Swiping Squirrel is a financially motivated cybercriminal actor active since at least 2022 that specializes in malicious domain dropcatching. The actor acquires expired domains, particularly domains previously embedded in compromised websites or previously used by other malicious operators, in order to inherit residual victim traffic without needing to compromise the affected websites directly. Swiping Squirrel is assessed to control more than 3,000 domains and is regarded as the most prolific of a cluster of related dropcatch actors that also includes Stuffy Squirrel and Shady Squirrel. Its core operating model is traffic monetization rather than direct payload hosting. Swiping Squirrel captures inherited traffic from compromised-site references and routes that traffic through cloaking and relay chains into zero-click advertising and affiliate ecosystems, where it is resold and frequently ends in scams or malware delivery. Reported downstream outcomes have included scam flows and malware-related lures. The actor has also been observed participating in affiliate monetization programs tied to commerce platforms. Operationally, Swiping Squirrel uses client-side JavaScript fingerprinting and cloaking to validate requests and reduce exposure to scanners. Observed behavior includes serving content only when requests originate from the expected compromised-site context and otherwise returning benign or not-found responses. The actor can coexist competitively with other dropcatch actors on the same compromised websites, and domains may pass between such actors over time through repeated expiration and re-registration cycles. Swiping Squirrel fits a broader criminal ecosystem built around exploiting the residual trust, backlinks, and traffic of expired domains for fraud, scam enablement, and malware-adjacent monetization. Its dominant motivation is financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Highly prolific cybercriminal dropcatch actor that reacquires expired malicious domains and redirects inherited victim traffic into zero-click advertising chains that often end in scams or malware.
A scavenger actor that acquires expired domains previously compromised by other attackers and inherits existing infection traffic.
A scavenger actor that acquires expired domains previously compromised by other attackers in order to inherit existing infection traffic.
A financially motivated scavenger that acquires expired domains and monetizes fraudulent traffic by sending it to zero-click advertising platforms that resell it for scams or malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.