Threat Reports

Read other reports

DNS Spotlight: 2026’s 5 Most Notorious Ransomware

The Swiss Cyber Institute named¹ the most notorious ransomware as of April 2026. We zoomed into five of them—LockBit, Cl0p, Akira, Medusa, and Qilin—in a bid to know more about their network IoCs and identify new artifacts.

After extracting domains from the subdomain IoCs and filtering out those that belonged to legitimate entities aided by the WhoisXML API MCP Server², we ended up with 84 network IoCs comprising three subdomains, eight domains, and 73 IP addresses for our analysis.

84

Original IoCs Analyzed

Domain and IP indicators from the reported campaign

Key Findings

5,100

Email-connected domains

2

Additional IP addresses

60

IP-connected domains

39

Malicious artifacts

These are key highlights from our analysis. The full report contains many more findings and detailed insights.

OUR RESEARCH PROCESS

  • Domain and subdomain IoC legitimacy check
  • Domain IoC WHOIS and DNS history analysis
  • IP IoC geolocation and traffic analysis
  • Email-connected domain discovery
  • IP- and string-connected domain discovery
  • Malicious artifact confirmation

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://swisscyberinstitute.com/blog/10-most-notorious-ransomware-groups-2026/
  • [2] https://main.whoisxmlapi.com/ai/mcp-server

Latest Reports

Read other reports

Try our WhoisXML API for free

Get Started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.