Provide current and historical ownership information on domains / IPs. Identify all connections between domains, registrants, registrars, and DNS servers.
The Swiss Cyber Institute named¹ the most notorious ransomware as of April 2026. We zoomed into five of them—LockBit, Cl0p, Akira, Medusa, and Qilin—in a bid to know more about their network IoCs and identify new artifacts.
After extracting domains from the subdomain IoCs and filtering out those that belonged to legitimate entities aided by the WhoisXML API MCP Server², we ended up with 84 network IoCs comprising three subdomains, eight domains, and 73 IP addresses for our analysis.
Original IoCs Analyzed
Domain and IP indicators from the reported campaign
Key Findings
Email-connected domains
Additional IP addresses
IP-connected domains
Malicious artifacts
These are key highlights from our analysis. The full report contains many more findings and detailed insights.
OUR RESEARCH PROCESS
- Domain and subdomain IoC legitimacy check
- Domain IoC WHOIS and DNS history analysis
- IP IoC geolocation and traffic analysis
- Email-connected domain discovery
- IP- and string-connected domain discovery
- Malicious artifact confirmation
Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.
—
- [1] https://swisscyberinstitute.com/blog/10-most-notorious-ransomware-groups-2026/
- [2] https://main.whoisxmlapi.com/ai/mcp-server