home.social

#dropcatch — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #dropcatch, aggregated by home.social.

  1. Three actors. Zero sites compromised. Thousands of victims inherited.

    In the third installment of our dropcatch series, we introduce three new opportunistic scavengers: actors who don't hack websites, but dropcatch the domains previous attackers left embedded in tens of thousands of compromised sites to redirect the inherited traffic to their own operations. We call these actors Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel.

    Most notably, in collaboration with @rmceoin, we discovered Shady Squirrel began using their catalogue of dropcatch domains to send traffic to SocGholish shortly after Operation Endgame's disruption of the actor in June.

    ⛔️ Sample IOCs:
    Stuffy Squirrel: gsstats[.]ru, weatherplllatform[.]com
    Shady Squirrel: advanceslibrary[.]com, blacksaltys[.]com
    Swiping Squirrel: blackshelter[.]org, jqueryapihelpers[.]com

    Full indicators on GitHub. infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #phishing

  2. 💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.

    Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.

    We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.

    Read the full teardown here: infoblox.com/blog/threat-intel

    Some Sable Squirrel dropcatch domains:

    thebreastcancercharities[.]org
    andromda[.]org
    d-rev[.]org
    churchofreality[.]org
    swradioafrica[.]com
    americansecuritytoday[.]com
    2026worldcupnorthamerica[.]com
    poweredbyclear[.]com
    fora[.]tv

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink

  3. Having trouble finding a free 📺 streaming site for World Cup 🏟️ matches? This threat actor has you covered with thousands of websites for all 104 matches! ⚽

    We've been tracking a likely Vietnam-based actor that mass purchases expired domains (we call these dropcatch) and repurposes their existing web traffic to funnel visitors into illegal sports streaming sites, and then straight into a betting platform the same actor operates. The domain portfolio is a graveyard of real internet history: 2026worldcupnorthamerica[.]com (once cited by the Dallas Morning News and the US Men's National Team Facebook fan page), childreninachangingclimate[.]org (formerly a children's aid program), thebreastcancercharities[.]org (formerly non-profit The Breast Cancer Charities of America), and a domain officially used by major US grocery store chains involved in a large proposed merger. Collectively, this actor has spent hundreds of thousands of dollars acquiring dropcatch domains alone — a strong signal that dropcatching is a genuinely effective vehicle for cyber fraud. Behind all of it sits a staggering tech stack operated by a single actor: 5,000+ domains, illegal streaming services, CDNs, TDSs, trackers, cloakers, betting platforms, and mobile apps. That's not a side hustle, that's an enterprise. 🏗️

    While the platform largely targets Vietnamese-speaking users, as well as others in Asia and Oceania, the financial damage reaches much further. Sports authorities and broadcasters worldwide are 📉 losing revenue every time someone watches a live NBA 🏀 , MLB ⚾ :, esports 🎮 , poker 🃏 , or World Cup 🏆 match for free on one of these sites, and this actor has all of them covered.

    Some examples from the domains we've uncovered so far:

    :Dropcatch domains host or redirect to illegal streaming services

    autoredistrict[.]org
    childreninachangingclimate[.]org
    2026worldcupnorthamerica[.]com
    folsomprisonmuseum[.]org
    allaboutbasketball[.]us
    thebreastcancercharities[.]org

    :Fraudulent domains host or redirect to illegal streaming services

    90phutaa[.]cc
    90phutab[.]cc
    90phutac[.]cc
    xoilaczzzzw[.]tv
    xoilaczzzzt[.]tv
    xoilaczzzzh[.]tv

    :Lookalike domains used by the betting platforms

    fifa001[.]com
    fifa002[.]com
    fifa02[.]com
    worldcup00[.]com
    worldcup000[.]com
    worldcup02[.]com

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #malvertising #illegalstreaming #sportsbetting #domainabuse #vietnam #worldcup #asia #fifa #streaming #betting #2026worldcup #charities #nonprofit #lookalike #xoilac #90phut