ZeroHour

Search: “infoblox”

158 stories

Low-quality casino sites conceal highly dangerous threat actors

Infoblox reveals China-aligned APT groups hiding PeckBirdy malware C2 domains inside roughly 1.7 million Chinese-language illegal casino websites.

An Infoblox report says it tracks about 1.7 million Chinese-language casino sites enabling illegal gambling, some of which double as command-and-control infrastructure. China-aligned APT groups have hidden PeckBirdy framework C2 domains inside these low-quality casino sites since 2023, injecting scripts that display fake software update pages to deliver malware. Over 3 percent of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain, and some sites rely on US cloud providers via 'infrastructure laundering.' Infoblox urges defenders not to dismiss casino-domain alerts as mere employee browsing violations.

The Register · Security · 3h agoThreat actor in the wild

Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware

Infoblox reports Sable Squirrel spent nearly $7 million on expired domains to redirect traffic to illegal sports streaming, gambling, and malware infrastructure.

Infoblox tracked 50,400 dropcatch domains re-registered daily in gTLDs during H1 2026, nearly 20% of all registrations, with .net and .xyz leading. The threat actor Sable Squirrel has acquired more than 10,000 expired domains supporting Asian sports piracy brands such as Xoilac, Cakhia, 90phut, Socolive, and MiTom while promoting betting services like VSBet, ColaScore, and 8xbet. The operation, assessed as Vietnam-based and overlapping the dismantled Xoi Lac TV streaming network, targets users in Vietnam, South Korea, Japan, Taiwan, Singapore, and Australia via a traffic distribution system, publishes Android apps through suspected compromised Google Play developer accounts, and deployed over 31,000 malware samples including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, and njRAT.

The Hacker News · 7d agoThreat actor in the wild

Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware

Infoblox finds dropcatch expired domains fuel malware delivery and C2, with actor Sable Squirrel spending ~$7M on 10,000+ domains.

Infoblox Threat Intel reports that in H1 2026 dropcatch (re-registered expired) domains made up nearly 20% of all new registrations, about 65,000 per day, inheriting reputation and traffic that attackers exploit. Threat actor Sable Squirrel spent nearly $7 million on 10,000+ expired domains, running Vietnamese, Korean, Japanese and Australian streaming platforms (Xoilac, Cakhia, 90phut) that double as C2 servers for Quasar RAT, AsyncRAT, DCRat and Remcos RAT. Scavenger actors like Shady Squirrel acquire previously compromised domains and feed inherited traffic to SocGholish and tech support scam networks.

Security Affairs · Aug 16, 2026Threat actor