Research Center

Access our latest research and insights on WHOIS, IP, and DNS data for cybersecurity, data science, and other business purposes through our webinars, podcasts, white papers, threat reports, and videos from the Academy.

Have questions?

Threat Reports

Probing the DNS Depths of PeckBirdy

Trend Micro recently reported on PeckBirdy, a JavaScript-based command-and-control (C&C) framework used by China-aligned APT actors since 2023. Designed to operate across multiple environments, PeckBirdy enables flexible deployment and has been linked to campaigns involving modular backdoors such as HOLODONUT and MKDOOR, along with Cobalt Strike payloads, stolen code-signing certificates, and exploitation of CVE-2020-16040.

The researchers identified 36 network IoCs1 tied to the activity. After extracting unique domains from the subdomains flagged as IoCs, we analyzed 56 IoCs in total. Using our homegrown tools to investigate the threat, we uncovered these findings:

  • Three unique client IP addresses communicated with one domain classified as an IoC
  • Continue reading

    What Remains of Black Basta Now That Alleged Gang Leader Joined the Most Wanted List?

    The Hacker News recently reported1 that alleged Black Basta ransomware leader Oleg Evgenievich Nefedov has been added to the EU Most Wanted and INTERPOL Red Notice lists. Over time, Black Basta2 affiliates have relied on phishing and vulnerability exploitation for initial access, followed by double extortion—encrypting systems and exfiltrating sensitive data. Victims were instructed to contact operators via Tor-based .onion portals and typically given 10–12 days before data publication on the “Basta News” leak site.

    Security researchers publicized 27 network IoCs3 tied to a recent campaign4. We analyzed 18 IoCs, including 15 IP addresses and three verified domains, to uncover additional infrastructure and connections.

    Using our homegrown tools to investigate the threat, we uncovered these findings:

    Continue reading

    Top 10 Malware of Q4 2025: A DNS Deep Dive

    On 29 January 2026, the Center for Internet Security (CIS) published1 its list of the top 10 malware observed in Q4 2025, identifying network indicators of compromise (IoCs) for seven families: SocGholish, CoinMiner, Agent Tesla, Calendaromatic, ZPHP, VenomRAT, and ACR Stealer. After removing legitimate domains and refining the dataset with the WhoisXML API MCP Server2, we analyzed 46 IoCs, comprising 32 domains and 14 subdomains.

    Our deep dive into the 46 IoCs for seven of the top 10 malware of Q4 2025 led to these discoveries:

    Continue reading

    A Look Back at the Top Ransomware Attack Targeting the Salesforce Supply Chain

    Several high-impact ransomware operations in 2025 leveraged SaaS supply chain access to infiltrate enterprise environments. Among them, the Salesforce SaaS supply chain attack stood out for its scale and cross-sector impact. Threat actors reportedly exploited trusted integrations and harvested OAuth tokens to pivot into downstream customer environments. The consequences included large-scale data exposure, CRM compromise, and multisector operational disruption.

    Security researchers published1,2 multiple IoCs tied to the campaign. After consolidating and validating the original lists, we analyzed 39 IoCs in total.

    Our investigation led to these discoveries:

    Continue reading

    QakBot Named a 2026 Top Malware Threat: An IoC Analysis

    An analysis1 of QakBot, recently named one of the top malware threats to watch in 2026, highlighted its continued role as a highly effective access trojan and loader. Commonly delivered through phishing emails, QakBot is used to harvest credentials, maintain command-and-control access, move laterally across networks, and deploy secondary payloads, including ransomware. Its operations predominantly target enterprise environments with heavy email reliance, making it a persistent threat despite repeated takedown efforts.

    The IoCs used in this analysis were sourced from a Trellix-published list2, from which we extracted 929 unique domains. After removing legitimate but potentially compromised infrastructure, the dataset was reduced to 492 domains. We then focused on 125 domains and 19 subdomains, resulting in 144 IoCs analyzed.

    Our investigation led to these discoveries:

    Continue reading

    Probing the DNS Depths of PHALT#BLYX

    An analysis of stealthy campaign PHALT#BLYX that targeted the European hospitality sector revealed its use of click-fix social engineering, fake CAPTCHAs, and fake BSOD pages to trick users into downloading DCRat. All that so the threat actors could take full remote access to infected systems and drop secondary payloads. The researchers cited 11 original IoCs in their report.1

    We analyzed 12 IoCs in total—one URL, eight domains, and three IP addresses—after further scrutiny. Our investigation uncovered these findings:

    Continue reading

    Divulging the DNS Secrets of DarkSpectre

    Koi Security has been monitoring a threat group known as DarkSpectre for more than a year. The group has been linked to multiple malware campaigns involving Zoom Stealer, ShadyPanda1, and GhostPoster, impacting more than 8.8 million users over seven years.

    In a newly identified campaign affecting 2.2 million users, DarkSpectre leveraged a GhostPoster-linked Opera browser extension with nearly 1 million installs as of December 2025. Koi Security identified 20 IoCs2 tied to this activity. After filtering legitimate infrastructure using Jake AI, we analyzed 15 IoCs in total, leading to the following findings:

    Continue reading

    Analyzing Account Takeover Attacks Leveraging SquarePhish2 and Graphish

    Several state-sponsored and financially motivated attacks enabled by SquarePhish2 and Graphish, among other phishing tools, tricked users into granting threat actors access to their Microsoft 365 accounts. The consequences included account takeover, data exfiltration, and others.

    Proofpoint identified several IoCs1 associated with the attacks. After a closer look at the original IoC list, we analyzed 46 IoCs in all comprising 21 subdomains (including four with multiple variations), 22 domains, one IP address, and two email addresses.

    Using our homegrown tools to investigate the threat, we uncovered these findings:

    Continue reading

    Trusted by
    the smartest
    companies

    Try our WhoisXML API for free

    Get started

    Have questions?

    We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

    Message sent!

    We'll contact you shortly.

    Oops!

    Something went wrong. Contact us via regular email.