Sable Squirrel is a financially motivated cybercriminal operation assessed to be centered in Vietnam. Active since at least June 2023, it has acquired more than 10,000 expired domains through dropcatching, investing an estimated $7 million to exploit inherited traffic, backlinks, search visibility, and reputation. Its principal business consists of pirated sports streaming used to promote online gambling and betting services, primarily to Asian audiences. The operation uses streaming brands including Xoilac, Cakhia, 90phut, Socolive, and MiTom, and has redirected selected users to betting platforms. A subset of Sable Squirrel's streaming infrastructure also operates as malware command-and-control infrastructure, in some cases while continuing to serve apparent live sports content to browser users. More than 31,000 malware samples have been observed communicating with this infrastructure, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos RAT, njRAT, and samples bearing HiddenTear ransomware signatures. At least 405 domains were confirmed as malware C2 infrastructure. Malware C2 activity emerged in late 2025, with a major weaponization wave in December 2025. Sable Squirrel also uses newly registered lookalike domains alongside acquired expired domains, enabling rapid expansion and replacement of its streaming and malware infrastructure. The operation has strong infrastructure and operational overlap with the Vietnamese Xoi Lac TV piracy network, though their identity as the same entity has not been conclusively established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
39 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Controls a large portfolio of expired domains masquerading as streaming and gambling sites that also serve as malware command-and-control infrastructure.
Operates a large-scale expired-domain acquisition campaign, repurposing established domain reputation and traffic for illegal sports streaming, online-gambling promotion, and malware command-and-control infrastructure.
Operates a large-scale expired-domain re-registration scheme, using dropcatch domains for pirated sports streaming aimed at Asian audiences, redirecting users to online betting sites, and supporting malware command-and-control infrastructure.
Acquires large volumes of expired domains to exploit inherited reputation, traffic, and DNS history for criminal operations including illegal sports streaming, gambling promotion, and malware command-and-control infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.