Stuffy Squirrel is a financially motivated cybercriminal actor specializing in malicious domain dropcatching and traffic monetization. Active since at least 2020, the actor acquires expired domains that were previously embedded in compromised websites or used in earlier malicious campaigns, allowing it to inherit residual victim traffic without needing to newly compromise the affected sites. Stuffy Squirrel has been observed controlling more than 500 domains and operating a traffic distribution system across multiple generations of infrastructure. The actor is notable for concealing malicious logic inside legitimate-looking JavaScript resources. A documented tradecraft pattern involves modifying benign libraries such as Raphaël.js to embed obfuscated code that executes selectively while preserving the appearance of a normal script. Stuffy Squirrel uses layered evasion, including selective server-side responses, path validation, decoy content for direct probing, and user-interaction gating so that malicious behavior is triggered only for real visitors, often after a click. This enables the actor to reduce exposure to automated scanners and casual inspection. Stuffy Squirrel has reused domains previously associated with other criminal activity, including infrastructure tied to web-injection and payment-card-skimming ecosystems such as Balada Injector and Magecart. Its traffic distribution and cloaking infrastructure is used to redirect inherited traffic into affiliate advertising and popunder monetization chains. Observed monetization has included push-notification and popunder advertising networks, with downstream outcomes centered on unwanted advertising and fraudulent traffic resale rather than ransomware operations. Stuffy Squirrel is one of several so-called scavenger actors that exploit the residual trust and traffic of expired malicious domains. Its activity overlaps conceptually with actors tracked as Shady Squirrel and Swiping Squirrel, but Stuffy Squirrel is distinguished by its emphasis on hiding malicious behavior inside legitimate scripts and by its long-running multi-generation traffic distribution infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercriminal dropcatch actor operating since at least 2020 that reacquires expired malicious domains to inherit victim traffic, uses a TDS, injects malicious code into legitimate scripts, and monetizes redirected traffic through affiliate advertising networks.
A scavenger actor that acquires expired domains previously compromised by other attackers and inherits existing infection traffic.
A scavenger actor that acquires expired domains previously compromised by other attackers in order to inherit existing infection traffic.
A financially motivated scavenger that acquires expired domains, operates a TDS, injects malicious JavaScript, and monetizes hijacked traffic through affiliate advertising networks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.