Malik Haidar is a veteran in the cybersecurity trenches, a man whose career has been defined by bridging the gap between high-level business strategy and the gritty reality of threat intelligence. Having spent years securing some of the world’s largest multinational corporations, Malik has witnessed the evolution of cybercrime from disorganized skirmishes to the highly industrialized operations we see today. His perspective is unique; he doesn’t just see code and servers, but rather the economic engines that drive criminal enterprises. We sat down with him to discuss a particularly insidious trend currently reshaping the threat landscape: the weaponization of expired domains. This conversation delves into how threat actors are spending millions of dollars to “launder” their reputations through the digital ghosts of defunct brands and projects, creating a massive security blind spot that traditional defenses are struggling to address.
Roughly 65,000 expired domains are re-registered daily, often inheriting years of established reputation and traffic. How is this “drop catching” phenomenon fundamentally changing the way threat actors approach infrastructure building compared to just registering new names?
In the past, a hacker would register a brand-new domain, but that came with a “newborn” status that modern security filters could easily flag. Now, we are seeing a massive shift toward “reputation laundering.” During the first half of 2026, we’ve tracked about 50,400 of these “dropcatch” domains being snapped up every single day in the generic top-level domains like .com alone. When you factor in the country code domains, that number climbs to 65,000, which means one out of every five new domain registrations is actually a re-birth of an old one. For a threat actor, this is like buying a vintage car that already has its registration and insurance paid for—it looks legitimate the moment it hits the road. They aren’t just buying a name; they are buying a head start with cached search results and lingering DNS records that allow them to bypass reputation-based algorithms that many security products still rely on too heavily.
The financial investment in these domains is staggering, with some groups spending millions to secure their infrastructure. What does the sheer scale of these operations, specifically groups like Sable Squirrel, tell us about the professionalization of these criminal enterprises?
It tells us that we are no longer dealing with hobbyists; these are sophisticated business operations with massive capital. We’ve seen the group we call Sable Squirrel pour nearly $7 million into acquiring expired domains to build an empire of illegal streaming, gambling, and malware. That kind of budget allows them to hoard over 10,000 domains, creating a backbone for piracy operations like Xoilac and 90phut. They aren’t just throwing darts at a board; they are using this money to buy aged registration history and residual traffic that keeps fans coming back to their platforms. It is a dual-track model where they use expired domains for legitimacy and freshly registered lookalikes to run the actual streaming fleet, creating a resilient, multi-layered criminal network that is incredibly hard to dismantle.
When these domains are re-registered, the speed of weaponization is remarkably fast. Can you walk us through the timeline of how a domain goes from an auction to hosting malicious activity?
The efficiency is actually quite terrifying because it shows how automated these workflows have become. Once a domain is secured, we see 24% of them go live with malicious content on the very same day. By the end of the first week, 76% are active, and within two weeks, 94% of these domains are fully weaponized. This isn’t a manual process; these actors use advanced computer algorithms to detect the precise millisecond a domain becomes available, issuing hundreds of consecutive purchase attempts. They are in a race to capitalize on the “residual trust” left by the previous owner before the security community catches on. They wire these domains into redirection chains almost immediately, ensuring that every drop of traffic the domain still attracts is funneled toward a scam or a malware payload.
You mentioned that these domains often come with “lingering connections.” What specific types of residual data or traffic are hackers most interested in when they target a high-value expired domain?
They are looking for the “digital residue” that lingers long after a company has moved on or shut down. This includes everything from emails intended for the original holder to inbound traffic from old backlinks that are still active across the web. Most importantly, they look for compromised sites that might still have code injection points pointing back to that specific domain. We have seen cases where threat actors like the “Scavengers” don’t even bother compromising new sites; they simply take over an expired domain that was previously used in an infection chain. They effectively inherit a pre-built victim pool. It’s a parasitic relationship where they feed off the work of the hackers who came before them, redirecting visitors to new scams or malware like SocGholish based on the visitor’s location and browser characteristics.
Some of the domains being hijacked belonged to major brands or significant corporate initiatives, such as healthymagination.com or rezilion.com. How does the “ghost” of a legitimate brand name make these attacks more effective against unsuspecting users?
It provides a level of psychological cover that is hard to beat. When a user sees a domain like “healthymagination.com,” which was a legitimate General Electric initiative launched back in 2009, there is an inherent level of trust. The same goes for “maxfactor-international.com” or the “krogeralbertsons.com” domain that was tied to a massive proposed merger. These domains carry the weight of established brands, making them the perfect hosts for C2 servers for things like Quasar RAT. Because these names were once tied to legitimate corporate entities, they are less likely to trigger red flags for users or even some IT professionals. It allows the threat actor to operate in a “gray zone” where their infrastructure looks like a forgotten piece of corporate history rather than a front for a malware operation.
The role of “Scavengers” like Stuffy, Shady, and Swiping Squirrel seems to represent a different tier of the ecosystem. How do these groups profit from the “leftovers” of other hackers’ work without having to perform the initial breaches themselves?
These “Scavengers” are the ultimate opportunists of the cyber world. Instead of the high-effort task of breaking into servers, they simply monitor the registries for domains that were already part of a malware ecosystem. For instance, Swiping Squirrel controls over 3,000 domains and focuses purely on redirecting that inherited traffic to zero-click advertising platforms. They don’t even distribute the malware themselves; they just monetize the flow of victims. On the other hand, Shady Squirrel, which is Russian-speaking and manages about 700 domains, acts as a middleman, sending traffic to initial access brokers. They are essentially recycling the infrastructure of past crimes, ensuring that once a site is compromised, it stays dangerous for years, even after the original attacker has vanished.
With the rise of redirection and cloaking chains, such as the ones used to hide betting pages, how difficult has it become for security researchers to map out the full extent of these operations?
It has become a high-stakes game of cat and mouse. These actors use domains like “6789x.site” as gatekeepers. If a bot or a security researcher from a known IP range hits the site, they are sent to a dead end—a harmless-looking page. But if a real user from a targeted region like Vietnam or South Korea clicks, they are routed through a traffic distribution system to the actual illicit content. This selective redirection makes it incredibly difficult to see the “whole elephant.” We’ve found over 31,000 malware samples, including Remcos RAT and HiddenTear ransomware, that are communicating with this infrastructure, but often they are hidden behind layers of legitimate-looking streaming content. You might be watching a football game on one of these sites, while in the background, your device is silently communicating with a command-and-control server.
What is your forecast for the evolution of reputation-based security in light of these industrialized domain-recycling tactics?
The traditional “set it and forget it” approach to domain reputation is effectively dead. We can no longer assume that a domain is safe just because it was registered ten years ago or because it belonged to a Fortune 500 company in 2024. Moving forward, security systems will have to become much more “temporal”—they need to track not just who a domain was, but who it became the moment it changed hands. We will see a shift toward analyzing the “behavioral delta” of a domain immediately after a re-registration event. If a domain that was a health blog for a decade suddenly starts pushing Android apps and communicating with known RAT signatures within 24 hours, its historical reputation must be discarded instantly. The battleground is shifting from the name on the domain to the intent of the current owner, and our defenses must become as agile as the “Drop” algorithms the criminals are using.

