Research Center

Access our latest research and insights on WHOIS, IP, and DNS data for cybersecurity, data science, and other business purposes through our webinars, podcasts, white papers, threat reports, and videos from the Academy.

Have questions?

Threat Reports

COLDRIVER’s MAYBEROBOT in the DNS Spotlight

The Google Threat Intelligence Group (GTIG) recently analyzed the evolution of Russia-affiliated threat group COLDRIVER’s homegrown malware NOROBOT. The tool has been redesigned into YESROBOT and now into MAYBEROBOT.1

GTIG identified 14 indicators of compromise (IoCs) comprising 13 domains and one IP address related to the threat. WhoisXML API dove deeper into the IoCs and uncovered these findings:

Continue reading

Burrowing into the Beamglea Campaign DNS Infrastructure

Recently, researchers uncovered 175 malicious npm packages related to the widespread Beamglea phishing campaign. The threat actors targeted more than 135 industrial, technology, and energy companies worldwide. In addition, as of 9 October 2025, the packages have been downloaded more than 26,000 times.

Sixteen indicators of compromise (IoCs) comprising four subdomains, three domains, and nine email addresses were identified. We dove deeper into them. Our analysis revealed these findings:

Continue reading

Chasing After RacoonO365 IoCs Using DNS and Domain Intelligence

In September 2025, Cloudflare and Microsoft jointly disrupted RaccoonO365, a Phishing-as-a-Service (PhaaS) operation that had enabled cybercriminals to steal over 5,000 user credentials worldwide. Despite the takedown, traces of the infrastructure remain scattered across the internet.

In its threat brief, Cloudflare1 listed numerous indicators of compromise (IoCs), including three cryptocurrency addresses, 21 subdomains, and 77 domain names. 

Our research team analyzed the domains tagged as IoCs, leading to the discovery of:

Continue reading

Spelunking into SVG Phishing: Amatera Stealer and PureMiner DNS Deep Dive

Phishing emails with image file attachments are not novel. But the images usually come as PNG or JPEG/JPG files. This time around, though, attackers laced SVG files with Amatera Stealer and/or PureMiner that took remote control of victims’ devices to collect sensitive information, hijack computing resources, and deliver additional malware.

FortiGuard Labs identified 26 IoCs comprising 25 domains and one IP address connected to the threat. Further investigation of the IoCs led to these discoveries:

Continue reading

Scouring the DNS for Traces of the Hiddengh0st and Winos SEO Poisoning Campaign

The recent Hiddengh0st and Winos search engine optimization (SEO) poisoning campaign targeted Chinese-speaking users. The attackers manipulated search rankings with SEO plug-ins and registered look-alike domains that closely mimicked legitimate software sites.

Fortinet identified 13 indicators of compromise (IoCs).1 We analyzed eight IoCs—five domains and four IP addresses, and discovered:

Continue reading

Thumbing through the DNS Trail of the TAOTH Campaign

Trend Micro analyzed what they dubbed as the “TAOTH Campaign,” which primarily targeted users across Eastern Asia. The attackers used fake software update, cloud storage, and login pages to distribute malware and collect sensitive information.

We analyzed eight indicators of compromise (IoCs)—three domains and five IP addresses—from the list Trend Micro compiled. Our deep dive led to these discoveries:

Continue reading

Deep Dive: 3 Lazarus RATs Caught in Our DNS Trap

Fox-IT and the NCC Group investigated a Lazarus subgroup linked to AppleJeus, Citrine Sleet, UNC47363, and Gleaming Pisces and uses different remote access Trojans (RATs) known as “PondRAT5,” “ThemeForestRAT,” and “RemotePE.”

The researchers specifically analyzed the three RATs in great depth and identified 19 domains and two IP addresses as indicators of compromise (IoCs) in the process.

Continue reading

Cross-Examining the CAPTCHAgeddon Brought on by ClickFix

Guardio analyzed the ClickFix stealer, an evolved version of fake browser updates. It used fake CAPTCHA pages that enabled it to evade detection and beat popular anti-bot solutions. As a result, it exfiltrated victims’ account credentials and other data from their computers.

The company identified 172 indicators of compromise (IoCs) comprising 156 domains and 16 IP addresses.1

WhoisXML API analyzed the IoCs further. Our deep dive led to these discoveries:

Continue reading

Trusted by
the smartest
companies

Try our WhoisXML API for free

Get started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.