Sable Squirrel is a large cybercriminal operation associated with a sprawling domain-based ecosystem used for illegal sports streaming, gambling promotion, traffic redirection, mobile app distribution, and malware command-and-control. The actor has been linked to control of more than 10,000 domains and is notable for spending heavily on expired dropcatch domains to inherit residual traffic, backlinks, and reputation signals, while also registering fresh lookalike domains tied to its streaming brands. Known associated brands include Xoilac, Cakhia, 90phut, Socolive, and MiTom, with apparent alignment to betting brands such as VSBet, ColaScore, 8xbet, and 6686. The actor has used its domain inventory as dual-use infrastructure, including simultaneous delivery of live football streaming content and command-and-control for commodity malware. Observed malware families on its infrastructure include Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, and malware carrying HiddenTear ransomware signatures. A major malware weaponization wave began in late 2025, with broad repurposing of existing streaming domains into malware C2 infrastructure and DCRat later becoming a primary payload. Malware samples have also contained branding artifacts associated with the actor’s streaming and betting ecosystem, indicating operational overlap between the illicit media business and malware activity. Sable Squirrel demonstrates strong capability in infrastructure acquisition and scaling, malware delivery support, command-and-control operations, and defense evasion through abuse of aged domains with established trust characteristics. Its infrastructure has been observed reaching victim networks across numerous sectors, with especially strong exposure in education, information technology and consulting, government, healthcare, and banking. The operation is assessed to strongly overlap with the Vietnamese Xoi Lac TV network that faced law-enforcement action in early 2026, although definitive identity equivalence has not been publicly confirmed. Available evidence supports characterization of Sable Squirrel as a financially motivated, Vietnam-linked cybercriminal enterprise embedded in a broader transnational Asian streaming-and-gambling ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
38 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor noted for spending millions of dollars acquiring dropped domains.
Operates a large cybercriminal enterprise built on thousands of domains used for illegal sports streaming, gambling promotion, traffic redirection, and malware command-and-control. The actor uses expired-domain dropcatching and lookalike registrations, and its infrastructure is tied to RAT families and HiddenTear-signature samples.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.