Sable Squirrel is a well-funded domain-hoarding cybercriminal enterprise that uses expired domains and lookalike registrations to run illegal sports streaming, gambling promotion, and malware command-and-control on the same infrastructure. The operation spans more than 10,000 domains, has spent millions on dropcatch acquisitions, and has been tied to Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, HiddenTear, Xoi Lac TV, VSBet, ColaScore, and 8xbet. #XoiLacTV #VSBet #ColaScore #QuasarRAT #AsyncRAT #DCRat #NanoCore #Remcos #njRAT #HiddenTear
Keypoints
- Sable Squirrel controls more than 10,000 domains and uses them for illegal sports streaming, gambling promotion, traffic redirection, and malware C2.
- The actor relies on two domain acquisition methods: cheap lookalike registrations and expensive dropcatch purchases of expired domains with aged reputation and backlinks.
- Investigators confirmed more than $430,000 in individually priced dropcatch purchases and estimate total dropcatch spending at over $7 million.
- A subset of streaming domains also functioned as malware command-and-control, with over 31,000 malware samples connecting to Sable Squirrel infrastructure.
- Observed malware families include Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, and samples with HiddenTear ransomware signatures.
- The operation overlaps strongly with the Vietnamese Xoi Lac TV network and recovered quickly after early-2026 enforcement actions.
- Vietnamese streaming brands feed users into betting platforms such as VSBet, ColaScore, 8xbet, and 6686 through actor-controlled redirection and cloaking.
MITRE Techniques
- [T1583.001 ] Acquire Infrastructure: Domains – Sable Squirrel buys expired and lookalike domains to build criminal infrastructure, including streaming, redirection, and C2 [‘Sable Squirrel buys reputation by the domain’ / ‘buys expired domains at auction’]
- [T1584.001 ] Compromise Infrastructure: Domains – One of the actor’s domains was taken over and used by another criminal crew, showing infrastructure compromise [‘the domain’s authoritative Cloudflare name servers were replaced’ / ‘possible compromise of the domain’s registrar account’]
- [T1036 ] Masquerading – The actor uses streaming sites and brand names to appear legitimate while serving illicit traffic [‘the sites look and feel like a legitimate streaming service’ / ‘display a free DMCA “protected” badge’]
- [T1105 ] Ingress Tool Transfer – Malware samples and tools connect back to actor-controlled domains, enabling delivery and command traffic [‘over 31,000 malware samples connecting back to C2 hosted on Sable Squirrel domains’]
- [T1090.001 ] Proxy: Internal Proxy – Actor-controlled redirection and cloaking routes users and automated traffic to different destinations [‘It routes real viewers to the betting platforms while sending automated visitors… into dead ends’]
- [T1071.001 ] Application Layer Protocol: Web Protocols – WordPress sites, WebSocket chat, and web-based C2/traffic flows use HTTP(S)-based services [‘Pressing play pulls video from a dedicated pool of streaming servers’ / ‘Opening the in-match chat connects the viewer to WebSocket services’]
- [T1110 ] Brute Force – Not mentioned in the article.
- [T1055 ] Process Injection – Not mentioned in the article.
- [T1547.001 ] Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder – A sample installs itself under a startup key to persist [‘The malware installs itself under a startup key named xoilac’]
Indicators of Compromise
- [Domains ] Dropcatch acquisitions / historical domains – veinteractive[.]com, healthymagination[.]com, and 2 more items
- [Domains ] Streaming and infrastructure domains – cel-robox[.]com, 6789x[.]site, and 10 more items
- [Domains ] Malware C2 / RAT-related domains – colatv88xb[.]cc, ws-xyz[.]com, and 3 more items
- [Domains ] Media, chat, and backend services used by the streaming fleet – imgts[.]com, api-score[.]com, and 6 more items
- [Domains ] Example compromised / abused sites – xemlaibongda[.]net, xoilacxys[.]top
- [IP / Network identifiers ] The article does not provide specific IP addresses; infrastructure is primarily identified by domain and DNS activity – no explicit IPs listed
- [File hashes ] Representative malware sample hash – 0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216
- [File names / artifacts ] Malware metadata and startup artifact – socolive[.]exe, startup key named xoilac