Research Center

Access our latest research and insights on WHOIS, IP, and DNS data for cybersecurity, data science, and other business purposes through our webinars, podcasts, white papers, threat reports, and videos from the Academy.

Have questions?

Threat Reports

Massive Photo ZIP Campaign Targets Booking.com Partner and Other Hotels across Japan and Europe

Microsoft Threat Intelligence uncovered¹ an active multistage intrusion campaign targeting hospitality and hotel organizations in Europe and Asia, particularly Japan, since April 2026. The unknown threat actors used photo-themed ZIP archives containing fake image shortcut files to launch an attack chain involving obfuscated PowerShell, a Node.js-based implant, registry persistence, and C&C communications. They also misused legitimate services such as Calendly’s email notification infrastructure and Google’s URL redirect functionality to deliver phishing emails.

Microsoft published 78 network IoCs—73 domains and five IP addresses. Using the WhoisXML API MCP Server², we determined that one domain belonged to a legitimate entity and analyzed the remaining 77 IoCs to uncover additional infrastructure and connections related to the campaign.

Continue reading

APT37 Strikes Again, This Time with NarwhalRAT

Genians Security Center¹ uncovered a North Korean cyberespionage campaign that deploys NarwhalRAT, a Python-based remote access trojan built for data theft. Victims receive spear-phishing emails posing as Microsoft account security alerts, and opening the attachment runs a malicious shortcut file that quietly installs the malware. Once active, NarwhalRAT can log keystrokes, capture the screen, harvest files from USB drives, and run commands remotely. Genians attributed the campaign to APT37, a state-sponsored group active since at least 2012.

Genians published 11 network IoCs—five domains and six IP addresses. Using the WhoisXML API MCP Server², we confirmed none of the domain IoCs were owned by legitimate entities and then analyzed all 11 to map the campaign’s wider footprint.

Continue reading

A DNS Investigation of LenAI’s ErrTraffic ClickFix Distribution Network

Sekoia’s Threat Detection & Research team analyzed¹ ErrTraffic, a fast-growing ClickFix malware distribution framework sold as a Malware-as-a-Service offering by a threat actor known as LenAI. The framework injects malicious JavaScript into compromised WordPress sites, showing visitors lures that trick them into running PowerShell commands that infect their machines with malware.

The original analysis publicized 71 domain IoCs. Aided by the WhoisXML API MCP Server², we investigated those 71 domain IoCs after confirming none were owned by legitimate entities.

Continue reading

62,081 Domains Referencing the 2026 U.S. Midterm Elections, Hundreds More Registered Every Week

The 2026 U.S. midterm elections have been showing up in domain registrations for several months. This research has tracked election-related names since September 2025, and thousands of new ones have been created every month since. Many are certainly harmless or legitimately motivated, but elections also combine two things that attract scams: online payments and strong feelings.

Using domain registration data that WhoisXML API collects and aggregates, the research narrowed the tracked names down to those built around the 50 best-funded Senate and 50 best-funded House campaigns from official FEC filings, then searched that set for unusual registration patterns. One case stood out: dozens of domains using the names of candidates from both parties, traced back to a single registrant abroad, several running online shops under the candidates’ names.

Inside a TDS-Powered ClickFix Malware Ecosystem: A DNS Deep Dive

Check Point Research uncovered¹ a large-scale operation that impersonated open-source and freeware projects to capture search traffic. The convincing fake project portals loaded a CloudFront-hosted JavaScript staging layer that rerouted download clicks into a strictly gated traffic distribution system (TDS). Downstream redirect chains then steered selected users to malware delivery infrastructure for RemusStealer, AnimateClipper, and the SessionGate framework.

The original analysis publicized 27 network IoCs. Aided by the WhoisXML API MCP Server², we investigated 30 IoCs—eight subdomains, 19 domains, and three IP addresses—after extracting the unique apex domains from the subdomain IoCs and running domain legitimacy and activity checks.

Continue reading

6,442 Domains Referencing Grand Theft Auto VI

Grand Theft Auto VI is scheduled for release on 19 November 2026. Domain registration activity referencing the game has already built up months ahead of launch, with a sharp June increase after pre-orders opened on 25 June.

Using current domain registrations containing game-related markers such as gta6, gtavi, gtasix, grandtheftauto, vicecity, leonida, rockstar, jasonduval, and luciacaminos, we built a 6,442-domain dataset and analyzed it across creation dates, registrars, registrant emails, name servers, naming themes, and threat signals.

1,755 Domains Referencing the 2026 F1 World Championship

The 2026 Formula 1 World Championship was accompanied by a visible wave of domain registrations referencing F1, Formula 1, Grand Prix, teams, drivers, circuits, tickets, stores, streaming, and fan activity. Registration volume fluctuated month to month but rose across the January–June window, peaking in June.

Using current domain registrations containing F1 markers such as f1, formula1, grandprix, and grand-prix, along with selected circuit, team, driver, and sponsor vocabulary, we built a 1,755-domain dataset and analyzed it across creation dates, registrars, registrant emails, name servers, naming themes, and threat signals.

DNS Investigation: Threat Actor TA4922 Goes Global

Proofpoint uncovered1 the global expansion of TA4922, a suspected Chinese-speaking cybercrime group that rapidly rotates malware—including Atlas RAT, RomulusLoader, SilentRunLoader, and ValleyRAT (Winos4.0)—and used localized HR-, tax-, and invoice-themed lures to deliver malware, credential phishing, and fraud schemes across Asia, Europe, and Africa.

The original analysis publicized seven network IoCs. Aided by the WhoisXML API MCP Server2, we investigated eight IoCs—one subdomain, two domains, and five IP addresses—after extracting the apex domain from the subdomain IoC.

Continue reading

Trusted by
the smartest
companies

Try our WhoisXML API for free

Get started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.

Get Started with WhoisXML API

Request Enterprise Demo

White Paper Download

Please complete the form below to download the required file:

Your business email will be validated while the request is being processed. This may take time.