Research Center

Access our latest research and insights on WHOIS, IP, and DNS data for cybersecurity, data science, and other business purposes through our webinars, podcasts, white papers, threat reports, and videos from the Academy.

Have questions?

Threat Reports

Illuminating Lumma Stealer DNS Facts and Findings

Popular malware-as-a-service (MaaS) offering Lumma Stealer has been active since 2022. It has been employed, in fact, to target victims in Argentina, Colombia, the U.S., the Philippines, and several other countries worldwide.1

In its latest campaign, the threat actors used fake CAPTCHAs to deliver the stealer. Cybersecurity researchers identified 34 indicators of compromise (IoCs) comprising 27 domains and seven subdomains in their in-depth analysis.2

The WhoisXML API research team dove deeper into the threat aided by our comprehensive DNS intelligence and uncovered potentially connected artifacts, namely:

Continue reading

DNS Deep Dive: Peeking into Back Doors to Abandoned but Live Backdoors

Backdoors allow threat actors to bypass a target organization’s normal authentication mechanisms.1 Most of these malware steal sensitive information and send it to command-and-control (C&C) servers—domains under the attackers’ control.

Did you ever wonder what happens to domains that served as C&C servers? Many of them remain operational and can be accessed by other threat actors.2

Continue reading

Early Discovery and Prediction of Meduza Stealer IoCs with First Watch

Meduza Stealer – a stealer-class malware that is capable of exfiltrating a wide variety of data from the infected device and can infect servers – has been first discovered in June 2023 by the Uptycs research team. It has been gaining traction since then, with multiple versions released by its developer that remains pretty active on darknet forums and Telegram. It has since been analyzed by research teams from Splunk, Broadcom, and other organizations.

Meduza Stealer is distributed by their creators on a subscription model, so there are various threat actors running multiple campaigns that use Meduza Stealer as a payload.

DNS Insights on a Free Form Builder Service Phishing Campaign

Phishers can take advantage of any third-party service to infiltrate an organization’s network. They did just that to harvest victims’ credentials and take over their organizations’ Microsoft Azure cloud infrastructure by leveraging the HubSpot Free Form Builder service.1

A total of 33 indicators of compromise (IoCs) related to the phishing campaign have already been identified. The WhoisXML API research team expanded the list of IoCs and uncovered:

Continue reading

The MOONSHINE Exploit Kit and the DarkNimbus Backdoor in the DNS Spotlight

While it may not be the first time the Earth Minotaur attackers used the MOONSHINE exploit kit to trail after targets, upping its capabilities with the addition of DarkNimbus delivery may be a novel tactic.1

Fellow threat researchers already identified 53 indicators of compromise (IoCs) related to the latest Earth Minotaur attack.2

The WhoisXML API research team dove deep into the threat aided by our comprehensive DNS intelligence and uncovered additional artifacts comprising:

Continue reading

More Signs of the more_eggs Backdoor Found in the DNS

Using resumes as a social engineering lure isn’t new. But they’re more often than not employed in run-of-the-mill phishing campaigns.

This time around, threat actor TA4557 utilized a weaponized resume to drop a backdoor called “more_eggs,” which leads to a persistent attack that results in credential theft.

The WhoisXML API research team obtained a published list of 17 more_eggs indicators of compromise (IoCs) and expanded it to identify more connected artifacts.1 Our in-depth analysis found:

Continue reading

Peering into Midnight Blizzard’s DNS Footprint

While Midnight Blizzard is believed to have been active since 2008, its tactics continue to evolve to this day. The threat actor was recently observed leveraging signed Remote Desktop Protocol (RDP) configuration files to gain access to victims’ devices.

The target? Thousands of people connected to various organizations in the public, academia, and defense sectors.1

The WhoisXML API research team expanded a list of 39 domains tagged as indicators of compromise (IoCs), 34 of which were extracted from subdomain IoCs. Our analysis led to the discovery of:

Continue reading

Trusted by
the smartest
companies

Try our WhoisXML API for free

Get started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.