Threat Trends Digest – July 2026

Welcome to the Threat Trends Digest, a monthly view of real-world threat patterns.

This report compiles data from the previous month using Malware Patrol’s global telemetry and live attack observations to surface key stats on malware, phishing, ransomware, C2s, and domain generation algorithms (DGAs). You’ll find insights into the most exploited TLDs, frequently seen malware hashes and IPs, and other critical indicators. Use this digest to keep a close pulse on attacker behavior, uncover shifting patterns, and better align your defenses with the latest threat activity.

For more articles, check out our #onpatrol4malware blog.

?

IOCs

Malicious IPs

IP Source Country
106.41.200.151 CHINANET HUNAN PROVINCE NETWORK CN
74.115.51.8 Weebly, Inc. US
74.115.51.9 Weebly, Inc. US
213.186.33.19 OVH SAS FR
77.65.212.167 PROGRESO.PL SP Z O.O PL
185.118.115.89 Dream Fusion – IT Services, Lda PT
70.40.210.164 Unified Layer US
27.254.33.92 CSLOXINFO-IDC TH
162.214.80.24 Unified Layer US
62.60.226.198 FEMO IT SOLUTIONS LIMITED DE
51.38.54.48 OVH SAS FR
95.173.180.73 Netinternet Bilisim Teknolojileri AS TR
213.186.33.17 OVH SAS FR
66.116.205.44 P.D.R Solutions FZC IN
213.186.33.87 OVH SAS FR
64.37.63.18 HostDime.com, Inc. US
188.241.222.214 Awesome Projects S.R.L. RO
97.74.93.253 GoDaddy.com, LLC SG
77.75.22.2 SysUP IT GmbH & Co KG AT
51.91.153.81 OVH SAS FR

Attacking IPs

IP Source (ISP/ASN) Country
103.161.34.10 GSJZ(CHINA)TECHNOLOGY CO.,LIMITED t/a Guosheng IDC lease NL
176.65.131.18 ZeXoTeK IT-Services GmbH NL
176.65.131.19 ZeXoTeK IT-Services GmbH NL
103.161.34.44 GSJZ(CHINA)TECHNOLOGY CO.,LIMITED t/a Guosheng IDC lease NL
103.161.35.72 GSJZ(CHINA)TECHNOLOGY CO.,LIMITED t/a Guosheng IDC lease NL
95.174.113.63 Consumer Internet Cooperative PG-19 RU
204.76.203.84 Intelligence Hosting LLC NL
204.76.203.2 Intelligence Hosting LLC NL
78.41.139.200 HOSTSHIELD LTD NL
45.156.87.223 TechTies Inc. NL
20.198.176.220 Microsoft Corporation SG
45.153.34.104 TechTies Inc. NL
45.153.34.106 TechTies Inc. NL
162.251.238.24 VegasNAP, LLC US
38.45.71.191 Cogent Communications, LLC US
192.129.220.186 RackNerd LLC US
181.214.99.234 Unesty Company DE
162.248.102.46 GALAXYGATE, LLC US
15.204.132.78 OVH SAS US
192.210.181.100 RackNerd LLC US

Malware Hashes

Hash (MD5) VT Detections Classification
5dcbf5399e5c9c238a6c467591bd7599 5/60 trojan.encodedpe/msil
471309df0f07c6b122a1715f6f5403ab 6/61 trojan.encodedpe/lausivloader
893a214bc719df8b3141cab10513566a 14/63 adware.polarwind/xzzmo
2b54972e8a3fc86e480c95aacd80ae9a 14/61 fragtor
8bdd2cdd39b2ad7b679faa50f629ce2b 29/62 phishing.akgpp/malurl
1f20cc44056395c837cf9a7211b09c04 29/63 trojan.usblgq26/abmrisk
246ff7da8826a2cab11f5013000b0b83 35/64 trojan.gelesz/runner
9256ec6a350db5344bad23866fe2c1e9 41/66 trojan.geluasz/usblev26
59ce0baba11893f90527fc951ac69912 42/61 trojan.mirai/mozi
b24c8affd984bc47b7a6c5bd11e58b16 43/63 trojan.tsunami/kaiten
dbc520ea1518748fec9fcfcf29755c30 45/62 trojan.mirai/ddos
fbe51695e97a45dc61967dc3241a37dc 47/62 trojan.mirai/mozi
c0fd19c0e4a252efb1864b267fb154ae 53/70 adware.ababsoftware/downloadasist
a73ddd6ec22462db955439f665cad4e6 49/62 trojan.mirai/mozi
796c596185e63803a4ec4003aa60f425 54/68 adware.qjwmonkey/bundler
3849f30b51a5c49e8d1546960cc206c7 50/62 trojan.mirai/mozi
5dfc3eefe1c51312d0020910020c4025 55/67 adware.qjwmonkey/nezchi
31549917cdc6e3f9d40a48ea5998493f 56/67 adware.qjwmonkey/dangeroussig
eec5c6c219535fba3a0492ea8118b397 53/63 trojan.mirai/mozi
96dd80012c33291e1621b66f5bd66967 61/69 adware.qjwmonkey/bundler

To learn more about how we collect, analyze, and deliver actionable threat intelligence, explore our Threat Intelligence Services. If you’re interested in running your own queries – whether for threat actors, CVEs, infrastructure, or emerging activity – see how our MCP Server helps turn intelligence into practical security insight. Both are designed to support real-world analysis, investigation, and decision-making.

Take advantage of our free threat intel trial.

?

Threat Trends Digest – June 2026

?

Welcome to the Threat Trends Digest, a monthly view of real-world threat patterns.

This report compiles data from the previous month using Malware Patrol’s global telemetry and live attack observations to surface key stats on malware, phishing, ransomware, C2s, and domain generation algorithms (DGAs). You’ll find insights into the most exploited TLDs, frequently seen malware hashes and IPs, and other critical indicators. Use this digest to keep a close pulse on attacker behavior, uncover shifting patterns, and better align your defenses with the latest threat activity.

For more articles, check out our #onpatrol4malware blog.

??

IOCs

Malicious IPs

IP Source (ISP) Country
213.186.33.87 OVH SAS FR
43.242.37.17 YOTTA NETWORK SERVICES PRIVATE LIMITED IN
188.241.222.214 Awesome Projects S.R.L. RO
96.125.172.210 Network Solutions, LLC US
109.234.166.59 O2SWITCH SAS FR
70.40.210.164 Unified Layer US
64.37.63.18 HostDime.com, Inc. US
154.0.169.106 AFRIHOST SP (PTY) LTD ZA
185.118.115.89 Dream Fusion – IT Services, Lda PT
213.186.33.19 OVH SAS FR
213.186.33.4 OVH SAS FR
104.21.89.111 Cloudflare, Inc. US
74.115.51.9 Weebly, Inc. US
77.65.212.167 PROGRESO.PL SP Z O.O PL
64.40.13.26 GLOBALHOSTINGSOLUTIONS INC US
106.41.200.151 CHINANET HUNAN PROVINCE NETWORK CN
185.199.110.133 GitHub, Inc. US
185.199.109.133 GitHub, Inc. US
185.199.108.133 GitHub, Inc. US
185.199.111.133 GitHub, Inc. US

Attacking IPs

IP Source (ISP/ASN) Country
213.199.50.203 Contabo GmbH FR
167.86.103.106 Contabo GmbH FR
78.41.139.200 HOSTSHIELD LTD NL
167.86.95.106 Contabo GmbH FR
207.180.236.132 Contabo GmbH FR
38.242.151.30 Contabo GmbH FR
213.199.49.171 Contabo GmbH FR
161.97.91.253 Contabo GmbH FR
213.199.49.105 Contabo GmbH FR
173.212.226.152 Contabo GmbH FR
161.97.92.64 Contabo GmbH FR
161.97.91.150 Contabo GmbH FR
84.247.184.190 Contabo GmbH FR
84.247.185.83 Contabo GmbH FR
80.75.212.112 Ferdinand Zink trading as Tube-Hosting DE
103.161.34.44 GSJZ(CHINA)TECHNOLOGY CO.,LIMITED t/a Guosheng IDC lease NL
176.65.131.19 ZeXoTeK IT-Services GmbH NL
130.12.183.13 Netiface LLC DE
176.65.131.18 ZeXoTeK IT-Services GmbH NL
103.161.34.10 GSJZ(CHINA)TECHNOLOGY CO.,LIMITED t/a Guosheng IDC lease NL

Malware Hashes

Hash VirusTotal Detections VirusTotal Label
31549917cdc6e3f9d40a48ea5998493f 56/67 adware.qjwmonkey/dangeroussig
8bdd2cdd39b2ad7b679faa50f629ce2b 29/62 phishing.akgpp/malurl
59ce0baba11893f90527fc951ac69912 42/61 trojan.mirai/mozi
3849f30b51a5c49e8d1546960cc206c7 50/62 trojan.mirai/mozi
eec5c6c219535fba3a0492ea8118b397 53/63 trojan.mirai/mozi
a73ddd6ec22462db955439f665cad4e6 49/62 trojan.mirai/mozi
796c596185e63803a4ec4003aa60f425 54/68 adware.qjwmonkey/bundler
c0fd19c0e4a252efb1864b267fb154ae 53/70 adware.ababsoftware/downloadasist
96dd80012c33291e1621b66f5bd66967 61/69 adware.qjwmonkey/bundler
fbe51695e97a45dc61967dc3241a37dc 47/62 trojan.mirai/mozi
724f25e7f93eae0ae54a80142e11b7ef 38/62 trojan.sshdoor/abtrojan
4cbfce17e2733c3926997aab98c20b8f 27/60 trojan.grhe/msil
5377e8f2ebdb280216c37a6195da9d6c 47/62 trojan.hajime/mirai
cb7569803c981f18d9e0756f0032b81d 11/60 trojan.agentb/remcos
936b35bfee8232f437bf6b46e88401dd 39/61 trojan.sshdoor/sshdkit
c3f53808a624b526d51356430923f9c6 4/61 trojan.encodedpe/packed2
dbc520ea1518748fec9fcfcf29755c30 45/62 trojan.mirai/ddos
f7459bc26baf2db287c39770f6a1e19c 35/63 trojan.mirai/awtg
9b6c3518a91d23ed77504b5416bfb5b3 49/63 trojan.hajime/mirai
b5b87f87c084115b7a57898dc54a6888 20/60 trojan.grhd/msil

To learn more about how we collect, analyze, and deliver actionable threat intelligence, explore our Threat Intelligence Services. If you’re interested in running your own queries – whether for threat actors, CVEs, infrastructure, or emerging activity – see how our MCP Server helps turn intelligence into practical security insight. Both are designed to support real-world analysis, investigation, and decision-making.

Take advantage of our free threat intel trial.

?

FIFA World Cup 2026: What We’re Seeing in Emerging Domain Activity

Major sporting events have long attracted cybercriminal activity, and the 2026 FIFA World Cup is no exception. Throughout the lead-up to the tournament, we have observed a growing number of FIFA- and World Cup-themed domains associated with betting operations, fake streaming services and apps, credential theft, and other forms of brand abuse. Public reporting has likewise documented concerns around ticket and merchandise scams, fraudulent hospitality offers, and phishing campaigns targeting fans and travelers.

The domains highlighted in this research were identified through our Emergent Threats feed, which aggregates intelligence from multiple sources, including newly registered domains, newly observed domains, certificate issuance activity, and other early-warning indicators. This allows defenders to identify potentially malicious infrastructure as it emerges, often before it becomes widely recognized or actively weaponized.

With the tournament soon underway, organizations should expect continued abuse of FIFA branding and related event infrastructure. Security teams should monitor for World Cup-themed domains, particularly those leveraging ticketing, hospitality, streaming, betting, and account-related lures.

Official FIFA World Cup Infrastructure

One of the simplest ways to reduce risk is to maintain an allowlist of known legitimate FIFA and World Cup-related infrastructure. While organizations should always validate domains independently and avoid overly broad allowlisting practices, the domains below represent official FIFA properties, tournament resources, hospitality platforms, and host-city websites associated with the 2026 FIFA World Cup.

These domains can serve as a useful baseline when reviewing newly registered domains, investigating user reports, tuning detections, or identifying suspicious lookalike registrations. Domains that closely mimic these properties, particularly those containing terms such as “official,” “tickets,” “hospitality,” “login,” “vip,” or host-city names, should be reviewed carefully for potential phishing, fraud, or brand-abuse activity.

FIFA

  • fifa.com
  • www.fifa.com

Official World Cup Pages

  • fifa.com/en/tournaments/mens/worldcup/canadamexicousa2026
  • fifa.com/en/tournaments/mens/worldcup
  • fifa.com/tickets
  • fifa.com/en/tournaments/mens/worldcup/canadamexicousa2026/articles/resale-ticket-exchange-marketplace (Ticket Resale/Exchange Marketplace)
  • fifa.com/hospitality

Host Cities

  • atlantafwc26.com
  • bostonfwc26.com
  • dallasfwc26.com
  • houstonfwc26.com
  • kansascityfwc26.com
  • losangelesfwc26.com
  • miamifwc26.com
  • nynjfwc26.com
  • philadelphiasoccer2026.com
  • bayareahostcommittee.com
  • seattlefwc26.org
  • vancouverfwc26.ca
  • torontofwc26.ca

Hospitality

  • fifaworldcup26.suites.fifa.com

 

What We’re Seeing

Analysis of World Cup-themed domains reveals several recurring categories:

  • Betting and gambling sites using FIFA and World Cup branding to promote sportsbooks, casinos, odds platforms, and wagering services.
  • Credential theft and phishing portals incorporating keywords such as “login,” “register,” “official,” and “account.”
  • Fake streaming and live broadcast sites leveraging terms such as “tv,” “live,” “zhibo,” and “kanqiu.”
  • General FIFA brand abuse designed to capture search traffic, impersonate official services, or redirect users to unrelated content.

Common Domain Patterns

Many suspicious domains appear to be generated from templates, combining FIFA-related keywords with generic modifiers, geographic identifiers, betting terms, or randomly generated strings.

Examples include:

fifa + worldcup + tickets
fifa + official + login
fifa + live + tv
fifa + 2026 + bet
fifa + host city + hotels

Security teams should also watch for clusters of similarly named domains, sequential registrations, domains hosted on free platforms such as Pages.dev, and domains combining FIFA branding with local language terms for betting, streaming, or sports content.

Useful hunting patterns for newly registered and newly observed domains can be found below in the Hunting/Regex section.

Download the Dataset

To assist defenders, we analyzed and categorized thousands of FIFA- and World Cup-themed domains identified through our Emergent Threats feed. Unlike traditional newly registered domain datasets, this feed combines multiple early-warning sources, including newly registered domains, newly observed domains, certificate issuance activity, and other indicators of emerging infrastructure.

The resulting data includes domains categorized as betting, streaming, phishing risk, Club World Cup, and general World Cup brand abuse. Organizations can use this data as a practical starting point for detection engineering, threat hunting, enrichment, and proactive monitoring.

Download the categorized domain list here.

 

Hunting/Regex

General
(?i)(?=.*(fifa|worldcup|world-cup|fwc26|fifawc|wc2026|copa[-_.]?mundial|mundial2026|shijiebei))(?=.*(ticket|tickets|hospitality|vip|login|register|official|tv|live|stream|bet|odds|casino|slot|togel|apk|download|hotel|travel|boletos|entradas|zhibo|kanqiu|h5|wap|app))
False Positive Suppression
(?i)(afifa|khafifa|hafifa|amalfifa|fifabric|fifamily|fifashion|defifa|fifarm|hififa|ififa)
Core FIFA / World Cup seed terms
(?i)(^|[-_.])(fifa|fwc26|fifawc|fifawcup|wc2026|worldcup|world-cup|fifaworldcup)([-_.]|$)
FIFA + 2026 permutations
(?i)(fifa[-_.]?(2026|26)|(2026|26)[-_.]?fifa|fwc[-_.]?26|wc[-_.]?2026)
World Cup 2026 permutations
(?i)(world[-_.]?cup[-_.]?(2026|26)|(2026|26)[-_.]?world[-_.]?cup|fifa[-_.]?world[-_.]?cup[-_.]?(2026|26))
Fake official / portal lures
(?i)(fifa|worldcup|fwc26|wc2026).*(official|offical|portal|account|login|signin|register|verify|auth|admin|secure|access)
Ticketing / hospitality / travel
(?i)(fifa|worldcup|fwc26|wc2026).*(ticket|tickets|resale|refund|hospitality|vip|suite|pass|entry|hotel|hotels|lodging|apartment|travel|parking|transport|limo)
Streaming / live scores
(?i)(fifa|worldcup|fwc26|wc2026).*(tv|live|stream|streaming|watch|broadcast|score|scores|schedule|fixture|match|zhibo|kanqiu|tiyu|shijiebei)
Betting / gambling
(?i)(fifa|worldcup|fwc26|wc2026).*(bet|odds|casino|slot|slots|togel|poker|stake|parlay|jackpot|gacor|bola|cuan|rtp|sbobet)
APK / game download lures
(?i)(fifa|worldcup).*(apk|android|download|mobile|app|mod|hack|coin|coins|generator|ultimate[-_.]?team|ppsspp)
Cloudflare Pages / disposable hosting
(?i)^(?=.*(fifa|worldcup|fwc26|wc2026)).*\.pages\.dev$
(?i)(fifa|worldcup|fwc26|wc2026).*\.workers\.dev$
Host-city abuse
(?i)(fifa|worldcup|fwc26|wc2026).*(atlanta|boston|dallas|houston|kansas[-_.]?city|los[-_.]?angeles|miami|new[-_.]?york|nyc|new[-_.]?jersey|philadelphia|philly|seattle|vancouver|toronto|guadalajara|monterrey|mexico[-_.]?city|cdmx)
Spanish/Mexico-focused terms
(?i)(fifa|worldcup|mundial|copa[-_.]?mundial).*(boleto|boletos|entrada|entradas|hotel|viaje|vip|transmision|en[-_.]?vivo|apuesta|apuestas)
Chinese-language targeting
(?i)(fifa|worldcup|shijiebei|???).*(zhibo|kanqiu|tiyu|saicheng|yuce|jingcai|touzhu|maiqiu|zh|zhcn|zhs|h5|wap)
High-volume generated campaign pattern
(?i)^(cn|ch|hk|jp|kr|th|us|global|intl|official|m|h5|wap|web|app|live|tv|score|login|register)[-_.].*(fifa|worldcup|fifawc|cwcfifa|wc2026)
Numbered / template-generated domains
(?i)(fifa|worldcup|fwc26|wc2026).*[0-9]{2,4}
(?i)(fifa|worldcup|fwc26|wc2026).*(88|888|999|234|777|138|168|303|365|789)
Club World Cup overlap
(?i)(fifa|cwc|club[-_.]?world[-_.]?cup|fcwc).*(2025|2026|ticket|tv|live|bet|official|app|login)
“Official” Impersonation Cluster
(?i)(official|offical|auth|verify|portal|secure|account|login).*(fifa|worldcup)
H5 / WAP Pattern
This is extremely common in Asian-focused campaigns.
(?i)(^h5-|^wap-|^m-|mobile|app).*(fifa|worldcup)
Country/Language Prefix Campaigns
(?i)^(cn|ch|hk|jp|kr|th|tw|vn|sg|id)[-_.]
combined with:
(?i)(fifa|worldcup|fifawc|wc2026)
Number-Based Gambling Naming
(?i)(fifa|worldcup).*(88|888|168|365|777|789|123|138|303)
High-Abuse TLDs
.cfd
.click
.xyz
.pw
.cam
.fun
.space
.shop

Free subdomain providers
(?i)(fifa|worldcup).*\.(uk|us|sa|za|ru)\.com$

?

How big are your threat data gaps?

See for yourself.

?

Threat Trends Digest – May 2026

?????

Welcome to the Threat Trends Digest, a monthly view of real-world threat patterns.

This report compiles data from the previous month using Malware Patrol’s global telemetry and live attack observations to surface key stats on malware, phishing, ransomware, C2s, and domain generation algorithms (DGAs). You’ll find insights into the most exploited TLDs, frequently seen malware hashes and IPs, and other critical indicators. Use this digest to keep a close pulse on attacker behavior, uncover shifting patterns, and better align your defenses with the latest threat activity.

For more articles, check out our #onpatrol4malware blog.

??

IOCs

Top Malicious IPs

IP

Source (ISP/ASN)

106.41.200.151 ChinaNet Hunan Province Network / AS4134
140.82.116.4 Github IP
185.199.111.133 Github IP
185.199.109.133 Github IP
70.40.210.164 VPN/Data Center IP
206.72.194.50 VPN/Data Center IP
74.115.51.8 Weebly Inc. / AS27647
74.115.51.9 Weebly Inc. / AS27647
64.40.13.26 GlobalHostingSolutions Inc  / AS395512
77.65.212.167 Progreso.pl SP Z O.O / AS210379
87.98.239.3 VPN/Data Center IP
162.214.80.24 VPN/Data Center IP
64.37.63.18 VPN/Data Center IP
104.18.43.151 Cloudflare IP Range
213.186.33.19 VPN/Data Center IP
160.22.122.114 Ionsite Software One Member Co Ltd / AS135918
217.182.30.109 VPN/Data Center IP
5.223.56.39 VPN/Data Center IP
188.241.222.214 Awesome Projects S.R.L. / AS5606
43.231.112.25 Apartment # 34, 2nd khoroo / AS63962
Summary
  • Malicious infrastructure is heavily concentrated in hosting, cloud, VPN, and proxy networks, with approximately 40–45% of the IPs originating from VPN/data center providers. This is consistent with infrastructure commonly used to host:
    • Malware payloads / Ransomware staging servers / Phishing kits / C2 systems / Cryptomining operations / DGA-related infrastructure
  • Several IPs originate from major cloud and developer platforms, including GitHub and Cloudflare, highlighting a common adversary tactic of abusing trusted services to distribute malware, host malicious content, or conceal attacker infrastructure behind reputable providers.
  • Overall, the dataset reinforces a common modern threat trend: attackers increasingly rely on cloud services, VPS providers, VPN networks, and short-lived rented infrastructure to host and rotate malware, phishing, ransomware, and C2 operations while blending into legitimate internet traffic.

Top Attacking IPs

IP

Source (ISP/ASN)

103.161.34.10 Guosheng IDC Lease / AS198584
103.161.35.72 Guosheng IDC Lease / AS198584
80.75.212.112 Tube Hosting / AS49581
176.65.131.18 Zexotek IT-Services GmbH / AS198584
80.75.212.67 Tube Hosting / AS49581
130.12.183.13 Netiface LLC / AS51396
45.153.34.104 VMHeaven.io / AS51396
172.245.75.28 VPN/Data Center IP
103.157.26.137 PT Linkgo Metro Teknologi / AS141107
172.245.75.11 VPN/Data Center IP
162.248.101.69 Galaxygate, LLC / AS397031
51.75.104.160 VPN/Data Center IP
185.119.90.69 United Internet Ltd. / AS207604
173.249.209.8 VPN/Data Center IP
135.148.160.225 VPN/Data Center IP
94.46.187.205 VPN/Data Center IP
185.103.255.38 IP Market – FZCO / AS200740
80.75.212.28 Tube Hosting / AS49581
185.214.10.121 365 Group LLC / AS202602
161.97.91.164 VPN/Data Center IP
 
Summary
  • ~35–40% of the IPs are identifiable VPN or data center addresses, a pattern commonly associated with:
    • Credential stuffing campaigns / SSH brute-force / Automated exploit frameworks / Anonymized attack infrastructure
  • The concentration of hosting-provider IPs strongly suggests largely automated activity, including:
    • Internet-wide scanning / Bot-driven reconnaissance / Credential harvesting attempts / Proxy/VPN-based attacks / Security research scanning / Commodity malware operations
  • Overall, the data reflects opportunistic internet “background noise” and automated threat activity, highlighting the continued prevalence of large-scale reconnaissance and brute-force operations targeting exposed services.

Top Malware Hashes

Hash

VirusTotal Detections

VirusTotal Label

31549917cdc6e3f9d40a48ea5998493f 61/75 adware.qjwmonkey/dangeroussig
59ce0baba11893f90527fc951ac69912 51/75 trojan.mirai/mozi
8bdd2cdd39b2ad7b679faa50f629ce2b 28/75 phishing.akgpp/malurl
3849f30b51a5c49e8d1546960cc206c7 51/75 trojan.mirai/mozi
eec5c6c219535fba3a0492ea8118b397 54/75 trojan.mirai/mozi
a73ddd6ec22462db955439f665cad4e6 51/75 trojan.mirai/mozi
796c596185e63803a4ec4003aa60f425 56/75 adware.qjwmonkey/bundler
c0fd19c0e4a252efb1864b267fb154ae 53/75 adware.ababsoftware/downloadasist
96dd80012c33291e1621b66f5bd66967 62/75 adware.qjwmonkey/bundler
a9438d893c19d866cf720a581c9476bc 65/75 virus.tenga/remoteexec
64eb7ad3aaf9b6639ccc5c0b30b6e59f 58/75 trojan.msil/powershell
fbe51695e97a45dc61967dc3241a37dc 50/75 trojan.mirai/mozi
5dfc3eefe1c51312d0020910020c4025 56/75 adware.qjwmonkey/nezchi
9b6c3518a91d23ed77504b5416bfb5b3 51/75 trojan.hajime/mirai
724f25e7f93eae0ae54a80142e11b7ef 39/75 trojan.sshdoor/abtrojan
5377e8f2ebdb280216c37a6195da9d6c 47/75 trojan.hajime/mirai
9f35fd3bcbc01b097602dbd85d6ecfbb 21/75 trojan.msil/powershell
936b35bfee8232f437bf6b46e88401dd 41/75 trojan.sshdoor/sshdkit
e4f0fc29322640a13934b97c788dd4d5 40/74 trojan.lazy/misc
f7459bc26baf2db287c39770f6a1e19c 34/75 trojan.mirai/awtg

To learn more about how we collect, analyze, and deliver actionable threat intelligence, explore our Threat Intelligence Services. If you’re interested in running your own queries – whether for threat actors, CVEs, infrastructure, or emerging activity – see how our MCP Server helps turn intelligence into practical security insight. Both are designed to support real-world analysis, investigation, and decision-making.

Take advantage of our free threat intel trial.

?

Threat Trends Digest – April 2026

Welcome to the Threat Trends Digest, a monthly view of real-world threat patterns.

This report compiles data from the previous month using Malware Patrol’s global telemetry and live attack observations to surface key stats on malware, phishing, ransomware, C2s, and domain generation algorithms (DGAs). You’ll find insights into the most exploited TLDs, frequently seen malware hashes and IPs, and other critical indicators. Use this digest to keep a close pulse on attacker behavior, uncover shifting patterns, and better align your defenses with the latest threat activity.

For more articles, check out our #onpatrol4malware blog.

?

IOCs

Top Malicious IPs

106.41.200.151
140.82.116.4
140.82.116.3
185.199.111.133
185.199.110.133
185.199.108.133
185.199.109.133
173.205.127.152
23.226.124.131
69.61.56.164
5.189.185.23
104.18.43.151
172.64.144.105
104.37.191.164
37.153.93.10
104.21.16.89
172.67.210.124
74.115.51.8
74.115.51.9
103.11.153.134

Top Attacking IPs

176.65.128.158
103.161.34.10
103.161.34.44
80.75.212.112
80.75.212.67
130.12.183.13
103.161.35.72
146.19.191.54
198.7.114.164
173.249.209.193
85.208.102.58
92.38.176.252
142.171.174.45
31.131.22.122
192.227.178.250
213.199.49.172
161.97.91.253
38.242.150.240
213.199.48.198
188.130.232.75

Top Malware Hashes

Hash VirusTotal Detections VirusTotal Label
31549917cdc6e3f9d40a48ea5998493f 56/70 adware.qjwmonkey
8bdd2cdd39b2ad7b679faa50f629ce2b 28/64 trojan.pdf.phishing.btq
59ce0baba11893f90527fc951ac69912 46/63 trojan.mirai/mozi
eec5c6c219535fba3a0492ea8118b397 52/63 trojan.mirai/mozi
3849f30b51a5c49e8d1546960cc206c7 48/62 trojan.mirai/mozi
a73ddd6ec22462db955439f665cad4e6 47/61 trojan.mirai/mozi
796c596185e63803a4ec4003aa60f425 57/71 adware.qjwmonkey/bundler
96dd80012c33291e1621b66f5bd66967 63/71 adware.qjwmonkey/bundler
c0fd19c0e4a252efb1864b267fb154ae 54/71 adware.ababsoftware/downloadasist
fbe51695e97a45dc61967dc3241a37dc 47/62 trojan.mirai/mozi
9b6c3518a91d23ed77504b5416bfb5b3 50/65 trojan.hajime/mirai
5dfc3eefe1c51312d0020910020c4025 61/72 adware.qjwmonkey/nezchi
c4374912473cd42cfe4e1abab51af40e 14/60 trojan.qwexlafiba
64eb7ad3aaf9b6639ccc5c0b30b6e59f 51/70 trojan.msil/powershell
d8f9a2adeaf9ba290ef88dfaf52c5e12 32/71 pua.drivernavigator/sobrab
5377e8f2ebdb280216c37a6195da9d6c 46/64 trojan.hajime/mirai
a53485b5394ccb5197543e018eda64c0 33/65 trojan.mirai/avyg
dc631d0b479e7f00b54c87ff3d3fba4d 32/67 trojan.
dbc520ea1518748fec9fcfcf29755c30 44/62 trojan.mirai/mozi
3a9349af006440c7e0da677724551239 26/61 trojan.generik

To learn more about how we collect, analyze, and deliver actionable threat intelligence, explore our Threat Intelligence Services. If you’re interested in running your own queries – whether for threat actors, CVEs, infrastructure, or emerging activity – see how our MCP Server helps turn intelligence into practical security insight. Both are designed to support real-world analysis, investigation, and decision-making.

Take advantage of our free threat intel trial.

?

Threat Trends Digest – March 2026

?

Welcome to the Threat Trends Digest, a monthly view of real-world threat patterns.

This report compiles data from the previous month using Malware Patrol’s global telemetry and live attack observations to surface key stats on malware, phishing, ransomware, C2s, and domain generation algorithms (DGAs). You’ll find insights into the most exploited TLDs, frequently seen malware hashes and IPs, and other critical indicators. Use this digest to keep a close pulse on attacker behavior, uncover shifting patterns, and better align your defenses with the latest threat activity.

For more articles, check out our #onpatrol4malware blog.

January Threat Trends
January Threat Trends
January Threat Trends
January Threat Trends
January Threat Trends
??

IOCs

Top Malicious IPs

68.171.213.176
5.189.185.23
198.38.87.214
43.231.112.25
192.95.37.21
64.40.13.26
85.194.202.130
91.213.40.2
213.186.33.19
213.186.33.5
213.186.33.4
162.241.191.17
5.223.56.39
45.56.219.253
83.69.226.16
195.24.68.28
198.20.76.2
173.205.127.152
100.25.96.70
94.125.180.197

Top Malware Hashes

31549917cdc6e3f9d40a48ea5998493f
59ce0baba11893f90527fc951ac69912
8bdd2cdd39b2ad7b679faa50f629ce2b
eec5c6c219535fba3a0492ea8118b397
3849f30b51a5c49e8d1546960cc206c7
a73ddd6ec22462db955439f665cad4e6
be02212ff7f679594d80cfe9ee41e943
fbe51695e97a45dc61967dc3241a37dc
a9438d893c19d866cf720a581c9476bc
796c596185e63803a4ec4003aa60f425
9b6c3518a91d23ed77504b5416bfb5b3
96dd80012c33291e1621b66f5bd66967
dbc520ea1518748fec9fcfcf29755c30
c0fd19c0e4a252efb1864b267fb154ae
c4374912473cd42cfe4e1abab51af40e
5dfc3eefe1c51312d0020910020c4025
221d8352905f2c38b3cb2bd191d630b0
ebbcfb749a959fb53e9fc8b6dc915838
85f8bd82370a634fcb8f5aca3e407395
5a579305a5ed446e5d235fdf055af4df

Top Attacking IPs

176.65.128.158
103.161.34.44
103.161.34.10
95.174.113.63
80.75.212.112
80.75.212.67
130.12.183.13
193.141.60.60
60.251.54.203
176.100.36.20
45.151.123.237
185.16.39.146
45.153.34.106
217.15.166.221
207.180.247.52
38.242.146.242
142.248.80.31
167.86.95.106
93.123.118.228
31.56.102.63

To learn more about how we collect, analyze, and deliver actionable threat intelligence, explore our Threat Intelligence Services. If you’re interested in running your own queries – whether for threat actors, CVEs, infrastructure, or emerging activity – see how our MCP Server helps turn intelligence into practical security insight. Both are designed to support real-world analysis, investigation, and decision-making.

Take advantage of our free threat intel trial.

?

Threat Trends Digest – February 2026

?

Welcome to the Threat Trends Digest, a monthly view of real-world threat patterns.

This report compiles data from the previous month using Malware Patrol’s global telemetry and live attack observations to surface key stats on malware, phishing, ransomware, C2s, and domain generation algorithms (DGAs). You’ll find insights into the most exploited TLDs, frequently seen malware hashes and IPs, and other critical indicators. Use this digest to keep a close pulse on attacker behavior, uncover shifting patterns, and better align your defenses with the latest threat activity.

For more articles, check out our #onpatrol4malware blog.

January Threat Trends
January Threat Trends
January Threat Trends
January Threat Trends
??

IOCs

Top Malicious IPs

74.115.51.9
213.186.33.16
66.147.242.174
104.21.65.87
172.67.189.179
211.97.84.77
198.23.50.111
8.218.200.39
213.186.33.17
149.56.178.73
95.173.180.244
54.83.252.56
67.20.113.17
82.165.181.201
116.196.150.210
169.150.221.147
142.4.17.174
173.231.196.56
64.37.63.18
60.31.192.68

Top Malware Hashes

59ce0baba11893f90527fc951ac69912
8bdd2cdd39b2ad7b679faa50f629ce2b
3849f30b51a5c49e8d1546960cc206c7
eec5c6c219535fba3a0492ea8118b397
a73ddd6ec22462db955439f665cad4e6
ecf47832c60945488d601012e568b663
3a8e23ef4cc9578a00b292323579b4d4
5377e8f2ebdb280216c37a6195da9d6c
fbe51695e97a45dc61967dc3241a37dc
9b6c3518a91d23ed77504b5416bfb5b3
3a9349af006440c7e0da677724551239
d65960b89e28e465691ed757a2fdec2a
9fa84266be8c795dc61dd60fd5c1567c
c210a847989f7e47e7569ce1df92ae9e
724f25e7f93eae0ae54a80142e11b7ef
dbc520ea1518748fec9fcfcf29755c30
0b0212e124390ff12d9c04a483e2334e
ad6a76af945f652961da68bf364cdde1
cbcb58ffe45c202c11bcf2070496aed6
cb41caac2b6d810837618e153dfc3cc5

Top Attacking IPs

176.65.128.158
84.247.147.74
60.251.54.203
23.137.105.55
154.26.139.222
84.247.147.209
161.97.115.157
95.174.113.63
45.153.34.104
45.153.34.106
34.80.38.201
84.247.147.238
161.97.117.226
173.249.17.160
36.102.207.194
82.197.69.32
84.247.147.68
173.249.25.37
207.180.221.87
173.249.29.134

To learn more about how we collect, analyze, and deliver actionable threat intelligence, explore our Threat Intelligence Services. If you’re interested in running your own queries – whether for threat actors, CVEs, infrastructure, or emerging activity – see how our MCP Server helps turn intelligence into practical security insight. Both are designed to support real-world analysis, investigation, and decision-making.

Take advantage of our free threat intel trial.

?

Threat Trends Digest – January 2026

?????????

Welcome to the Threat Trends Digest, a monthly view of real-world threat patterns.

This report compiles data from the previous month using Malware Patrol’s global telemetry and live attack observations to surface key stats on malware, phishing, ransomware, C2s, and domain generation algorithms (DGAs). You’ll find insights into the most exploited TLDs, frequently seen malware hashes and IPs, and other critical indicators. Use this digest to keep a close pulse on attacker behavior, uncover shifting patterns, and better align your defenses with the latest threat activity.

For more articles, check out our #onpatrol4malware blog.

January Threat Trends
January Threat Trends
January Threat Trends
??

IOCs

Top Malicious IPs

91.238.72.69
120.138.9.38
103.15.20.10
81.91.85.141
176.53.12.17
43.231.112.25
45.114.225.27
46.59.86.3
72.9.148.195
163.44.198.41
192.250.229.213
31.31.198.199
203.175.8.87
194.93.14.42
198.187.31.106
95.173.180.70
212.99.45.180
203.98.83.109
103.16.146.2
198.38.87.214

Top Malware Hashes

59ce0baba11893f90527fc951ac69912
8bdd2cdd39b2ad7b679faa50f629ce2b
3849f30b51a5c49e8d1546960cc206c7
a73ddd6ec22462db955439f665cad4e6
eec5c6c219535fba3a0492ea8118b397
fbe51695e97a45dc61967dc3241a37dc
9b6c3518a91d23ed77504b5416bfb5b3
3a9349af006440c7e0da677724551239
5377e8f2ebdb280216c37a6195da9d6c
724f25e7f93eae0ae54a80142e11b7ef
dbc520ea1518748fec9fcfcf29755c30
221d8352905f2c38b3cb2bd191d630b0
cbcb58ffe45c202c11bcf2070496aed6
b8ed2cb3e9fedec5b164ce84ad5a08d0
6a16e166948ddb9e6e9f9de503e21c60
fd28239ca545da6ae157a6c7ab14dbf0
ebbcfb749a959fb53e9fc8b6dc915838
c3c561c20e48169f4906c6b0b135984b
936b35bfee8232f437bf6b46e88401dd
5f49ac82edd8f3a3d7c47746b6523de9

Top Attacking IPs

80.75.212.112
205.209.119.82
85.192.63.30
80.75.212.116
80.75.212.126
162.220.15.190
162.220.15.170
193.141.60.60
130.12.183.19
134.209.37.214
69.164.255.130
65.109.32.114
20.12.212.103
204.76.203.223
65.108.231.96
38.190.177.184
135.181.128.54
65.21.123.25
142.132.220.146
65.108.120.126

To learn more about how we collect, analyze, and deliver actionable threat intelligence, explore our Threat Intelligence Services. If you’re interested in running your own queries – whether for threat actors, CVEs, infrastructure, or emerging activity – see how our MCP Server helps turn intelligence into practical security insight. Both are designed to support real-world analysis, investigation, and decision-making.

Take advantage of our free threat intel trial.

?

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends

Malware Patrol recently partnered with Cisco’s SURGe Team to investigate how cybercriminals exploit newly registered domains (NRDs) for fraud during major geopolitical events. While we’ve offered NRD data for several years and know firsthand how powerful it is for uncovering malicious activity, the sheer volume of data – 200,000+ domains per day – makes it rather difficult to explore and manipulate it in meaningful ways without the right tooling and know-how. Thankfully, the knowledgeable SURGe team and Splunk Enterprise enabled us to slice and visualize a whopping two and a half years’ worth of newly registered domains in myriad ways, helping us surface patterns, trends, and supporting statistics that would have been hard to see otherwise. We’d like to express our appreciation to their team, namely: Lauren Stemler, Ryan Fetterman, James Hodgkinson and Vandita Anand.

In short, by retroactively aligning NRD activity with a timeline of key geopolitical events, we were able to validate that this data is extremely useful for spotting threats and cybercrime infrastructure. And while our analysis looked backward, the same logic applies going forward: using current newly registered domains data in near real time can help surface burgeoning campaigns and fraud as geopolitical events unfold. We hope this research helps security teams see new ways to make use of NRD data to protect against emerging threats, or at least underscores that the intersection of geopolitics and domain registrations is an important signal they shouldn’t ignore.

The original article appears on their site.

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends

Events in the physical world influence the digital world. In the wake of major geopolitical events, attackers register new domains and infrastructure to support fraudulent activities. These domains come in many forms, for example, posing as a natural disaster relief fund to solicit donations, collecting interest in a crypto coin offering, or creating a fake auto insurance website. Large-scale newly registered domain (NRD) analysis reveals consistent patterns in this behavior, allowing us to predict attacker activity long before associated fraud becomes visible.

To demonstrate the relationship between these physical and digital events, Cisco’s SURGe Team and Malware Patrol analyzed more than 200 million historical NRD records in Splunk Enterprise. Since most cyber campaigns require supporting infrastructure, NRDs offer a useful signal of malicious intent. By examining domain registration patterns around key U.S. events from 2023 to mid 2025, specifically in cryptocurrency, natural disasters, and financial sectors, we aimed to identify trends that connect real-world disruption with spikes in suspicious digital activity. This work offers practical insights for defenders seeking to anticipate and analyze fraud tied to geopolitical developments.

Understanding the Link Between Headlines and Cyber Threats

We began our research effort by building a comprehensive list of major breaking news events from January 2023 through August 2025, then narrowed our focus to events with clear opportunities for financially motivated cybercrime, prioritizing situations where adversaries could exploit urgency or heightened interest to obtain money or sensitive information. This prioritization process led to three event categories where attackers create infrastructure in response to real-world developments: cryptocurrency, financial (non-crypto), and natural disasters.
After selecting these three categories, we expanded each into a detailed event timeline. For cryptocurrency, this included Bitcoin price milestones, regulatory shifts, and exchange-related news. For financial events, we incorporated interest rate decisions, market volatility, earnings reports, and tariff/policy announcements. For natural disasters, we tracked hurricanes, wildfires, tornado outbreaks, floods, and severe weather systems. Each event was assigned a time window to allow consistent comparison against NRD activity.

Inside the Dataset: What 213 Million New Domain Registrations Reveal

Our analysis relied on Malware Patrol’s global NRD dataset, which contains more than 213 million domain registrations for the selected period. Each record contains metadata including timestamp, Top-Level Domain (TLD), hosting information, and historical indicators that can be used towards fraud classification. To isolate patterns tied to geopolitical events, we developed custom keyword and regex-based classifiers to tag domains relevant to cryptocurrency, natural disasters, and financial markets.

newly registered domains statistics

Splunk Enterprise’s large-scale search and visualization capabilities allowed us to detect anomalies, compare category-level trends against global baselines, and identify moments where domain activity sharply diverged from normal behavior. NRD data does not capture all malicious infrastructure, but it can expose the earliest stages of fraud campaigns.

Detecting Event-Driven Patterns

With this dataset mapped and categorized, the next step was to determine whether meaningful patterns emerged around real-world events. To explore this idea, we used various types of data analysis, combining event volume, fraud rate, and applying Natural Language Processing techniques to intuit the meaning behind the data.

We generated time charts of domain registration activity within each category, and across the full timeframe, measuring activity to identify statistical anomalies using rolling sensitivity bands.

The peaks and valleys of our time charts were aligned with our documented timelines of significant events to look for co-occurrences where we can retroactively confirm significant fraud activity occurred.

Semantic Shift: How is keyword use changing over time?

The volumetric and fraud-rate analyses showed when unusual behavior occurred within a category of interest, but not what attackers were trying to exploit. To capture language-specific changes, we conducted a semantic shift analysis, which would reflect how the language of newly registered domains within a category of interest changed over time.

We parsed each domain into meaningful tokens removing TLDs and subdomains, splitting on punctuation, and digits, segmenting fused words, and removing boilerplate stop words (extremely common words like “a,” “the,” “is,” are filtered out because they have little semantic value on their own). Token counts were aggregated monthly to form a month-by-term frequency matrix. We then converted this matrix into TF-IDF vectors so that each month was represented by its characteristic vocabulary rather than raw frequency dominated by common terms.

To visualize how that vocabulary changed, we projected the monthly TF-IDF vectors into two dimensions using t-SNE. Plotting them chronologically produced a trajectory in which nearby points reflected similar keyword distributions, while long jumps indicated major shifts in attacker themes.

We interpreted these jumps by reviewing top-ranked terms each month and, when useful, examining cosine distances and keyword heatmaps. For example, between December 2024 and January 2025, in the natural disaster category, new terms such as “rebuild,” “wildfire,” “disaster,” “la,” and “firestorm” suddenly became dominant, with “supplies” and “emergency” rising sharply as well. This shift aligned precisely with the Palisades Fire (discussed below) and appeared clearly in the semantic trajectory even before drilling into individual domains.

This natural language analysis, combined with event tagging, anomaly detection, and fraud-rate modeling, helped reveal not only when domain activity spiked in response to real-world events, but how attacker intent and focus changed in measurable ways.

Key Finding #1 Real-world crises create immediate and measurable spikes in fraudulent domain activity

Natural disaster–related domains represent the smallest subset of the study’s tagged NRDs, averaging 313 domains per day. Despite the lower volume, some important insights can be gained from this category due to its event-driven fluctuations. Natural disasters offer one of the clearest demonstrations of how quickly attackers capitalize on real-world crises.

One event that clearly illustrates this pattern is The January 2025 Palisades Fire in Los Angeles County – one of the most destructive and costly wildfire events in recent U.S. history. Within hours of the first evacuation alerts, our data showed a sudden surge in newly registered domains referencing the fire, Los Angeles, relief efforts, or related humanitarian themes. As the fire intensified over the following days, malicious activity grew alongside it.

Attackers registered domains impersonating relief organizations, emergency resource hubs, and donation portals, rapidly deploying infrastructure to exploit public confusion and urgency.

newly registered domains related to natural disasters

Attackers also blended in more modern lures, including Solana-themed “wildfire relief” tokens and fake cryptocurrency airdrops. Several domain clusters were bulk-registered with identical landing pages designed to harvest email addresses for later phishing campaigns, an increasingly common pattern in crisis-driven fraud. For more information on the most common attack techniques being observed, please check out the Cisco Talos Year in Review Report.

The language embedded in these domains provided further evidence. Using our semantic-shift analysis, we observed a sudden rise in tokens such as “wildfire,” “firestorm,” “lafire,” “supplies,” “donate,” and “emergency”, terms that were largely absent from the dataset just one month prior. January 2025 became the clear high-water mark for natural disaster–related domain registrations in the entire two-year period, and a significant outlier compared to overall NRD activity and the baseline growth trends of other event categories.

Viewed alongside earlier case studies, the Palisades Fire reinforces a broader pattern: real-world shocks produce immediate, measurable spikes in attacker infrastructure. Unlike crypto or financial events, which often generate longer-term waves of fraud, disaster-driven domain activity is sudden and closely tied to public attention cycles. The rapid registration of look-alike donation sites, emergency-aid portals, and geographically themed domains demonstrates how quickly threat actors mobilize when people are most vulnerable. For defenders, this means disaster-driven fraud often materializes before the public fully understands the scale of the event.

Key Finding #2: Crypto events produce the highest fraud volume and the longest-lasting impact.

While natural disasters trigger short-lived bursts of attacker activity, cryptocurrency events generate more persistent waves of fraud. Across the entire dataset, crypto-related domains represented the largest event-linked category and consistently showed the highest fraud prevalence. This pattern coincided with major market and regulatory milestones. One of the most significant upticks occurred in March 2024, when Bitcoin surpassed its previous all-time high. In the days surrounding this event, our dataset recorded one of the largest domain registration spikes in the two-year period, with newly created domains referencing Bitcoin, wallets, exchanges, investment platforms, and token names far exceeding upper sensitivity thresholds.

Unlike natural-disaster spikes, crypto activity didn’t return to baseline. Instead, March 2024 marked the beginning of a new elevated period that persisted throughout late 2024 and well into 2025. One of our hypotheses prior to starting analysis was that the recent positive changes in the regulatory environment in the U.S. would create more opportunities for crypto-related fraud. These events, for example include:

  • January 10, 2024: the SEC approved the first 11 Bitcoin exchange-traded products (ETFs/ETPs) in the U.S. These ETFs provide investors with direct exposure to Bitcoin’s price movements without the need to buy, store, or manage Bitcoin personally.
  • March 6, 2025: The U.S. signed an executive order establishing a strategic bitcoin reserve, specifically naming Bitcoin, Ethereum, XRP, Solana, and Cardano currencies.
  • March 28, 2025: The U.S. FDIC rescinded its 2022 letter that required banks to notify and obtain prior approval for crypto activities. At this point, FDIC-supervised may engage in permissible crypto activities without prior approval.
  • July 18, 2025: The U.S. approves the Guiding and Establishing National Innovation for U.S. Stablecoins (GENIUS act). This legislation continued to signal the trend that cryptocurrencies would be regulated, including reserve rules and marketing standards.

These developments drew millions of new and inexperienced users into the market, widening the pool of potential victims. Attackers responded by registering domains that impersonated exchanges, mimicked customer dashboards, hosted fake wallet downloads, and advertised fraudulent staking or investment opportunities.

The rise in pig-butchering operations during this period further illustrates how attackers adapted to this influx of new users. These long-con social engineering schemes rely on building trust with victims over weeks or months before steering them toward fabricated crypto-investment platforms. Crypto fraud was not only quick-hit phishing attempts, but attackers were playing the long game of establishing trust between themselves and their victims.

Since crypto coin scams often involve multiple domains on shared infrastructure, we used known fraud IOCs to hunt for clusters of other probable fraud activity. Building on a list of initial IOCs we have created flexible categories for capturing common memecoin related themes, and then bucket the category count to give us a variety of sorting options for investigating the data:

The resulting output aggregates suspicious categories as a distinct count and can be used to review values of domain names sharing IP space with known fraud sites.

While U.S. regulation has helped legitimize cryptocurrencies in the past years, investors should consider any investment opportunities advertised in this realm with healthy skepticism and due diligence. The FBI cites increased risk of scam for companies that are not part of self-regulatory organizations like the National Futures Association or FINRA.

Key Finding #3: Economic Fears Supercharge Uncertainty & Cyber Crime

In the financial (non-crypto) category, one of the strongest domain registration surges occurred in March 2024, during a period of heavy U.S. news coverage about increased cost of living and rising insurance costs. As we examined the data, a clear pattern emerged: insurance-related keywords began increasing frequency as early as February and reached a peak in April.

From January through April 2024, U.S. national news outlets repeatedly highlighted double-digit increases in auto-insurance rates, numerous hospital and insurer contract disputes, as well as claims & prior-authorization denial controversies, were publicized. Additionally, Centers for Medicare & Medicaid Services (CMS) confirmed a 2025 premium increase (3.7%) for Medicare Advantage. This sustained narrative produced high consumer awareness and uncertainty, resulting in the kind of environment scammers reliably exploit to deploy convincing insurance-themed phishing, refund fraud, fake coverage notifications, eligibility-verification fraud, and fake insurer-comparison websites.

In the data, we observed a shift in the domains being registered during this period. Insurance-related terms such as “insurance,” “rate,” “car,” “Medicare,” “renew,” and “health” appeared with increasing frequency. We also observed clusters using commonly abused TLDs (.xyz, .site, .online, .buzz, .bond), consistent with disposable phishing infrastructure. Numerous domains were generic or service-oriented (e.g., “insurance,” “health insurance,” “getinsurance,” “ethical insurance”), typical of phishing, scam, or fraud-oriented lures targeting people seeking coverage.

March 2024 – Volume Precedes Focused Campaigns

The data from March mirrors the rise in general financial-services domain creation during ongoing tax-season fraud, refund scams, and credit-repair themes while also demonstrating a strong overlap with the insurance-related narratives that were entering peak national coverage.

• car-insurance-47993.bond (multiple sequential variants)
• health-insurance-19289.bond (multiple sequential variants)
• insuranceconcierge.expert, insuranceconcierge.guru (bulk-pattern cluster)
• betterinsurancerate.net
• insurebestrateusa.info
• auto-insurance-deals.shop
• autoinsurancefind.today
• plansmedicare.org
• fullycoveredinsurance.com

April 2024 – A Surge in Insurance-Specific Keywords

Despite March’s higher overall volume, April produced significantly more domains containing insurance-trigger keywords:
• autoinsuranceforseniors204203.life (multiple sequential variants)
• accident-insurance-15849.bond (multiple sequential variants)
• getinsurance.pro
• governmentmedicalinsurance.com
• gov-insurance-now-8.live
• cheapautoinsurancetip.top
• cheapcarinsurancenet.top
• health-insurance-12396.bond (multiple sequential variants)
• insuranceforseniorsite.com
• medical-insurance122.online (multiple sequential variants)
• middle-agedandelderlyinsurance991.online (multiple sequential variants)
• senior-car-insurance-20352.bond (multiple sequential variants)
• americanmedicarequote.com, americanmedicarequotes.com
• medicareformedicare.site, medicare-plans-help.today
• the-car-insurance030.site (multiple sequential variants)

As a point of interest, April’s activity showed more diverse insurance subcategories (auto, medical, Medicare, homeowners, cyber, senior, contractor), suggesting that the campaigns were directly “riding” the elevated media noise from the preceding months. There were also more bulk/cluster registration patterns in April’s data, a possible indication of heightened (or peak) malicious campaign activity.
Our analysis indicates that both the March 2024 financial-domain surge and the insurance-specific increase in April can likely be explained by the compounding effect of January to March news cycles. The steady stream of headlines created fertile ground for threat actors to exploit confusion around benefits, coverage options, and plan updates.

Cross-Category Comparison: How Each Event Type Behaves in the Data

Since the scale of each category of interest is different, for a direct side-by-side comparison, we instead tracked the relative growth of each category. Each line starts at 100 for the first month; rising to 150 means +50% vs its own baseline. The tight tracking of these lines shows how each category is still influenced by macro-level trends, and deviations from the cohort overall are more notable.

As a grouped category, crypto-related domains had the highest fraud rate, of 26.86%, well above the global baseline of 23.10%. While the Natural Disaster category is much smaller in daily volume, it produces the sharpest short-term deviations and is easier to track trends without detailed keywords, compared to the financial categories. Fraud rates for Natural Disasters were also elevated to 24.26%. Financial (non-crypto) events tend to create modest increases in suspicious domain activity. Fraud rates for this category average 23.69%, slightly higher than the global baseline. Our categorization of ‘fraud’ for these purposes included any historical hosting of malware, domain generation algorithms, or command-and-control infrastructure. Since this reputation is IP-based, we expect the rate of fraud domains (many of which can be hosted on the same IP) to be potentially inflated and not representative of the true global rate of fraudulent domains.

Conclusions: Turning Event Awareness into Early Action

Attacker infrastructure frequently appears within hours or days of major real-world events, which means defenders benefit from treating external developments as operational signals. Incorporating event awareness into threat intelligence workflows begins with tracking high-impact geopolitical and economic activity and prioritizing the events most relevant to your sector or user base.

Once relevant events are identified, teams can determine which organizations or services attackers are most likely to impersonate. Converting those likely targets into keyword patterns makes NRD monitoring more effective, allowing clusters of newly registered domains to surface as early indicators of staging activity. Domains using unusual TLDs, typosquatting, or obfuscated permutations (for example, govuk-verify[.]info or unhcr-supp0rt[.]org) can then be evaluated against known threat-actor behaviors to assess whether they align with phishing kits or previously observed campaigns.

Adding contextual tags, such as the associated event, likely “spoofed entity”, or “suspected TTP”, helps SOC analysts and threat hunters pivot on related domains more effectively. Certificate metadata and sandboxing results provide additional signals to distinguish benign alerts from malicious activity. Feeding this enriched context into a SIEM or TIP allows detections to operate faster and with greater precision.

These findings highlight that NRD monitoring is a reliable early indicator of cybercrime taking shape. By pairing domain trends with current events, defenders can anticipate the kinds of lures and impersonation themes that are likely to emerge next. Building this context into threat intelligence programs helps teams detect malicious infrastructure earlier, prioritize investigations more effectively, and prepare for incoming campaigns rather than reacting after the fact. As cybercriminals align their operations with real-world disruptions, adopting event-driven threat intelligence is essential for staying ahead.

Credit to authors and collaborators: Lauren Stemler (Splunk / SURGe), Ryan Fetterman (Splunk / SURGe), James Hodgkinson (Splunk / SURGe) and Vandita Anand (Splunk / SURGe), Andre Correa (Malware Patrol), Leslie Dawn (Malware Patrol).

 

?

How big are your threat data gaps?

See for yourself.

?

MCP Servers for Cybersecurity

MCP Servers for Cybersecurity: Smarter, Safer, and Ready to Work

The adoption of AI in cybersecurity is accelerating, but both integration and security remain challenges.

While large language models (LLMs) are great at understanding language, they don’t easily connect to structured threat data or existing tools. Prompting alone isn’t enough to make AI useful in the SOC.

That’s where MCP servers come in.

What Is an MCP Server?

MCP stands for Model Context Protocol. It’s an open standard that allows LLMs to interface with tools, APIs, and data sources in a secure, structured way. An MCP server acts as a bridge between a language model and the tools it needs to work with, such as a SIEM, threat intelligence platform, malware sandbox, or internal detection engine.

Instead of encoding instructions into long prompts, an LLM connected to an MCP server can:

  • Discover available tools and documentation
  • Select and call the right tool
  • Pass inputs and receive outputs in structured formats
  • Chain multiple actions for more complex workflows

It effectively gives LLMs real operational capabilities in the cybersecurity space.

How MCP Servers Work

At its core, an MCP server exposes tools in a standardized JSON format. Each tool has metadata, documentation, and security controls. The LLM can inspect available tools and choose which to call based on the user query and system context.

Example:

  1. A user asks, “Find indicators tied to APT29 in the last 90 days.”
  2. The model calls a threat intelligence search function through MCP.
  3. The tool returns matching IOCs from a database.
  4. The LLM interprets and summarizes the results.

The server handles routing, context tracking, and access controls, so the model only works within approved boundaries.

Why MCP Servers Matter in Cybersecurity

For LLMs to be useful in cybersecurity, they must interact with:

  • Threat intelligence platforms
  • Malware analysis tools
  • SIEMs and XDRs
  • Incident response workflows
  • Case management and alerting systems

Public models like ChatGPT or Copilot don’t offer secure access to any of these. MCP servers fill that gap by allowing LLMs to operate inside controlled environments with full traceability.

Real Use Cases for MCP in Security

Security teams are already exploring how MCP servers can:

  • Generate threat actor profiles from live data
  • Run malware samples in sandboxes and summarize behavior
  • Enrich alerts with correlated IOCs
  • Automate triage and investigation flows
  • Generate or validate YARA and Sigma rules

Projects and Tools Using MCP in Cybersecurity

Here are some MCP-related projects and offers currently available in the industry:

Secure-by-Design: What to Look For

As with any tool in cybersecurity, MCP servers should be built securely:

  • Role-based access control
  • Tool-specific authorization
  • Logging and auditing of all calls
  • Input validation
  • Session-aware context isolation
  • Support for on-prem or air-gapped deployment

The Bottom Line

MCP servers make it possible to safely combine the reasoning power of LLMs with real cybersecurity tools. They’re becoming a key part of how AI is being embedded into SOCs, IR platforms, and threat intel systems.

For AI to work in security, it must interact with tools and data in a controlled, auditable way. MCP is the protocol making that possible.

Want to see a real-world example? Check out Malware Patrol’s MCP Server.

?

How big are your threat data gaps?

See for yourself.

?

Introducing the Malware Patrol MCP Server

Introducing the Malware Patrol MCP Server for Cybersecurity Teams

We recently wrote about how MCP servers are unlocking new ways to use AI in cybersecurity. If you missed it, start here to learn what MCP servers are and how they work.

Today, we’re excited to announce the beta launch of our own MCP server, purpose-built for security teams.

Why We Built It

Security professionals need AI that’s more than just a chatbot. The Malware Patrol MCP server connects a custom-trained LLM to structured data, IOCs, and security context, enabling real-world workflows like:

  • Threat actor profiling
  • IOC investigation and correlation
  • Campaign tracking and attribution
  • CVE and malware analysis
  • Infrastructure overlap detection
  • Alert enrichment

What Powers the Malware Patrol MCP Server

Our model has been trained on a curated set of cybersecurity industry content, including:

  • APT and threat group profiles
  • Campaign breakdowns
  • Post-incident investigation reports
  • Security research articles

From this content, we extract structured indicators such as:

  • Threat actor profiles
  • IP addresses
  • File hashes
  • Email addresses used to exfiltrate data and in phishing and other malicious campaigns
  • CVEs abused by threat actors
  • Cryptocurrency wallet addresses

This information is stored and made accessible through our MCP interface. You can query it using natural language.

Sample Questions You Can Ask

  • What are all the known aliases of APT28?
  • What is the timeline of known activity for APT15?
  • Retrieve the latest IOCs associated with APT39.
  • Which threat actors are known to use Cobalt Strike and target retail?
  • Which CVEs are exploited by both APT15 and APT35?
  • Which actor is associated with the hash 7568062ad4b22963f3930205d1a14df7?

These are just a few of the hundreds of supported queries.

Built for Integration and Control

Malware Patrol MCP server supports:

  • Role-based access and authentication
  • Session-aware tool calling
  • Input validation and call logging
  • API integration with internal tools or threat intel platforms

As the system evolves, we will add more tools and workflows based on customer needs and feedback.

Join the Beta Program

AI is powerful. Connected to your tools, your intelligence, and your policies, it becomes operational. We’re offering early access to security teams, MSSPs, and researchers interested in:

  • Using LLMs for real-world threat research
  • Automating investigation workflows
  • Connecting AI to internal tools
  • Helping shape the next generation of cybersecurity copilots

Request beta access here.

?

How big are your threat data gaps?

See for yourself.

?

Emerging Threats Intelligence: A Curated Signal with Predictive Power

The Value of Emerging Threats Intelligence

Threat campaigns often evolve too quickly for traditional defenses to catch them in time. Our Emergent Threats Domains feed is built to provide early visibility into domains that are likely to be used in malicious activity. By combining multiple data sources with advanced analysis techniques, we surface high-risk domains before they are operationalized in active campaigns. This allows security teams to move from reactive defense to proactive action, reducing exposure and improving response times.

Identifying Risk Before It’s Weaponized

To identify emerging threats, we combine several raw data sources, including newly registered domains (NRDs), newly observed domains (NODs) from DNS traffic and other signals from our global collection systems. On their own, these datasets are high-volume and unfiltered, but by applying multiple layers of analysis we can identify domains that are far more likely to be weaponized in malicious campaigns.

Each domain is scored based on the following (among other) criteria:

Structural analysis: Detecting randomness, entropy, and other patterns common in algorithmically generated domains (DGAs)

Infrastructure associations: Mapping connections to infrastructure from both current and previous malicious campaigns tracked in Malware Patrol’s extensive historical database, revealing reuse of attacker resources

Brand lookalikes: Spotting domains designed to impersonate trusted brands, a common precursor to phishing and fraud

TLD reputation: Factoring in the track record of top-level domains (for example, .xyz) that frequently appear in malicious campaigns

This combination of broad input data and layered analysis transforms raw domain activity into a curated feed of high-risk signals. Even though these domains may not yet appear on VirusTotal or in traditional intelligence feeds, they often carry subtle indicators of risk.

Key Benefits for Security Teams

By highlighting suspicious domains early, the feed gives defenders a head start. With emerging threats intelligence, security teams can:

  • Block high-risk domains before they are weaponized
  • Identify suspicious infrastructure earlier in the attack chain
  • Reduce attacker dwell time by acting faster
  • Strengthen DNS-layer defenses and detection systems with predictive data

Advantages and Limitations

Like any security solution, our Emergent Threats Domains feed has strengths and trade-offs that should be considered.

Advantages:

  • Pre-filtered and enriched, reducing noise and making it ready to deploy in firewalls, SIEMs, and DNS layers
  • Compact enough to work within the limits of tools that cannot process large blocklists
  • Includes enrichment and scoring, providing immediate context for faster decisions
  • Well-suited for smaller teams or those without capacity to build enrichment pipelines internally

Limitations:

  • Filtering and scoring are determined by vendor criteria, which may not fully align with every organization’s unique threat model
  • By design, not every domain is included, only those identified as suspicious, so some activity could be missed
  • Less flexible than raw feeds, making it less suitable for organizations that prefer to create custom detection logic

Comparison: Newly Registered Domains vs Emergent Threats Domains

Both NRDs and emerging threats intelligence provide valuable visibility, but they serve different needs as outlined in the table below.

Newly Registered Domains (NRDs) Emergent Threats Domains
Broad coverage of all new domains Focused coverage of domains flagged as suspicious
High volume and unfiltered Pre-filtered, enriched, and scored
Requires custom enrichment and filtering by the user Includes enrichment such as entropy, brand lookalikes, infrastructure ties, and TLD reputation
Useful for hunting, research, and building custom detections Useful for immediate blocking and SOC operations
May overwhelm tools or teams without filtering Compact size avoids overwhelming security tools
Best for mature SOCs and research teams Best for smaller teams or those prioritizing operational efficiency

In short, NRDs give maximum visibility and flexibility, while Emergent Threats Domains provides ready-to-use intelligence that reduces noise and speeds up action.

Try Malware Patrol’s Emergent Threats Domains With a Free Trial

Whether you want the flexibility of raw NRDs or the convenience of enriched Emergent Threats Domains, we can help you choose the right approach for your environment. We also offer free evaluations so you can see the data in action and decide which feed best fits your security needs.

Get started today and take the first step toward staying ahead of tomorrow’s threats. We’d be happy to discuss options and set up a free trial. Use this link to schedule time with us.

?

How big are your threat data gaps?

See for yourself.

?

Newly Registered Domains: A Raw Signal with Real Value

Working with Newly Registered Domains

We provide a Newly Registered Domains (NRDs) feed, and one of the most common questions we receive is: “How can this data be used?”

It is a valid question. By their very nature, NRDs are high-volume and unfiltered, which can make them challenging to work with at first glance. But that rawness is also what makes them powerful: they provide one of the most comprehensive snapshots of Internet activity you can get. After all, every malicious domain begins life as an NRD. For defenders who know how to work with this telemetry, that makes NRDs an invaluable early-stage signal.

With the right enrichment and filtering, what first looks like overwhelming noise can quickly turn into actionable intelligence. Organizations that invest in detection engineering or custom hunting workflows can use NRDs to spot attacker infrastructure before it’s weaponized in campaigns, often long before it ever appears in curated threat feeds.

Before we dive into how organizations can put NRDs to work, let’s take a step back. When we say “NRD feed,” what exactly does that include? And why is this raw data so valuable?

What is an NRD Feed?

A Newly Registered Domains (NRD) feed is a daily snapshot of every domain registered on a given date. It captures everything, from legitimate business sites and personal projects to the very first traces of attacker infrastructure.

Threat intelligence providers may structure NRD intelligence in different ways, but the most common fields include the domain name, the registration date, and related DNS records. These basic elements make up the raw dataset.

Malware Patrol takes it a step further. In addition to listing new domains, we resolve each one through DNS and check the resulting IP addresses against our current and historical databases of malicious infrastructure. The output is a simple indicator, presented by threat type, showing whether a domain has ever resolved to an IP tied to malicious activity. This doesn’t turn NRDs into a curated threat feed, but it does provide valuable context to help security teams prioritize where to look first.

Example NRD Feed Entry (Simplified)

{
“DOMAIN”: “zzzzbetjogos.com”,
“REGISTRATIONDATE”: 20250928,
“A_RECORD”: [
{
“IP”: “104.21.18.168”,
“HOSTINGC2”: 0,
“HOSTEDC2”: 0,
“HOSTEDDGA”: 0,
“HOSTINGMALWARE”: 0,
“HOSTEDMALWARE”: 0
}
],
“AAAA_RECORD”: [
{ “ADDRESS”: “2606:4700:3035::6815:12a8” }
],
“NS_RECORD”: [
{ “HOST”: “lennon.ns.cloudflare.com” },
{ “HOST”: “nelly.ns.cloudflare.com” }
]
}

Why Should You Care About NRDs?

Attackers depend on newly registered domains as a foundation for their operations. Whether establishing fresh infrastructure for malware delivery or spinning up lookalike sites that mimic trusted brands, new domains give adversaries a clean slate. With no reputation history and no presence on blocklists, they’re the perfect launchpad for malicious activity.

Every day, threat actors register domains to:

  • Launch phishing and social engineering campaigns

  • Set up malware infrastructure like C2 servers and drop zones

  • Impersonate legitimate brands through typosquats and lookalikes

  • Avoid being caught by existing blocklists.

Of course, many newly registered domains are harmless, but the critical point is that every malicious domain starts as an NRD. This makes NRDs a powerful early-warning signal. By using them, security teams can detect attacker infrastructure before it’s weaponized in campaigns and long before it shows up in curated threat feeds.

Use Cases for Newly Registered Domains Feeds

Here’s what your team can do with this data:

  • Block NRDs for a fixed period (e.g., 3–7 days): Most legitimate sites aren’t operational immediately. Blocking during this window dramatically reduces exposure to phishing and malware campaigns.
  • Prioritize NRDs that resolve to suspicious infrastructure: Use Malware Patrol’s malicious-IP indicator as a filter to decide which domains may warrant closer inspection.
  • Monitor for brand impersonation or typo squatting: Detect lookalike domains before they appear in phishing emails.
  • Detect DGA or high-entropy domains: Flag domains likely generated by Domain Generation Algorithms. A DGA domain typically looks like a random string of characters, often unpronounceable, and statistically unlikely in natural language (e.g., xj3k9u2p.biz).
  • Retroactive incident analysis: Check which NRDs were queried during dwell time in an incident.
  • Security research: Track TTPs of threat actors by watching domain registration patterns. Investigate bulk registrations, suspicious registrars, or ASN patterns to spot attacker infrastructure.

NRDs: Raw Fuel for Custom Defenses

If you’re looking to enrich internal detection pipelines, protect your brand, or analyze emerging infrastructure at Internet scale, NRDs are where that work starts. While NRDs are not a plug-and-play threat feed, they empower organizations to hunt earlier, detect faster, and build detections tuned to their own threat models. (With our malicious-infrastructure correlations, subscribers also get a bit of extra context to help prioritize analysis!)

We understand that working with a raw NRD feed can be challenging, which is why we help our subscribers get the most out of it. Our team can customize the feed to align with your environment – at no cost – and provide guidance on setting internal parameters so you can filter, enrich, and prioritize domains in a way that fits your security goals.

And if your organization prefers not to manage this kind of data, we also offer an alternative: Emergent Threats Domains. This feed is informed in part by NRDs but is pre-filtered, enriched, and ready for immediate use in security controls.

Want to explore what your organization can do with NRDs? Let’s talk.

?

How big are your threat data gaps?

See for yourself.

?

Tor Exit Nodes: Risks, Monitoring, and Defensive Use

????

What Are Tor Exit Nodes?

Tor exit nodes frequently appear in cybersecurity discussions, and for good reason. This post explains why they matter so you can decide if your security team should take a closer look.

The Tor network is a powerful tool for enabling anonymity online, and like many privacy-preserving technologies, it has both legitimate and malicious uses (we’re looking at you, DoH!). While it supports privacy for users around the world, it also helps attackers hide their infrastructure, evade detection, and bypass traditional defenses. Understanding how Tor works and how it’s used across different stages of an attack can help defenders apply controls, such as traffic monitoring and access policies, more effectively.

The Tor (The Onion Router) network is a system designed to enable anonymous communication over the Internet. When a user routes their connection through Tor, their data is encrypted and bounced through a series of volunteer-operated nodes, also known as relays, in a layered manner, like peeling an onion. Tor exit nodes are the final relay in the Tor network through which traffic emerges before reaching its destination.

Here’s how it works:

  1. Client Encryption and Path Building:
    When a user initiates a connection via the Tor Browser, the client software selects a random path through the Tor network, consisting of three relays:

    • Entry (Guard) Node – The first hop; it knows the user’s IP address.
    • Middle Node – The second hop; it connects the entry and exit nodes.
    • Exit Node – The final hop; it decrypts the traffic and sends it out to the public Internet.
  2. Onion Routing:
    Each relay only knows the previous and next hop, not the full path, and traffic is encrypted in multiple layers. As each relay receives the data, it peels away one layer of encryption (hence “onion routing”) until the exit node forwards the plaintext traffic to the destination website or server.
  3. Exit Node Role:
    The exit node is where the traffic appears to originate from as far as the destination is concerned. It sees the content of the request (unless it’s encrypted with HTTPS), but not the origin IP address of the user. This is why exit nodes are a focus in both privacy discussions and cybersecurity operations.

Because exit nodes are the only points in the Tor network that interact with the open Internet, they are a key observation point for defenders monitoring suspicious traffic. You can download a current list of active exit nodes and as well as find more technical detail about changes to the service on their official blog.

Why Tor Exit Nodes Matter in Cybersecurity

While Tor has many legitimate uses, its anonymity makes it attractive to threat actors. Attackers frequently leverage Tor for:

  • Exfiltration of data after compromising a system
  • Command-and-control (C2) communications
  • Scanning and probing for vulnerabilities anonymously
  • Anonymized web scraping or credential stuffing

Traffic emerging from Tor exit nodes presents challenges for attribution, enforcement, and even rate-limiting. Monitoring or blocking these nodes can help reduce noise and risk in certain environments.

MITRE ATT&CK TTPs

To further the discussion about Tor’s significance in cybersecurity, it’s helpful to look at how the MITRE ATT&CK framework classifies the different ways attackers abuse it. We compiled the following list to emphasize the broad utility of Tor (or similar services) across the threat landscape. From infrastructure obfuscation and anonymous scanning to covert data theft, Tor enables a wide spectrum of malicious operations. By showcasing its versatility, we aim to help defenders implement more effective detection and mitigation strategies in their environments.

Tactic Technique ID Technique Name Description Use Case
Command and Control T1090.003 Proxy: Multi-hop Proxy Multi-hop proxy chains are used to conceal the true source and destination of network traffic. Tor acts as a multi-hop encrypted proxy. Operators route C2 traffic through it to hide their infrastructure and bypass perimeter defenses.
Command and Control T1102 Web Service Legitimate web services can be leveraged to carry out C2 communications while blending with normal traffic. Tor hidden services (.onion domains) are used to host C2 endpoints anonymously, making them harder to block or trace.
Command and Control T1102.001 Dead Drop Resolver Commands or payloads are stored at web-accessible locations and retrieved by malware. Malware connects over Tor to .onion pages that host instructions (dead drops), reducing the need for persistent C2 channels.
Command and Control T1102.002 Bidirectional Communication Two-way communication channels are established using web services, allowing command issuance and response retrieval. Tor provides encrypted, anonymous communication between infected systems and their controller using hidden services.
Command and Control T1572 Protocol Tunneling Malicious traffic is encapsulated within another protocol, such as HTTPS, to evade detection mechanisms. Communication is tunneled through Tor using standard protocols like HTTPS or SOCKS to blend with legitimate activity.
Command and Control T1001 Data Obfuscation Traffic is modified or disguised to make it more difficult to analyze or detect. Tor’s encrypted routing layers hide both the content and the destination of communications, helping obscure intent.
Exfiltration T1041 Exfiltration Over C2 Channel Data is embedded within command and control traffic for covert transmission out of the environment. Tor-based C2 channels are frequently used to exfiltrate stolen data along with commands due to encryption and anonymity.
Exfiltration T1567.002 Exfiltration to Cloud Storage Data is exfiltrated using cloud storage or web services, often over encrypted channels. Tor is used to anonymize the transfer of stolen data to attacker-controlled storage or .onion servers.
Resource Development T1583.006 Acquire Infrastructure: Web Services Web infrastructure such as domains or servers is obtained for later operational use. .onion domains and hidden services are registered and deployed over Tor to host malware, C2 servers, or phishing kits anonymously.
Defense Evasion T1027 Obfuscated Files or Information Code or data is hidden or encoded to prevent detection by security tools. Traffic routed over Tor benefits from inherent encryption and anonymization, making it harder to inspect or attribute.
Discovery T1595 Active Scanning Target networks are scanned to gather information such as open ports, services, or potential vulnerabilities. Scanning activities are conducted over Tor to mask the source of probes against target infrastructure.
Discovery T1595.001 Scanning IP Blocks Large address spaces are scanned to locate accessible systems and services. Tor exit nodes are used to scan wide IP ranges, identifying exposed assets while remaining anonymous.
Discovery T1595.002 Vulnerability Scanning Specific systems are scanned to identify known vulnerabilities or misconfigurations. Vulnerability scanning tools route traffic through Tor to identify weaknesses in targets without revealing the attacker’s origin.
Credential Access T1110 Brute Force Repeated login attempts are made to gain unauthorized access by guessing or using common passwords. Login brute-force attacks are launched via Tor to bypass IP restrictions and avoid detection.
Credential Access T1110.004 Credential Stuffing Previously leaked credentials are used to attempt logins across services. Tor is used to distribute these login attempts across many IPs, increasing stealth and success while avoiding rate limits.
Reconnaissance T1589.003 Gather Victim Identity Information: Credentials Username and password data is collected from public or breached sources to inform follow-on targeting. Tor is used to scrape credential leaks from forums, dumps, or pastes while hiding the requester’s identity.

Defensive Applications of Tor Exit Node Intelligence

There are multiple defensive use cases for tracking and leveraging Tor exit node IPs in a security program:

  1. Blocking Tor Exit Traffic

Many security teams choose to block inbound or outbound traffic involving known Tor exit nodes, especially in environments that do not serve anonymous users. This can be done via:

  • Firewall rules
  • Web application firewalls (WAFs)
  • DNS-based filtering
  • SIEM correlation rules

Keep in mind, this approach may generate false positives if your service intentionally serves Tor users.

  1. Threat Hunting and Monitoring

By monitoring network traffic to and from Tor exit nodes you can uncover suspicious or malicious behavior such as:

  • Beaconing to C2 infrastructure
  • Unauthorized data transfers
  • Anonymized access attempts

This is particularly useful in SOC environments that log DNS queries, proxy traffic, or NetFlow/Zeek logs.

  1. Threat Intelligence Enrichment

Ingesting and enriching alert data with Tor exit node intelligence can improve triage workflows. For example:

  • Flagging alerts from exit node IPs with a higher risk score
  • Adding context during incident investigations
  • Enhancing SOAR playbooks with automated risk annotations

Where to Get Reliable Tor Exit Node Data

There are a few trustworthy sources for up-to-date Tor exit node information:

Considerations and Cautions

Blocking or monitoring Tor exit traffic is not always the right choice. For organizations supporting user privacy, activism, or global accessibility, outright blocking could limit service availability or raise ethical concerns. Any implementation should be aligned with your organization’s risk posture and user profile. Also, IP addresses of Tor exit nodes can change frequently. This means real-time updates and automation are essential if you’re maintaining blocklists or alerts.

Here are a few good resources for advice about developing a Tor security policy:

Final Thoughts

Using Tor exit node IPs as part of your threat intelligence strategy adds visibility into a common vector for anonymous, and potentially malicious, traffic. Whether you’re blocking, monitoring, or enriching alerts, Tor exit node intelligence is a flexible and valuable tool, but it should be used thoughtfully and in context. Not all Tor traffic is malicious, and indiscriminate blocking can lead to unintended consequences. Instead, aligning Tor intelligence with your organization’s risk tolerance and use cases ensures it contributes meaningfully to detection, response, and threat hunting efforts.

For our customers, Tor exit node data can also be integrated directly into existing threat intelligence subscriptions upon request. Contact your account manager to learn more about integration options or additional enrichment.

As part of our commitment to empowering defenders, we offer several free OSINT feeds, one of which includes a regularly updated list of active Tor exit nodes. Click below to sign up for free access.

Leslie Dawn

Technical Account Manager

Leslie Dawn is a Technical Account Manager / Threat Intelligence Analyst at Malware Patrol. Her background of nearly a decade in cyber threat intelligence provides her with a nuanced understanding of threat landscapes and client security needs.

 

?

Malicious Domains: A Cybersec Foundation

Malicious domains are a foundational layer of threat intelligence and provide critical visibility into where attackers operate online. You can integrate domain-based intelligence across your security stack to: enhance prevention with DNS filtering and firewall rules, improve detection via IDS/IPS systems, guide SOAR-driven response playbooks, and support retrospective threat hunting. Their versatility makes them valuable for organizations of any size because they serve as both a frontline defense and an investigative asset.

Why Domains (Not Just IPs) Matter

Blocking domains offers a more precise and effective way to deny access to malicious infrastructure compared to blocking at the IP-level. Unlike IP addresses, which are often shared across many services and tenants (e.g., cloud providers), domains tend to be unique to the threat actor’s campaign or infrastructure. Blocking a malicious IP risks affecting legitimate services; blocking a malicious domain is more targeted and typically less prone to false positives.

Where to Get Domain Blocklists

There are several sources for malicious domain blocklists:

  • Commercial Threat Intelligence Vendors – They offer curated, regularly updated feeds, often enriched with context like first-seen dates, associated malware families, or related indicators (IPs, hashes, etc.).
  • Open Source Intelligence (OSINT) – Communities such as Abuse.ch, PhishTank, and threat-sharing platforms publish free lists. While useful, they can vary in accuracy, timeliness, and depth of context.
  • Internal Sources – Your organization’s own detection systems (e.g., sandboxing, phishing reports) can be a powerful generator of high-confidence domains worth adding to local blocklists.

Of course, not all feeds are created equal. Freshness, coverage, and enrichment are key to determining how useful a feed is in real-world defensive operations.

The Importance of Freshness and Context

Threat actors continuously evolve their infrastructure. Domains can be registered and weaponized within minutes. That’s why static or infrequently updated lists are of limited use. A quality feed should not only be updated frequently, ideally hourly or daily, but also provide context: Why is this domain flagged? Is it linked to a specific malware family? Was it part of a known phishing kit? When was it first detected?

Rich metadata and context allow security teams to make informed decisions. For example, knowing a domain is associated with a known command-and-control server for a particular ransomware strain might justify more aggressive response actions than if it were merely flagged for spam.

How to Use Malicious Domain Feeds

You can integrate domain intelligence into your environment in several ways:

  • Network Controls – Feed domains into firewalls, DNS security tools, or secure web gateways to block access in real time.
  • IDS/IPS Systems – Tools like Suricata or Snort can inspect DNS traffic for requests to known bad domains and generate alerts or drop packets.
  • SIEMs and SOARs – Enrich alerts with domain context to improve triage speed and accuracy.
  • EDR and XDR – Use domain feeds to flag suspicious outbound connections from endpoints and correlate with other malicious activity.
  • Threat Hunting – Historical DNS logs or proxy logs can be cross-referenced against the feed to identify prior compromise.
Best Practices for Operational Use
  1. Use Multiple Feeds – Every source has limitations in coverage, geography, etc. Selecting feeds from multiple vendors and publicly available offers help to maximize coverage.
  2. Automate Ingestion and Updates – Integrate feeds into your tech stack with automation tools or platforms.
  3. Monitor for Overblocking – Even with domain-level granularity, verify false positives and build feedback loops to tune your blocklists.
  4. Use Enriched Feeds for Decision Making – Context reduces alert fatigue and helps prioritize incident response.

Final Thoughts

Malicious domain feeds are a tried and true foundational element of threat prevention, detection, and response. From stopping phishing attempts to flagging command-and-control activity, domain-level intelligence provides a tactical advantage in defending against today’s fast-moving threats.

Malware Patrol offers domain intelligence designed to meet the needs of security teams who require both breadth and depth. We cover a wide range of threats, from phishing and malware to emerging threats, cryptomining, DGAs, and C2 infrastructure. Our feeds are also enriched with the metadata that helps turn alerts into action. For ease of use, we format the feeds for compatibility with the most popular security tools and platforms.

Ready to add precision and power to your defenses? Contact us to learn more or to request a free trial.

?

How big are your threat data gaps?

See for yourself.

?