errors rather than the malicious scripts served through embedded website URLs.
- Automated analysis without user interaction can miss Stuffy Squirrel's popunder delivery, even when its malicious script executes.
- Shady Squirrel's routing depends on referral information and additional cloaking checks; most visits do not expose the final payload.
- Expired malicious domains can remain dangerous because compromised websites continue requesting their resources after ownership changes.
- The researchers reported Swiping Squirrel and AdventureFeeds activity to Team Internet.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | ads-analytic[.]com | Keitaro server that returned JavaScript redirecting visitors to Help TDS and affiliate advertising infrastructure. |
| DOMAIN | advanceslibrary[.]com | Shady Squirrel domain registered on June 27, 2026, likely specifically for SocGholish; associated fake-update delivery was confirmed on July 10. |
| DOMAIN | blacksaltys[.]com | Shady Squirrel dropcatch domain formerly operated by TA2726. |
| DOMAIN | blackshelter[.]org | Listed as a Swiping Squirrel dropcatch domain. |
| DOMAIN | blocksovetnik[.]ru | Listed as a Stuffy Squirrel dropcatch domain. |
| DOMAIN | bluegaslamp[.]org | Listed as a Swiping Squirrel dropcatch domain. |
| DOMAIN | brodirect3s[.]site | Shady Squirrel dropcatch domain formerly used by a commercial push notification service. |
| DOMAIN | cdnjslibraries[.]com | Shady Squirrel dropcatch domain used for Keitaro delivery and subsequently for its custom injection. |
| DOMAIN | checkoutbump[.]com | Listed as a Stuffy Squirrel dropcatch domain. |
| DOMAIN | draggedline[.]org | Listed as a Swiping Squirrel dropcatch domain. |
| DOMAIN | getshopstar[.]com | Listed as a Swiping Squirrel dropcatch domain. |
| DOMAIN | gsstats[.]ru | Stuffy Squirrel's primary popunder delivery entry point since November 2025. |
| DOMAIN | hpmdnetwork[.]ru | Listed as a Stuffy Squirrel dropcatch domain. |
| DOMAIN | imhd[.]io | Formerly legitimate CDN domain acquired for Shady Squirrel infrastructure. |
| DOMAIN | jqueryapihelpers[.]com | Listed as a Swiping Squirrel dropcatch domain. |
| DOMAIN | lzdatheme[.]com | Listed as a Swiping Squirrel dropcatch domain. |
| DOMAIN | magesource[.]su | Stuffy Squirrel script infrastructure previously used for Magecart payment-card skimming on compromised Magento stores. |
| DOMAIN | memtkh[.]com | Listed as a Stuffy Squirrel dropcatch domain. |
| DOMAIN | pausewatchings[.]com | Shady Squirrel dropcatch domain observed sending traffic to ProPush in mid-July 2026. |
| DOMAIN | pills-europe[.]com | Shady Squirrel dropcatch domain observed sending traffic to ProPush in mid-July 2026. |
| DOMAIN | renpaste[.]top | Tech support scam infrastructure supplying call-center phone numbers to scam pages. |
| DOMAIN | renteres[.]ru | Listed as a Stuffy Squirrel dropcatch domain. |
| DOMAIN | simplejscdn[.]com | Shady Squirrel dropcatch domain formerly used by an affiliate of a commercial push notification service. |
| DOMAIN | slurpslimes[.]org | Listed as a Swiping Squirrel dropcatch domain. |
| DOMAIN | sport2news[.]com | Served JavaScript that established a two-part Keitaro chain leading to Help TDS in a historical sample. |
| DOMAIN | tofuturepubs[.]com | Stuffy Squirrel popunder delivery entry point used during 2024 and 2025. |
| DOMAIN | weatherplllatform[.]com | Stuffy Squirrel script infrastructure previously used by Balada to infect thousands of WordPress sites. |
| DOMAIN | webpixel[.]app | Listed as a Swiping Squirrel dropcatch domain. |
| DOMAIN | wesq[.]me | Shady Squirrel dropcatch domain formerly used by a commercial push notification service affiliate. |
| DOMAIN | windowlight[.]org | Listed as a Swiping Squirrel dropcatch domain. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe article describes obfuscated injection scripts, including Shady Squirrel's two-part Keitaro loader.T1036 · MasqueradingStuffy Squirrel inserts malicious JavaScript into a file that retains the appearance and filename of the legitimate Raphaël.js library.T1059.007 · JavaScriptThe actors execute browser-side JavaScript loaders, fingerprinting scripts, and injection chains to control visitor routing.T1189 · Drive-by CompromiseVisitors to compromised websites encounter injected JavaScript that routes them to scams, malicious advertising, or SocGholish fake updates.T1219 · Remote Access ToolsThe article describes tech support scam call centers convincing victims to install remote access tools that give the operators control of their machines.T1497.001 · System ChecksShady Squirrel and Swiping Squirrel use fingerprinting and bot checks to withhold malicious behavior from scanners; tech support redirects also check for Windows.T1497.002 · User Activity Based ChecksStuffy Squirrel requires a real user click before opening popunder windows, preventing automated script execution alone from exposing downstream delivery.T1583.001 · DomainsThe three Squirrel actors acquire expired domains to reactivate references on compromised websites; Shady Squirrel also registers new domains.
People
Threat Actors
ClearFakeNamed as a threat actor using compromised websites to steal credentials and sell them for further exploitation.master134Named as a notorious malvertiser with previously reported connections to AdventureFeeds.Shady SquirrelRussian-speaking dropcatch operator active since at least July 2023, with over 700 identified acquired domains; routes traffic to gambling, tech support scams, SocGholish, and Keitaro infrastructure.SocGholishDescribed as a fake-update threat actor receiving traffic from Shady Squirrel after the June 2026 Operation Endgame disruption.Stuffy SquirrelTracked dropcatch operator active since at least 2020, controlling over 500 identified domains and hiding traffic-distribution scripts inside legitimate JavaScript.Swiping SquirrelTracked operator with over 3,000 identified domains acquired since 2022; fingerprints and cloaks inherited website traffic before selling it through affiliate advertising platforms.TA2726Previous operator of malicious domains subsequently acquired by the Squirrel actors; also associated with the cookie values observed in Keitaro injection chains.
Malware
BaladaThe infrastructure consists almost entirely of dropped domains that once served malicious infrastructure for various actors, including TA2726, and actors running Magecart and Balada injection campaigns.SocGholishSome of the most pernicious threat actors, like SocGholish and ClearFake, use these sites to steal user credentials and sell them to others for further exploitation.
Vendors
AdventureFeedsWe experienced a ClickFix attack this way: our click was sold by ZeroPark to AdventureFeeds, who in turn displayed the fake captcha, presumably through one of their own advertisers.ExoClickPhase I: PushHouse and ExoClickPropeller AdsIn this instance, Shady Squirrel kicked off three events and one is a redirection to Propeller Ads’ push monetization service, ProPush.PushHousePhase I: PushHouse and ExoClickTeam InternetAccording to our observations, Swiping Squirrel sells most of their traffic to Team Internet’s ZeroPark.
Products
1WinIn 2026, they sent traffic to four downstream actors: a Russian gambling platform called 1Win; a tech support scam actor; the original fake update actor, SocGholish; and a Keitaro server.AliExpressThey also appear to be enrolled in an affiliate program for AliExpress and a handful of other commerce entities.MagentoThe domain magesource[.]su was previously used as a Magecart card-skimming domain targeting compromised Magento stores to steal payment card data.Microsoft AzureBefore that, the thief abused Microsoft Azure static webhosting to serve lures, creating nearly 10k accounts a month across at least nine regions globally.Microsoft WindowsThis is due to a third layer of evasion that sits beyond both server-side checks: the popunder windows only open on a real user click.ProPushIn this instance, Shady Squirrel kicked off three events and one is a redirection to Propeller Ads’ push monetization service, ProPush.WordPressThe domain weatherplllatform[.]com was previously used as Balada injector infrastructure, infecting thousands of WordPress sites during the campaign’s peak and was Sucuri’s second most-blocklisted resource in 2022.ZeroParkAccording to our observations, Swiping Squirrel sells most of their traffic to Team Internet’s ZeroPark.
Tools
BinomIt also incorporated a Binom tracker check.Help TDSResearch led to several discoveries, including a tech support actor, a previously unpublished two-part Keitaro injection chain, and an unusual Help TDS infection vectorKeitaroResearch led to several discoveries, including a tech support actor, a previously unpublished two-part Keitaro injection chain, and an unusual Help TDS infection vector
Countries
Industries
adult contentThese platforms operate in several verticals but are dominated by adult content.affiliate advertisingThey sell traffic to specific affiliate advertising networks.E-commerceOther verticals we’ve seen include e-commerce affiliate fraud and online gambling.online gamblingOther verticals we’ve seen include e-commerce affiliate fraud and online gambling.