Swiping Squirrel is a financially motivated cybercriminal dropcatch actor active since at least 2022. It acquires expired domains formerly used in malicious infrastructure and exploits residual traffic from compromised websites that still reference those domains. The actor has acquired more than 3,000 domains and is characterized as the most prolific among the related scavenger actors Stuffy Squirrel and Shady Squirrel. Swiping Squirrel monetizes fraudulently inherited traffic by relaying it to zero-click advertising platforms and affiliate programs, where it can be resold into scam, advertising-fraud, or malware-delivery chains. Observed downstream activity has included ClickFix-style fake CAPTCHA lures. Swiping Squirrel employs client-side JavaScript fingerprinting and cloaking to selectively return content only when requests originate from the intended compromised-site context, limiting exposure to direct inspection. It has also coexisted with Shady Squirrel on compromised websites, with the actors at times acquiring expired domains previously controlled by one another.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as another group observed acquiring and abusing expired domains; the article generally associates such groups with redirecting existing traffic to malware, advertising fraud, or scams.
Tracked as another group monetizing expired domains by capturing residual traffic from previous owners and redirecting it to ad networks, scam sites, and other cybercriminals.
Highly prolific cybercriminal dropcatch actor that reacquires expired malicious domains and redirects inherited victim traffic into zero-click advertising chains that often end in scams or malware.
A scavenger actor that acquires expired domains previously compromised by other attackers and inherits existing infection traffic.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.