WhoisXML API uncovered 62,081 domains referencing the 2026 U.S. midterm elections, including look-alike candidate stores traced to a few registrants. Download the threat research materials now.
Continue readingA DNS Investigation of Shadow-Earth-053
Trend Micro uncovered1 Shadow-Earth-053, a China-aligned cyberespionage campaign targeting government and critical infrastructure across South, East, and Southeast Asia and a NATO member state. The actor exploited N-day vulnerabilities in internet-facing Microsoft Exchange and IIS servers, deployed GODZILLA web shells for persistence, and staged ShadowPad implants via DLL sideloading of signed executables.
From the 26 network IoCs in the original analysis, we expanded to 31 IoCs—16 subdomains, 10 domains, and five IP addresses—for our investigation, aided by the WhoisXML API MCP Server2.
Our DNS deep dive into Shadow-Earth-053 led to these discoveries:
- 865 unique client IP addresses that communicated with three of the domain IoCs
- Two domain IoCs that were likely registered with malicious intent
- 10 distinct IP addresses potentially owned by victims that communicated with three of the IP IoCs
- 835 email-connected domains
- Nine additional IP addresses, seven of which were confirmed malicious
- Nine IP-connected domains, one of which was confirmed malicious
- 749 string-connected domains, six of which were confirmed malicious
Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.
—
- [1] https://www.trendmicro.com/en_us/research/26/d/inside-shadow-earth-053.html
- [2] https://main.whoisxmlapi.com/ai/mcp-server