Shady Squirrel is a financially motivated traffic-monetization and malware-delivery actor active since at least July 2023. The actor specializes in acquiring expired domains that were previously embedded in compromised websites or used in malicious infrastructure, then reusing the inherited traffic without needing to newly compromise those sites. More than 700 domains have been attributed to this activity since 2023. Shady Squirrel primarily acquires dropped domains previously associated with malware operations and affiliate advertising ecosystems. The actor has also conducted a supply-chain-style hijack by acquiring a formerly legitimate CDN domain and repurposing its residual trust and traffic to redirect visitors from legitimate websites to malicious downstream content. Operationally, Shady Squirrel uses custom JavaScript injections, Keitaro-based traffic distribution, and server-side fingerprinting to cloak malicious behavior. The actor commonly serves benign or original content to bots and scanners while selectively redirecting real users. A characteristic two-stage Keitaro handoff is used in which an initial script establishes client-side configuration and a second-stage response determines whether to redirect, inject HTML, or remain inactive. Observed downstream monetization and abuse chains have included a Russian gambling platform, push-monetization services, tech support scams, and malware delivery. In 2026, Shady Squirrel routed traffic to multiple downstream actors, including SocGholish shortly after Operation Endgame disrupted that ecosystem. This activity was assessed to have helped restore SocGholish access to large numbers of previously compromised websites by reactivating traffic from expired malicious domains still referenced on those sites. Shady Squirrel was also linked to tech support scam campaigns that selectively targeted Windows users arriving from search engines, with observed victim targeting in Japan and the United States. Known aliases are limited to Shady Squirrel.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used an expired CDN-related domain acquired via dropcatch to redirect website visitors to malware.
Russian-speaking dropcatch actor operating a cloaked TDS using expired malicious domains, custom JavaScript injections, and Keitaro-based delivery to route victims from compromised websites to gambling, tech support scams, fake updates, and affiliate adtech. The report highlights its role in enabling SocGholish's rapid return after Operation Endgame.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.