Research Center

Access our latest research and insights on WHOIS, IP, and DNS data for cybersecurity, data science, and other business purposes through our webinars, podcasts, white papers, threat reports, and videos from the Academy.

Have questions?

Threat Reports

New MITRE ATT&CK Groups for 2025: A DNS Deep Dive

The MITRE Corporation typically updates its ATT&CK page by listing the new groups it monitors for malicious activity twice a year—generally in April and October. The latest Updates – April 20251 advisory listed seven new groups with corresponding lists of indicators of compromise (IoCs).

WhoisXML API dove deep into the seven groups’ DNS footprints and uncovered connected artifacts that have not yet been publicized. We specifically found:

Continue reading

Hunting for DNS Traces of Hundreds of Malicious Google Play Apps

Bitdefender uncovered a large-scale ad fraud campaign involving hundreds of malicious apps available for download in Google Play.1 According to the researchers, the apps have been downloaded more than 60 million times. When installed, they displayed out-of-context ads and persuaded victims to give away their credentials and credit card information via phishing.

The security researchers identified 428 URLs as indicators of compromise (IoCs) that we extracted 197 unique domains from. Our expansion analysis of the 197 domains tagged as IoCs led to the discovery of:

Continue reading

Exploring the DNS Flipside of SideWinder

The SideWinder advanced persistent threat (APT) group, active since 2012 and known for targeting government, military, and business entities throughout Asia, primarily Pakistan, China, Nepal, and Afghanistan,1 changed gears. They not only updated their toolset and created new infrastructure but also significantly increased attacks against maritime and logistics companies notably in Djibouti and Egypt and nuclear power plants in South Asia and Africa.

Researchers identified 35 domains as indicators of compromise (IoCs),2 which we expanded to find more connected artifacts. We uncovered:

Continue reading

Unlocking the DNS Strongbox of BADBOX 2.0

BADBOX 2.0 has reportedly infected more than 1 million consumer devices as of March 2025. And the subsequent attacks (e.g., click fraud, account takeovers [ATOs], distributed denial-of-service [DDoS] attacks, etc.) that may ensue aided by the botnet may affect millions more.1

WhoisXML API analyzed 109 indicators of compromise (IoCs) related to the threat and found more domains and IP addresses that could be part of the BADBOX 2.0 network. Our DNS deep dive led to the discovery of:

Continue reading

Tempering Tax Season Troubles with DNS Intel

Another year, another chance to take advantage of U.S. taxpayers paying their dues. Despite the fact that tax day—15 April 2025—has passed, WhoisXML API believes threat actors can continue to prey on potential victims who filed for extension up to 15 October 2025.2

Microsoft cybersecurity researchers identified 11 domains and one IP address as indicators of compromise (IoCs) related to ongoing tax-themed phishing campaigns.3 WhoisXML API expanded the current IoC list and uncovered potentially connected artifacts, namely:

Continue reading

Unearthing the DNS Roots of the Latest Lotus Blossom Attack

Lotus Blossom launched several cyber espionage campaigns targeting government, manufacturing, telecommunications, and media organizations using Sagerunex and other hacking tools.1

Cisco Talos identified several indicators of compromise (IoCs), including 10 domains and 28 IP addresses, which WhoisXML API expanded through a DNS deep dive.2 Our analysis led to the discovery of:

Continue reading

Rounding Up the DNS Traces of RA World Ransomware

Threat actors typically come in two types. They are either cybercriminals who are in it for profit or advanced persistent threat (APT) group members in it for ideology.

There are times, though, when actors get involved in both attack types. Case in point? Researchers recently reported that a threat actor who has been involved in installing backdoors in the systems of target government institutions instigated an RA World ransomware attack.1 The actor used the same tools as those involved in China-linked espionage campaigns.

Continue reading

Decrypting the Inner DNS Workings of EncryptHub

Rising cybercriminal entity EncryptHub seems to have unknowingly exposed elements of its malicious enterprise. An Outpost24 investigation unveiled new aspects of the group’s infrastructure, tools, and behavioral patterns.

The security researchers were able to take a peek into the threat actors’ stealer logs, malware executables, PowerShell scripts, and Telegram bot configurations. These errors shed light on the group’s operations, including their attack chain and methodologies.1

Outpost24 identified 20 indicators of compromise (IoCs) that WhoisXML API expanded through a DNS deep dive.

Continue reading

Trusted by
the smartest
companies

Try our WhoisXML API for free

Get started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.