Automatically translated.View original post

A group of hackers raised over $7 million.

A group of hackers has invested over US $7 million to buy expired domains to release malware.

According to a report by the Yahoo Tech website, the activity of a group of hackers using the defunct Domain technique to register a new domain name, or a technique called "Dropcatch Domains," by a research team from Infoblox Threat Intel, was said in a study report that, just in the early 2026 "s, 2569) Up to 50,400 new domains are registered per day when only the Generic Top-Level Domains are counted, and if the Country-Code Domains are counted, the peak will reach 65,000 domains per day, of which the highest type of domain is .net with 30% of the total domain type, followed by .xyz with 24.5%.

In this trend, a group of hackers and cybercriminals called Sable Squirrel have been detected with more than 10,000 domains. These domains are often used as infrastructure for streaming Vietnamese-language bootleg sports under the brands Xoilac, Cakhia, 90phut, Socio, and MiTom. A review by the research team found that the hacker group has spent as much as $7 million ($230,356,000) on purchases of expired domains, the largest amount of money on record from investments by a single group of hackers. But what is worth it? Even more concerned, those streaming domains have been used as malware servers (C2 or Command and Control), while websites under them have been streaming bootleg football to regular visitors at the same time.

When examining over 31,000 malware samples covering a wide range of malware, Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, and njRAT with Ransomware, the name HiddenTear can be traced back to the infrastructure of such hackers. This is due to the negligence of such hackers that have identified the names of websites under the control of the group, such as socolive, xoilac, and 8xbet, within the Metadata data of the files for running on Windows Executable of such group malware. The total number of domains has been identified by the research team as approximately 405. All domains under the control of a group of hackers that serve as C2 servers for the above-mentioned malware groups. In addition to providing bootleg streaming services and releasing malware, the research team found that the core business of this group of hackers is actually a gambling web.

This outrageous act cannot be ignored by the Vietnamese authorities. About 30 suspects associated with the group have been invaded and seized up to US $12 million ($394,752,000) during the past February. But even a heavy crackdown could not stop the Sable Squirrel hackers. During the World Cup, the hackers purchased a large number of World Cup-related domains in June for use in their group's activities (which are thought to be streaming playoff football). And in the field of football gambling).

# Trending # lemon 8 diary # Hackers # Domain name # freedomhack

9/11 Edited to

... Read moreจากประสบการณ์ส่วนตัวที่ติดตามข่าวสารวงการไซเบอร์ซีเคียวริตี้ พบว่าการใช้โดเมนหมดอายุมาทำกิจกรรมผิดกฎหมายเป็นปัญหาที่กำลังเพิ่มมากขึ้นอย่างรวดเร็ว เทคนิค "Dropcatch Domains" ทำให้แฮกเกอร์สามารถจดทะเบียนโดเมนที่ถูกละทิ้งไปแล้วมาใช้งาน เพื่อสร้างความน่าเชื่อถือในสายตาผู้ใช้งานทั่วไป ด้วยชื่อโดเมนที่ดูเหมือนเว็บไซต์จริง กลุ่มแฮกเกอร์ Sable Squirrel ใช้โดเมนเหล่านี้เพื่อวางเซิร์ฟเวอร์ควบคุมมัลแวร์ (C2) และสตรีมมิงฟุตบอลเถื่อนในเวียดนาม ซึ่งผมเคยเห็นกรณีที่เว็บไซต์สตรีมมิงลักษณะนี้ลิงก์ไปยังหน้าโฆษณาหรือดาวน์โหลดไฟล์ที่ติดมัลแวร์อย่างแอบแฝง โดยไฟล์มัลแวร์บางตัว เช่น Quasar RAT และ njRAT มีศักยภาพในการขโมยข้อมูลและควบคุมเครื่องคอมพิวเตอร์ผู้ใช้ระยะไกล จากการตรวจสอบ Metadata ของไฟล์ Executable เหล่านี้ พบว่ามีข้อมูลระบุชื่อโดเมนที่เกี่ยวข้องกับกลุ่มแฮกเกอร์ ดังนั้นการป้องกันขั้นต้นที่ดี ควรระมัดระวังการดาวน์โหลดหรือคลิกลิงก์จากเว็บไซต์ที่ไม่น่าไว้วางใจ รวมถึงควรอัปเดตโปรแกรมแอนตี้ไวรัสอยู่เสมอ กรณีนี้ยังสะท้อนให้เห็นความยากลำบากของหน่วยงานบังคับใช้กฎหมายในการปราบปราม เพราะแม้จะจับผู้ต้องสงสัยและยึดทรัพย์จำนวนมาก กลุ่มนี้ก็ยังสามารถขยายกิจกรรมโดยใช้โดเมนใหม่ ๆ รวมถึงสร้างรายได้จากเว็บพนันและสตรีมมิงเถื่อนในช่วงฟุตบอลโลก ซึ่งเป็นช่วงที่มีผู้สนใจสูงสุด ด้วยเหตุนี้ ผู้ใช้ทั่วไปควรเพิ่มความระมัดระวังเมื่อต้องเข้าสู่เว็บไซต์สตรีมมิง หรือพนันออนไลน์ โดยควรตรวจสอบแหล่งที่มาและเลือกใช้บริการที่ถูกกฎหมายเพื่อลดความเสี่ยงจากการถูกโจมตีมัลแวร์ผ่านโดเมนที่ถูกควบคุมโดยกลุ่มแฮกเกอร์เหล่านี้