DNS Spotlight: New MITRE ATT&CK Group Entrants as of October 2025

Nine new groups were listed on the MITRE ATT&CK October 2025 Updates1 page under three categories—Enterprise, Mobile, and ICS. We collated a list of 144 IoCs comprising 108 domains, 31 IP addresses, and five email addresses after filtering out legitimate domains from sources MITRE listed for each group.

We analyzed the 144 IoCs and the results revealed:

  • 1,839 unique potential victim IP addresses that communicated with four distinct IP addresses identified as IoCs
  • Two domains tagged as IoCs were deemed likely to turn malicious 10 days before they were reported as such
  • 78 email-connected domains, 11 were found malicious
  • Eight additional IP addresses, seven were found malicious
  • 196 IP-connected domains, five were found malicious
  • 718 string-connected domains, 11 were found malicious

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://attack.mitre.org/resources/updates/
Try our WhoisXML API for free
Get started