Research Center

Access our latest research and insights on WHOIS, IP, and DNS data for cybersecurity, data science, and other business purposes through our webinars, podcasts, white papers, threat reports, and videos from the Academy.

Have questions?

Threat Reports

A Deep Dive into the GreedyBear Attack

The GreedyBear crypto theft campaign actors have already reportedly amassed more than US$1 million. According to Koi Security, the attackers used 150 weaponized Firefox extensions, close to 500 malicious executables, and dozens of phishing sites.

The company identified 18 domains as indicators of compromise (IoCs).1 WhoisXML API dove deeper into the attack in a bid to uncover more information and new artifacts. Our in-depth analysis of the IoCs led to these discoveries:

Continue reading

Into the Deep DNS Sea with the JSCEAL Campaign

Check Point Research (CPR) reported on the JSCEAL campaign targeting crypto app users.1 The threat actors used malicious ads to trick victims into installing fake versions of nearly 50 of the most popular crypto trading apps. In the first half of 2025 alone, they released around 35,000 malicious ads that have been viewed at least a few million times in the European Union (EU) alone. The apps the users downloaded were, of course, masked variants of JSCEAL.

Continue reading

Spilling the Beans on Multiplatform Cryptominer Soco404

Wiz analyzed the Soco404 campaign that exploited cloud environment vulnerabilities and misconfigurations to deploy cryptominers.1 Soco404 payloads were embedded in fake 404 HTML pages hosted on websites built using Google Sites. Note, however, that Google has taken down the sites since they were reported.

The researchers identified nine domains as indicators of compromise (IoCs), which WhoisXML API further analyzed. Our deep dive led to these discoveries:

Continue reading

RomCom and TransferLoader IoCs in the Spotlight

Proofpoint’s “10 Things I Hate about Attribution: RomCom vs. TransferLoader”1 detailed connections between RomCom and TransferLoader. WhoisXML API further analyzed the campaign infrastructures, specifically the domains used in the attacks, to spot even more similarities and uncover new artifacts in a two-part investigation.

The first part covers our search for typosquatting domain groups (with an IoC and look-alike domains) and unraveling similarities. We found:

Continue reading

Top 10 Malware of Q2 2025: A Deep Dive into the IoCs

The Center for Internet Security (CIS) Cyber Threat Intelligence (CTI) Team recently published “Top 10 Malware Q2 2025”1 that not only listed the malware families that took centerstage during the quarter but also their corresponding indicators of compromise (IoCs).

The report identified 62 IoCs for nine of the malware comprising 53 domains and nine IP addresses.

Our in-depth analysis of the current IoCs led to these discoveries:

Continue reading

A DNS Exploration of the Latest Educated Manticore Attack

The Iranian threat group Educated Manticore recently launched a spearphishing attack targeting Israeli journalists, high-profile cybersecurity experts, and computer science professors from leading Israeli universities.

Victims who engaged with the attackers were led to fake Gmail login pages or Google Meet invitations. And the credentials they entered on phishing pages? These were sent to the attackers, letting them intercept passwords and 2FA codes and gain unauthorized access to their accounts.

Check Point Research identified 141 IoCs in their report.1 We analyzed these in greater depth and uncovered:

Continue reading

Beneath the Belly of the Latest BlueNoroff Attack: A DNS Investigation

The latest BlueNorroff attack used a malicious Zoom extension in the guise of a Calendly meeting invite from a supposed contact sent via Telegram. Instead of a Google Meet page as the link hinted, however, users ended up on a threat actor-controlled fake Zoom domain. That triggered the download of a malicious AppleScript whose final payload was the malware, a keylogger.1

The researchers identified four domains and three URLs as indicators of compromise (IoCs). We derived seven domains from the IoCs for further analysis. Our bid to uncover more potentially connected artifacts, led to the discovery of:

Continue reading

Trusted by
the smartest
companies

Try our WhoisXML API for free

Get started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.