Threat Reports

Read other reports

Domain Shadowing IoC Expansion Led to Thousands of Possible Connections

Threat actors have been known to hide behind legitimate Internet services1 to spread malware and lure victims to phishing sites and other malicious campaigns.

In this study, we built on a Palo Alto Networks report2 to dig deeper into a tactic called “domain shadowing” that enables cybercriminals to ride on the legitimacy of an entity’s domain name. The study led us to:

  • 2,900+ new subdomains beginning with strings used in the IoCs added between 1 September and 24 October 2022
  • 1,600+ web properties sharing the same IP addresses as the IoCs
  • About 4% of the connected artifacts that have been flagged as malicious
  • Several properties hosting suspicious pages, some of which look similar to content hosted by the IoCs

Get access to our findings and uncover more on your own. Download the report now.

  • [1] https://main.whoisxmlapi.com/threat-reports/gallium-apt-group-and-other-threat-actors-have-in-disguise 
  • [2] https://unit42.paloaltonetworks.com/domain-shadowing/#post-125143-_wkwf346ho2ji

Latest Reports

Read other reports

Try our WhoisXML API for free

Get Started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.