Research Center

Access our latest research and insights on WHOIS, IP, and DNS data for cybersecurity, data science, and other business purposes through our webinars, podcasts, white papers, threat reports, and videos from the Academy.

Have questions?

Threat Reports

A Network IoC Analysis for 8 Iran-Affiliated APT Groups

Amid the ongoing conflict involving Iran, we examined whether geopolitical tensions have extended into cyberspace. Building on findings from S2W’s Iran APT Landscape Report1, we traced the DNS footprint of eight Iran-affiliated APT groups, including APT42, APT34, and MuddyWater.

After a closer look at the original IoC list, we analyzed 191 IoCs in all comprising four subdomains, 136 domains, and 51 IP addresses. Using our homegrown tools to investigate the threat, we uncovered these findings:

Continue reading

Unearthing DNS Facts about UAT-8099

Several cyber attacks attributed to the Cisco Talos-tracked UAT-8099 campaign have targeted vulnerable Microsoft IIS servers across Asia since late 2025. The activity leveraged web shells, PowerShell scripts, and the GotoHTTP tool to gain remote access, alongside region-specific BadIIS variants.

Cisco Talos identified1 17 network IoCs. After refining the dataset using the WhoisXML API MCP Server, we analyzed 27 IoCs comprising 10 domains and 17 subdomains. Using our tools to expand the investigation, we uncovered these findings:

Continue reading

ForceMemo in the DNS Spotlight

Several attacks tied to the ForceMemo campaign have targeted developers by compromising GitHub repositories and injecting malware into widely used Python projects. The activity, uncovered and tracked by StepSecurity, has affected hundreds of repositories since March 2026.

StepSecurity identified1 several IoCs associated with the campaign. After refining the dataset and removing legitimate infrastructure, we analyzed 20 IoCs comprising nine subdomains, five domains, and six IP addresses. Using our proprietary tools to further investigate the threat, we uncovered these findings:

Continue reading

DNS Analysis of the Keenadu Backdoor Network

A backdoor dubbed “Keenadu” has been identified in the firmware of certain Android devices, likely introduced through a malicious static library linked with libandroid_runtime.so during the firmware build process or delivered via compromised OTA updates. The malware acts as a multistage loader, enabling remote control of infected devices and supporting activities such as search hijacking and app monetization.

Securelist identified1 several IoCs associated with the threat. Building on these, we analyzed 29 refined IoCs, leading to these findings:

Continue reading

A DNS Exploration of Operation Olalampo

MuddyWater has long been active in state-sponsored cyber operations. In its latest campaign, dubbed “Operation Olalampo,” the group targeted organizations and individuals primarily across the MENA region, leveraging geopolitical tensions. The attackers deployed new malware variants and used Telegram bots for command-and-control (C&C).

Group-IB identified1 seven network IoCs associated with the activity. We analyzed all seven IoCs, comprising four domains and three IP addresses, and confirmed that none were tied to legitimate ownership. Using our homegrown tools to investigate the threat, we uncovered these findings:

Continue reading

DNS Deep Dive: LummaStealer + CastleLoader = Larger Threat

LummaStealer, an information-stealing malware family, continued operating despite a major law-enforcement disruption in 2025 by shifting hosting providers and adopting alternative loaders and delivery techniques such as ClickFix.

Bitdefender uncovered1 a new LummaStealer campaign that used CastleLoader as its main delivery mechanism. After extracting domains from IoC-tagged subdomains and excluding those belonging to legitimate organizations, we analyzed 211 IoCs in all, comprising two subdomains, 180 domains, and 29 IP addresses. Using our homegrown tools to investigate the threat, we uncovered these findings:

Continue reading

A Look Back at 11 of the Red Report 2026 Featured Threats

Several state-sponsored and financially motivated threat actors leveraged widely used MITRE ATT&CK techniques identified in Picus Security’s Red Report 2026 to compromise target environments.

After reviewing the original materials, we analyzed 147 network-based IoCs1 in total, comprising subdomains, domains, and IP addresses associated with 11 attacks linked to groups such as STATICPLUGIN, SadBridge Loader, XLoader, Operation BarrelFire, ClickFix, APT36, Chihuahua Stealer, Earth Ammit, PlushDaemon, and Earth Alux.

Using our homegrown tools to investigate the threat, we uncovered these findings:

Continue reading

A Close Look under the DNS Hood of CoolClient

Securelist recently reported1 a HoneyMyte (also known as “Mustang Panda” or “Bronze President”) campaign using an updated version of the CoolClient backdoor. Active in cyber-espionage operations, the group has previously deployed tools such as ToneShell, PlugX, Qreverse, Tonedisk, and SnakeDisk.

The 2025 CoolClient update introduces additional capabilities, including browser credential stealers and scripts for reconnaissance and data exfiltration.

Researchers initially identified four CoolClient network IoCs. After extracting domains from subdomains and filtering legitimate infrastructure, we analyzed six IoCs in total—three domains, two subdomains, and one IP address. Domain ownership checks using the WhoisXML API MCP Server2 confirmed that none of the domains were associated with legitimate entities.

Our investigation of the CoolClient IoCs led to these findings:

Continue reading

Trusted by
the smartest
companies

Try our WhoisXML API for free

Get started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.