Mining for DNS Maxims: Top 10 Malware of Q3 2025

The Center for Internet Security (CIS) named the top 10 malware of Q3 2025 and identified 31 domains as IoCs for five of them.1 After weeding out legitimate domains from their list with the help of the WhoisXML API MCP Server,2 we were left with 26 domains for our study. Our in-depth analysis of the IoCs for SocGholish, Agent Tesla, ZPHP, Gh0st, and Lumma Stealer led to these discoveries:

  • Two domains identified as IoCs deemed likely to turn malicious 150–598 days prior to being dubbed as such
  • One domain tagged as an IoC was bulk-registered with others and could be a typosquatter
  • 5,266 email-connected domains, 56 were found malicious
  • 11 IP addresses, seven were found malicious
  • 104 IP-connected domains
  • 606 string-connected domains, one was found malicious

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://www.cisecurity.org/insights/blog/top-10-malware-q3-2025
  • [2] https://main.whoisxmlapi.com/ai/mcp-server
Try our WhoisXML API for free
Get started