Research Center

Access our latest research and insights on WHOIS, IP, and DNS data for cybersecurity, data science, and other business purposes through our webinars, podcasts, white papers, threat reports, and videos from the Academy.

Have questions?

Threat Reports

DNS Spotlight: The Silver Fox in the Henhouse

Disguised as Russian threat actors, Chinese APT group Silver Fox managed to infiltrate well-protected targets. They used Cyrillic characters in their SEO poisoning campaign lures that deployed ValleyRAT1 into target networks.

Silver Fox abused Microsoft Teams to install ValleyRAT into victims’ systems to conduct state-sponsored espionage for sensitive intelligence and engage in financial fraud and theft to fund their operations.2

ReliaQuest originally identified 41 IoCs comprising six domains, 17 subdomains, and 18 IP addresses after analyzing the cyber attack in great depth. We investigated the Silver Fox infrastructure further and jumping off 55 IoCs in total unearthed these discoveries:

Continue reading

An In-Depth Analysis of the Ashen Lepus AshTag-Enabled Attack

Palo Alto Networks’ Unit 42 has been tracking and monitoring Ashen Lepus’s cyber espionage campaign that leverages a new malware suite they dubbed “AshTag.” The researchers witnessed a tangible evolution in the group’s operational security and TTPs.

Unit 42 identified 12 subdomains as IoCs.1 Upon further scrutiny, we extracted 10 unique domains from the subdomains, bringing the total of IoCs for our in-depth analysis to 22.

Our investigation of the 22 AshTag IoCs led to these discoveries:

Continue reading

Illuminating ShadyPanda DNS Infrastructure Facts

ShadyPanda launched a seven-year-long campaign that affected the browsers of 4.3 million Chrome and Edge users to date. The actor’s secret? Some malicious extensions were featured and verified by Google, resulting in instant trust and massive distribution.

Koi Security identified seven IoCs1 comprising four domains and three subdomains. After extracting unique domains from the subdomains, we accumulated six domains and three subdomains for further analysis.

Continue reading

Mining for DNS Maxims: Top 10 Malware of Q3 2025

The Center for Internet Security (CIS) named the top 10 malware of Q3 2025 and identified 31 domains as IoCs for five of them.1 After weeding out legitimate domains from their list with the help of the WhoisXML API MCP Server,2 we were left with 26 domains for our study. Our in-depth analysis of the IoCs for SocGholish, Agent Tesla, ZPHP, Gh0st, and Lumma Stealer led to these discoveries:

Continue reading

Thumbing through the DNS Traces of TamperedChef

TamperedChef, a massive malvertising campaign, leveraged apps users commonly installed on their computers. Potential victims were tricked into downloading malicious scripts via clever social engineering ruses. Infections could lead to establishing and selling remote access for profit, stealing and monetizing sensitive credentials and healthcare data, preparing compromised systems for future ransomware deployment, and engaging in opportunistic espionage by exploiting access to high-value targets.

The Acronis TRU identified 58 IoCs comprising URLs and subdomains.1 We extracted 58 unique domains from them and weeded out those that were legitimate. We were left with 46 domains for further analysis. Our in-depth investigation led to these discoveries:

Continue reading

Predicting ValleyRAT: Early Detection with First Watch

ValleyRAT is a multi-stage Remote Access Trojan (RAT) that primarily targets Chinese-speaking users and enterprises through coordinated phishing campaigns designed to gain complete control over infected systems and deploy additional malware. ValleyRAT was first discovered by Proofpoint researchers in 2023 and has since been observed in various campaigns.

According to research by Morphisec Threat Labs, the malware is distributed via malicious emails and websites. It comes disguised as legitimate software, such as Google Chrome, or as Microsoft Office documents. These files deliver a multi-component loader designed to bypass security measures.

DNS Spotlight: New MITRE ATT&CK Group Entrants as of October 2025

Nine new groups were listed on the MITRE ATT&CK October 2025 Updates1 page under three categories—Enterprise, Mobile, and ICS. We collated a list of 144 IoCs comprising 108 domains, 31 IP addresses, and five email addresses after filtering out legitimate domains from sources MITRE listed for each group.

We analyzed the 144 IoCs and the results revealed:

Continue reading

Going DNS Deep Diving into GhostCall and GhostHire

BlueNoroff struck again, this time with interrelated campaigns GhostCall and GhostHire.1 The actors went after tech company execs, venture capitalists, and Web3 developers, stealing personal information and other well-kept secrets.

Securelist identified 39 domains as IoCs, which we further analyzed. Our investigation led to these findings:

Continue reading

Trusted by
the smartest
companies

Try our WhoisXML API for free

Get started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.