Provide current and historical ownership information on domains / IPs. Identify all connections between domains, registrants, registrars, and DNS servers.
Additions made to the Cybersecurity & Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog1 on 9 June 2025 CVE-2025-324332 and CVE-2024-420093 were reportedly abused by APT28 to hack government webmail servers4 in an operation dubbed “RoundPress.”
WhoisXML API expanded the list of 19 indicators of compromise (IoCs)5 ESET researchers identified related to Operation RoundPress to uncover more potentially connected artifacts. Our analysis led to the discovery of: