Attackers Use Expired Websites for Malware Scams


Dead websites may seem harmless once they are abandoned by their owners, but their old internet reputation can make them important tools for threat actors. A new research by Infoblox Threat Intel has revealed that threat actors are spending millions of dollars buying expired domain names and misusing them for online gambling, malware, scams, and illegal streaming.

Infoblox discovered that around 65,000 earlier previously registered domains are re-registered everyday, showing around one in five newly found domains,

What makes dead domains valuable

When a domain is dead, the history does not vanish immediately. The domain may still consist of traffic, backlinks, search-engine visibility, and an image built when it was in legitimate use previously.

Attackers can buy these domains and exploit the existing digital footprint. This can make a malicious infrastructure less dangerous than an entirely new domain. 

The tactic is usually called “dropcatchin”. Instead of making new sites from scratch, threat actors buy domains that have already created some level of visibility and trust.

Sable Squirrel behind the campaign

One of the largest campaigns detected by Infoblox is an attacker called Sable Squirrel. According to experts, the group has control over 10,000 domains and believe that it has invested over $7 million buying expired domains. 

“This actor has spent years turning other people’s domain history into its own criminal infrastructure, then using that infrastructure to run illegal sports streaming, online gambling promotion, and malware command-and-control (C2) side by side,” Infoblox said. 

Majority of the domains support a large gambling operation and sports streaming aimed mostly at Asian users, But experts found that some of the same infrastructure was utilised for command and control (C2) operations. 

Infoblox found over 31000 malware samples interacting with Sable Squirrel infrastructure such as njRAT, Remcos, NanoCore, DCRat, AsnycRAT, and Quasar RAT additionally with samples linked to HiddenTear ransomware. Experts confirmed 405 domains being exploited as malware command-and-control infrastructure. 

A larger cybercrime picture

Sable Squirrel was not the only group using dead domains, Infoblox also detected groups such as Swiping Squirrel, Shady Squirrel and Stuffy Squirrel. Some groups buy domains previously associated with malicious activity and exploit the existing traffic to redirect targets towards malware, advertising fraud, or scams.

Sable Squirrel’s main business is gambling, but it masks it as a streaming operation, while also doubling as an acquisition channel for the same.

“In Sable Squirrel’s hands, the domain becomes more than an address. It is the unit of trust, the traffic source, the brand surface, the routing layer, and, in some cases, the control channel,” said Infoblox.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: