Research Center

Access our latest research and insights on WHOIS, IP, and DNS data for cybersecurity, data science, and other business purposes through our webinars, podcasts, white papers, threat reports, and videos from the Academy.

Have questions?

Threat Reports

Tracing the DNS Footprints of REF7707

The REF7707 campaign actors recently targeted the foreign ministry of a South American country. According to a published report, the group has been connected to previous compromises in Southeast Asia.

The threat actors reportedly used three new malware—FINALDRAFT, GUIDLOADER, and PATHLOADER—for the attack. The study listed 13 indicators of compromise (IoCs) comprising eight domains and five IP addresses.1

WhoisXML API expanded the current list of IoCs and uncovered connected artifacts, namely:

Continue reading

DNS Deep Diving into 2025’s Up and Coming Ransomware Families

Ransomware attacks are expected to continue plaguing individual users and organizations worldwide because they work. As of 2024, victims were asked to pay an average of US$2.5 million per incident.1

A report named 10 of the most active ransomware families in 2024,2 which WhoisXML API decided to further investigate. We obtained lists of indicators of compromise (IoCs) for RansomHub,3 LockBit 3.0,4 Play,5 Akira,6 Hunters,7 Medusa,8 BlackBasta,9 Qilin,10 BianLian,11 and INC. Ransom12 (aka Lynx).13

We expanded a list of 120 IoCs comprising 48 domains and 72 IP addresses to uncover connected artifacts and found:

Continue reading

Igniting a DNS Spark to Investigate the Inner Workings of SparkCat

A recent investigation led to the discovery of Android and iOS apps laced with a malicious software development kit (SDK) dubbed “SparkCat.” As a result, the apps stole victims’ crypto wallet recovery phrases. Based on the malware time stamps and configuration file creation dates found in GitLab repositories, SparkCat has been seemingly active since March 2024.

SecureList published five indicators of compromise (IoCs) related to SparkCat.1 WhoisXML API dove deep into the threat’s DNS footprints and uncovered other artifacts comprising:

Continue reading

Malicious Ads Targeting Advertisers in the DNS Spotlight

Google and Microsoft are consistently among the most-phished brands. Case in point: Microsoft topped a recently published list1, while Google ranked third.

A total of 97 domains were recently identified as indicators of compromise (IoCs) related to a new attack that targeted Microsoft advertisers. The threat actors used malicious Google ads to steal the login information of users of Microsoft’s advertising platform.2

Continue reading

A DNS Investigation of SEO Manipulation via Bad Seed BadIIS

Search engine optimization (SEO) manipulation campaigns are not necessarily new in the cybercrime world. Many attacks often target users of popular software and services.

A new report featured such a threat dubbed “BadIIS” that has been trailing its sights on Internet Information Services (IIS) users.1 The campaign redirected victims from Asian countries to illegal gambling websites. The report identified 51 indicators of compromise (IoCs).2

Continue reading

Sneaking a Peek into the Inner DNS Workings of Sneaky 2FA

Phishing-as-a-service (PhaaS) offering Sneaky 2FA was recently used in an adversary-in-the-middle (AitM) attack targeting Microsoft 365 users. It reportedly used fake Microsoft authentication pages with automatically filled-in email address fields to add to its sense of authenticity to lure in victims.1

Researchers analyzed the threat and identified at least 61 indicators of compromise (IoCs) comprising 57 domains, two IP addresses, and two subdomains.

Continue reading

Unloading MintsLoader IoCs Using DNS Intelligence

A sophisticated malware campaign leveraging MintsLoader is targeting critical infrastructure and legal firms across the U.S. and Europe. MintsLoader’s advanced techniques, including using a domain generation algorithm (DGA) to create new command-and-control (C&C) servers, make detection difficult.1

Building on the 61 indicators of compromise (IoCs) related to the ongoing MintsLoader attack identified by threat researchers at eSentire2, the WhoisXML API research team utilized our comprehensive DNS intelligence and uncovered additional artifacts comprising:

Continue reading

DNS Spotlight: Rockstar2FA Shuts Down, FlowerStorm Starts Up

It’s not unusual for threat actors to take over fellow criminals’ existing infrastructure after they have been abandoned. Think ZeuS, which its original operator allegedly sold to another actor who eventually turned it into SpyEye.1

Rockstar2FA followed ZeuS’s fate it seems, as soon after its operators quieted down, FlowerStorm, which shared many of its features and functionality, took its place.2

Continue reading

Trusted by
the smartest
companies

Try our WhoisXML API for free

Get started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.