Find notable cyber news and cases, enriched with sources, timelines, and signals.

Sable Squirrel expired-domain redirection and cloaking campaign

Campaign
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

The Sable Squirrel campaign is using expired domains, social platforms, and a traffic distribution system (TDS) to redirect users in Vietnam, South Korea, Japan, Taiwan, Singapore, and Australia to illicit sports streaming and betting sites, widening the operation’s reach across multiple markets. The actor has spent nearly $7 million on the domain portfolio and controls more than 10,000 domains to keep the traffic pipeline moving. The same infrastructure is also tied to malware command-and-control (C2), increasing the risk that users and scanners encounter both fraud and malware services. Many of the repurposed domains are weaponized quickly, often within two weeks of re-registration.

Related Happenings

Lurking Lizard trojanized 7-Zip installer campaign

Campaign
H score84 First: 09.07.2026 07:01 Last: 09.07.2026 07:01 Sources 1

About this happening: A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...

Lurking Lizard ecosystem shift changes threat-actor operations

Threat Actor Meta
H score87 First: 09.07.2026 07:01 Last: 09.07.2026 07:01 Sources 1

About this happening: The Lurking Lizard operation has been exposed as a multi-stage residential proxy business, turning compromised devices into monetizable proxy nodes and widening unauthoriz...

DCloud Uni-App scam website campaign

Campaign
H score70 First: 29.06.2026 14:57 Last: 29.06.2026 14:57 Sources 1

About this happening: The DCloud Uni-App scam-site campaign has grown into a 236,493-domain fraud network that steals credentials, drains crypto wallets, and impersonates major brands. The site...

Broad Keitaro TDS abuse across more than 120 campaigns

Trend
H score33 First: 27.04.2026 09:33 Last: 27.04.2026 09:33 Sources 1

About this happening: Keitaro TDS was abused by more than 120 distinct campaigns between October 2025 and January 2026, showing a broad recurring pattern of malicious link delivery and spam...

Timeline

  1. 14.08.2026 21:48 2 articles · 2d ago

    Sable Squirrel uses expired domains to redirect traffic to streaming, gambling, and malware

    Initial Disclosure

    Infoblox reported that Sable Squirrel is acquiring expired dropcatch domains to inherit traffic and reputation, then using the repurposed infrastructure to send users to illegal sports streaming, online gambling promotion, and malware services. The analysis says the group has spent nearly $7 million on expired domains, controls more than 10,000 domains, and uses a redirection and cloaking chain to reach users in Vietnam, South Korea, Japan, Taiwan, Singapore, and Australia; some repurposed domains also serve as malware command-and-control while still hosting live streaming content.

    Show sources