Infoblox Threat Intel said it observed roughly 65,000 expired domains being re-registered each day during the first half of 2026, accounting for nearly 20 percent of all newly observed domains in its data.

The cybersecurity company’s research focused on so-called dropcatch domains, or domain names that are registered by a new owner after the previous registration expires. Such domains can retain backlinks, web traffic, and reputation associated with their previous owners, which can make them attractive to cybercriminals, Infoblox said.

One investigation identified an actor the researchers call Sable Squirrel, which Infoblox estimates spent more than $7 million acquiring over 10,000 expired domains. The company said the domains were used across infrastructure linked to illegal streaming, online gambling and malware distribution, including command-and-control infrastructure for remote access trojans.

Infoblox also described three other actors that acquired previously malicious domains which remained embedded in compromised websites. One of them, tracked by the company as Shady Squirrel, allegedly redirected victims toward SocGholish-related infrastructure after earlier using scareware and call-center tactics. The findings are based on Infoblox’s own threat-intelligence telemetry and analysis.

The research adds another dimension to the role of domain intelligence in security operations. A TNGlobal INSIDER article published in March examined how threat intelligence can provide context for suspicious domains and other indicators used in security operations centers.

Renée Burton, Vice President of Infoblox Threat Intel, said the volume of re-registered domains and the amounts some actors were willing to spend were greater than the researchers had expected. She said expired domains can provide a shortcut to existing traffic and reputation, making ownership changes an important risk signal for defenders to examine.

Infoblox published the findings as a three-part research series covering the broader dropcatch market, the Sable Squirrel investigation, and additional actors that acquire expired malicious domains.