Research Center

Access our latest research and insights on WHOIS, IP, and DNS data for cybersecurity, data science, and other business purposes through our webinars, podcasts, white papers, threat reports, and videos from the Academy.

Have questions?

Threat Reports

Rounding Up DNS Facts about Operation RoundPress

Additions made to the Cybersecurity & Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog1 on 9 June 2025 CVE-2025-324332 and CVE-2024-420093 were reportedly abused by APT28 to hack government webmail servers4 in an operation dubbed “RoundPress.”

WhoisXML API expanded the list of 19 indicators of compromise (IoCs)5 ESET researchers identified related to Operation RoundPress to uncover more potentially connected artifacts. Our analysis led to the discovery of:

Continue reading

Baring the DNS Traces of the Slow Pisces Attack on Cryptocurrency Developers

Slow Pisces gained renown for stealing billions of dollars from the cryptocurrency sector in various countries since 2023. It is up to no good again as it recently trailed its sights on cryptocurrency developers, engaging with them on LinkedIn in their 2025 campaign.1

Palo Alto Unit 42 reported on the attack and identified 54 indicators of compromise (IoCs) in the process. WhoisXML API expanded the current list of IoCs and uncovered other potentially connected artifacts comprising:

Continue reading

Uncovering the DNS Underbelly of UNC5174: The Shift from SNOWLIGHT to VShell

Chinese-sponsored group UNC5174, known for using the open-source reverse shell tool SUPERSHELL, struck again. At the start of 2025, they used a new open-source tool and command-and-control (C&C) infrastructure dubbed “SNOWLIGHT.” In this attack, they began using another tool dubbed “VShell.”

Sysdig disclosed their findings about UNC5174’s latest campaign, including 25 indicators of compromise (IoCs) comprising 13 domains and 12 IP addresses. WhoisXML API expanded the current list of IoCs, which led to the discovery of these new artifacts:

Continue reading

Down the DNS Funnel and into the Funnull Infrastructure

The Federal Bureau of Investigation (FBI) issued a FLASH report to disseminate indicators of compromise (IoCs) related to Funnull.1 Threat actors used them to manage cryptocurrency investment fraud scams between October 2023 and April 2025. The report provided links to two lists.2, 3

WhoisXML API analyzed the threat in two parts. First, we looked at the 277,779 domains using several of our tools, which allowed us to gather these findings:

Continue reading

Framing the AkiraBot Framework Under the DNS Lens

SentinelLABS recently discovered the AkiraBot framework that threat actors crafted to spam website chats and contact forms to users. All that to promote a low-quality search engine optimization (SEO) service since September 2024. The bot uses OpenAI to generate custom outreach messages matching the target sites’ purpose.1

The researchers identified 34 domains as AkiraBot indicators of compromise (IoCs). WhoisXML API expanded the list through a DNS deep dive and, in the process, uncovered:

Continue reading

Shining the DNS Spotlight on Lumma Stealer

On 19 May 2025, the U.S. Department of Justice seized 114 domains connected to a major information-stealing campaign utilizing Lumma Stealer.1 The Cybersecurity and Infrastructure Security Agency (CISA) published the list of indicators of compromise (IoCs) on the same date.2

WhoisXML API analyzed the IoCs in great depth to uncover more artifacts and other information. Take a look at a summary of our findings below.

Continue reading

A DNS Examination of the Phishing Campaign Targeting Japanese Brokerage Firms

Yahoo! News Japan reported about tons of cases of securities account hijacking in May 2025.1 Cybercriminals were said to have sold stocks without their rightful owners’ permission. And between January and April 2025, more than 3,500 fraudulent transactions have already been recorded. Worse? Affected stock owners have already lost ¥300+ billion.

A report on the possible tool used to phish the stock owners identified seven domains as indicators of compromise (IoCs). We used this data, along with other information from various reports on similar phishing campaigns to identify more connected artifacts and other pertinent information.

Continue reading

A DNS Deep Dive into the LabHost PhaaS Infrastructure

The Federal Bureau of Investigation (FBI) warned the public about the LabHost phishing-as-a-service (PhaaS) campaign that threatened the security of users worldwide.1 They published a massive list of related indicators of compromise (IoCs) that WhoisXML API analyzed in depth through a DNS deep dive.

The FBI identified 42,515 LabHost PhaaS campaign IoCs.2 We analyzed 42,401 domains after excluding duplicates and non-domain entries. To these, we added 1,661 net new typosquatting domains akin to the IoCs on the FBI list. Our investigation of the joint list of 44,062 domains led to these findings and enrichments:

Continue reading

Trusted by
the smartest
companies

Try our WhoisXML API for free

Get started

Have questions?

We are here to listen. For a quick response, please select your request type. By submitting a request, you agree to our Terms of Service and Privacy Policy.

Message sent!

We'll contact you shortly.

Oops!

Something went wrong. Contact us via regular email.