Research Center

Access our latest research and insights on WHOIS, IP, and DNS data for cybersecurity, data science, and other business purposes through our webinars, podcasts, white papers, threat reports, and videos from the Academy.

Have questions?

Threat Reports

Tracking Down APT Group WIRTE’s DNS Movements

Many if not all advanced persistent threat (APT) groups continue to launch attacks long after they are first formed. One such group, WIRTE, for instance, has been active since at least August 2018.1

The most recent WIRTE attack utilized custom loaders like IronWind to infiltrate target networks based in the Middle East, specifically the Palestinian Authority, Jordan, Egypt, and Saudi Arabia.2

Continue reading

Unraveling the DNS Connections of ToxicPanda

Banking Trojans like Zeus or ZBOT have been plaguing bank customers the world over since around 2007.1 And the primary reason for their longevity and persistence to date is that they work.

While many banking Trojans focused on infecting computers, newer ones like ToxicPanda have been designed to affect Android devices.2

The WhoisXML API research team expanded a list of 21 domains tagged as ToxicPanda indicators of compromise (IoCs) and uncovered:

Continue reading

Silent Night, Deadly Sites: How Christmas Cyber Threats Lurk in the DNS

For many people, Christmas is a time for gift giving, shopping, and merrymaking. And more often than not, they opt to make their purchases and reservations online. That’s where trouble, unfortunately, typically begins.

Many online offers and deals, especially those at unbelievably affordable prices, are either scams or threat vectors.1

WhoisXML API collated 22,923 christmas domains from First Watch Malicious Domains Data Feed on 26 November 2024 and analyzed their DNS footprint. We uncovered:

Continue reading

A DNS Deep Dive into New Crypto Threat “Hidden Risk”

The number of people who own cryptocurrencies the world over has reached more than 560 million people this year.1 To cyber attackers, that could mean more than half a million potential victims, as crypto owners are often lured by fake news promising investment opportunities or market insights. The actors behind Hidden Risk appear to have targeted them with a malicious campaign that uses fake crypto news to distribute the RustBucket malware.

The WhoisXML API research team compiled 81 indicators of compromise (IoCs) from a published report and expanded it aided by DNS intelligence.2

Continue reading

A DNS Investigation of the GootLoader Campaign

It’s one thing for a piece of malware to steal victims’ data. It gets worse, though, when that malware paves the way for even more sinister actions like dropping a ransomware or allowing further compromise without getting detected. That’s the case for GootLoader.1

Twelve domains have been tagged as GootLoader indicators of compromise (IoCs).2 The WhoisXML API expanded this list to uncover other connected artifacts and found:

Continue reading

Uncovering Potential Black Friday and Thanksgiving Threats with DNS Data

Thanksgiving may be one of the most awaited holidays in the U.S. along with the day of the biggest sale—Black Friday—typically associated with it. Unfortunately, cybercriminals also lie in wait for unwitting people in search of the best promos and biggest discounts to visit their malware-laden web pages.

We obtained a sample of 2,324 domains containing the text strings blackfriday and thanksgiving from the First Watch Malicious Domains Data Feed and analyzed their DNS footprint.

The WhoisXML API research team’s in-depth DNS investigation led to the discovery of:

Continue reading

Exploring the SideWinder APT Group’s DNS Footprint

The SideWinder advanced persistent threat (APT) group, also known as “T-APT-04” or “RattleSnake,” has been around for more than a decade now. So it is not surprising for its network to have grown over the years. In fact, as many as 100 domains have been identified as SideWinder indicators of compromise (IoCs) as of 15 October 2024.1

The WhoisXML API research team dove deep into the existing SideWinder network using DNS intelligence by expanding the current IoC list and found:

Continue reading

A DNS Deep Dive into FUNNULL’s Triad Nexus

If you have heard of the Polyfill supply chain attack, then you may already have an idea about what FUNULL is. It is said to have bought the domain polyfill[.]io, which was responsible for a massive attack that affected millions of websites in June 2024.1

FUNULL, as it turns out, is not only behind the Polyfill supply chain attack but also several other malicious campaigns involving investment scams, fake trading app distribution, and suspect gambling networks, all clumped together in what security researchers have dubbed “Triad Nexus.”2

The WhoisXML API research team expanded a list of 63 Triad Nexus suspicious indicators and found tons of other potentially connected artifacts, namely:

Continue reading

Trusted by
the smartest
companies

Try our WhoisXML API for free

Get started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.