Provide current and historical ownership information on domains / IPs. Identify all connections between domains, registrants, registrars, and DNS servers.
The MITRE Corporation typically updates its ATT&CK page by listing the new groups it monitors for malicious activity twice a year—generally in April and October. The latest Updates – April 20251 advisory listed seven new groups with corresponding lists of indicators of compromise (IoCs).
WhoisXML API dove deep into the seven groups’ DNS footprints and uncovered connected artifacts that have not yet been publicized. We specifically found: