Research Center

Access our latest research and insights on WHOIS, IP, and DNS data for cybersecurity, data science, and other business purposes through our webinars, podcasts, white papers, threat reports, and videos from the Academy.

Have questions?

Threat Reports

A DNS Investigation into Mamba 2FA, the Latest AitM Phishing Player

Adversary-in-the-middle (AitM) phishing attacks have been growing in popularity, and it’s not surprising.1 As more companies adopt multifactor authentication (MFA) security measures, more threat actors are using this tactic. Why? AitM has the ability to bypass security measures like MFA.

WhoisXML API recently analyzed Mamba 2FA, the latest addition to the list of AitM phishing players.2 In particular, we expanded a list of 58 indicators of compromise (IoCs) and uncovered:

Continue reading

New RomCom Variant Spotted: A Comparative and Expansion Analysis of IoCs

RomCom has once again evolved and been made stealthier as per its latest variant, Snipbot.

The new version was popularly used in attacks that led to data theft, while the previous variants were used to deliver ransomware. The victim pool included organizations across various sectors, including legal and IT services.1

The WXA research team sought to compare the list of IoCs of the three latest versions—RomCom 3.0,2 RomCom 4.0,3 and Snipbot.4 We also expanded the list of IoCs to uncover more potentially connected artifacts. Using WHOIS, IP, and DNS intelligence, our analysis led to the discovery of:

Continue reading

A DNS Investigation of the 32 Doppelganger Websites the U.S. Government Seized

Pretty much everything people need to accomplish these days, especially obtaining information, is doable online. So, is it really surprising how much fake news we can find on the Web?

The threat actors behind the Doppelganger campaign showed how much damage disinformation can sow, and what believing in it can result in. Fake news, for instance, can have real-life consequences like losing an election or long-term reputational damage.

Continue reading

Investigating the Proliferation of Deepfake Scams

Deepfakes can cause real harm. In February 2024, for example, an employee of a multinational company was tricked into handing US$25 million to a scammer who pretended to be their company’s CFO.1

In light of this and similar attacks, security researchers have tried to shed more light into deepfake scams and the risks they pose. One report, in particular, unveiled 416 scam IoCs.2

The WhoisXML API research team investigated just how widespread deepfake scam infrastructures could be in the DNS through an IoC list expansion analysis. Our study uncovered potentially connected artifacts comprising:

Continue reading

Examining the DNS Underbelly of the Voldemort Campaign

The threat actors behind the malware that must not be named, also known as “Voldemort,” reportedly sent around 20,000 phishing emails that impacted at least 70 organizations worldwide.1 Believed to be part of an advanced persistent group (APT), they used Voldemort distributed via weaponized Google Sheets files to infect the systems of target nations.

Nineteen indicators of compromise (IoCs) comprising 10 subdomains and nine IP addresses have already been identified, but more artifacts could be lurking in the DNS.2

Continue reading

Stripping Down the BlackSuit Ransomware Network Aided by DNS Data

Ransomware attacks are among the biggest threats organizations face, potentially costing them millions of dollars. One of the most recent campaigns involves the BlackSuit ransomware, a rebranded version of Royal ransomware. BlackSuit actors stole and exposed 1 million individuals’ full names, Social Security numbers (SSNs), birthdays, and insurance claim details.1

In response, the Cybersecurity and Infrastructure Security Agency (CISA) updated its BlackSuit ransomware advisory, which now includes 91 indicators of compromise (IoCs) comprising 14 domain names, five subdomains, and 72 IP addresses.2

Continue reading

A DNS Deep Dive into the NetSupport RAT Campaign

NetSupport RAT,1 the weaponized version of legitimate remote device administration tool NetSupport Manager, is no longer a newbie when it comes to cyber attacks. It was first used in November 2023 and then again in January 2024.

Security researchers have performed in-depth analyses on the tool, in the process identifying nine domain names as indicators of compromise (IoCs).2

Continue reading

Tracking the DNS Footprint of the Polyfill Supply Chain Attackers

Threat actors will always find a way to get into their targets’ networks, even if they have to go through indirect channels. Such was the story behind the Polyfill supply chain attack.

Users of the content delivery network (CDN) service worldwide ended up with compromised networks courtesy of a malicious JavaScript code the cyber attackers injected.

Continue reading

Trusted by
the smartest
companies

Try our WhoisXML API for free

Get started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.