Research Center

Access our latest research and insights on WHOIS, IP, and DNS data for cybersecurity, data science, and other business purposes through our webinars, podcasts, white papers, threat reports, and videos from the Academy.

Have questions?

Threat Reports

GHOST STADIUM Takes Advantage of FIFA 2026: DNS Deep Dive

Group-IB uncovered1 GHOST STADIUM, a Chinese-speaking, financially motivated threat actor running a sophisticated phishing campaign across more than 300 domains ahead of the 2026 FIFA World Cup. The operation deployed a near pixel-perfect clone of the official FIFA website, complete with a replicated single sign-on (SSO) authentication flow and multilanguage support, to harvest credentials and payment details from fans seeking tickets. Researchers estimated potential losses from premium ticket fraud alone at US$71–474 million.

Continue reading

TA416 European Government Espionage Campaigns: DNS Deep Dive

Proofpoint reported1 that the China-aligned threat actor TA416 resumed targeting European government and diplomatic organizations from mid-2025 onward, later expanding to Middle Eastern entities. The campaigns paired web bug reconnaissance with malware delivery, rotating through several initial infection chains to ultimately deploy the group’s customized PlugX backdoor.

The original analysis publicized 96 network IoCs. Aided by the WhoisXML API MCP Server2, we filtered out domains potentially belonging to legitimate entities and narrowed our investigation to 91 IoCs.

Continue reading

A DNS Investigation of Shadow-Earth-053

Trend Micro uncovered1 Shadow-Earth-053, a China-aligned cyberespionage campaign targeting government and critical infrastructure across South, East, and Southeast Asia and a NATO member state. The actor exploited N-day vulnerabilities in internet-facing Microsoft Exchange and IIS servers, deployed GODZILLA web shells for persistence, and staged ShadowPad implants via DLL sideloading of signed executables.

Continue reading

DNS Deep Diving into FakeWallet Crypto Stealer

Securelist uncovered FakeWallet, a campaign of more than 20 phishing apps in the Apple App Store posing as popular crypto wallets such as MetaMask, Ledger, Trust Wallet, and Coinbase. When launched, the apps redirected users to fake App Store–style pages serving trojanized versions of the legitimate wallets, which were engineered to hijack victims’ recovery phrases and private keys. Malware metadata indicates the campaign had been active since at least fall 2025.

Continue reading

DNS Deep Dive: Pushpaganda Network IoCs

HUMAN’s Satori Threat Intelligence and Research Team recently uncovered a novel threat combining ad fraud, social engineering, and scareware that they named “Pushpaganda.” The operation generated invalid organic traffic from real mobile devices by tricking users into enabling push notifications—the source of its name—which then delivered alarming messages designed to make victims act on fabricated issues.

Continue reading

An Analysis of the AtlasCross RAT Network IoCs

Hexastrike Cybersecurity uncovered1 a multistage AtlasCross RAT campaign leveraging domains impersonating trusted software brands including Surfshark VPN, Signal, Telegram, Zoom, and Microsoft Teams. Attributed to the Silver Fox APT group, the operation targeted users of VPN clients, messaging platforms, videoconferencing tools, cryptocurrency trackers, and e-commerce apps.

The original research identified 13 IoCs comprising 12 domains and one IP address. Using our homegrown tools, we uncovered these findings:

Continue reading

The DNS Anatomy of the Axios Supply Chain Attack

GTIG uncovered1 a UN1069 attack targeting the widely used NPM package axios at the end of March 2026, with detailed analysis released shortly after. Elastic Security Labs disclosed2 additional IoCs, while GitHub listed3 another set of IoCs associated with the campaign.

After deduplication, domain extraction from subdomains, and filtering of legitimate infrastructure, we analyzed 22 IoCs, including five subdomains, seven domains, and 10 IP addresses. Using our DNS intelligence capabilities, we uncovered the following findings:

Continue reading

A Look Back at the Top 10 Ransomware of 2025

Several ransomware groups initially highlighted in our March 2025 analysis of emerging ransomware families went on to dominate the actual 2025 threat landscape. Six groups we previously examined—Qilin, Akira, Play, INC Ransom, Lynx, and RansomHub—ultimately appeared in Picus Security’s top 10 ransomware list1.

To revisit their infrastructure footprints, we analyzed 267 network IoCs extracted from public threat reports covering 10 major ransomware operations. Using the WhoisXML API MCP Server and our homegrown threat investigation tools, we uncovered the following findings:

Continue reading

Trusted by
the smartest
companies

Try our WhoisXML API for free

Get started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.