NordVPN Promotion

Home / Industry

3 Russian Threat Groups Target Persons of Interest

Google Threat Intelligence Group (GTIG) recently published a report on three Russian threat groups—UNC6293, UNC7005, and UNC5976—targeting various persons of interest for the country. They identified 32 network IoCs comprising two subdomains, 25 domains, and five IP addresses.

We extracted two domains from the subdomain IoCs, ending up with 27 in total. We then weeded out those that belonged to legitimate companies aided by the WhoisXML API MCP Server, trimming down the number to 26 domains. All in all, we analyzed 33 network IoCs made up of two subdomains, 26 domains, and five IP addresses.

Our DNS deep dive into the threat led to these findings:

  • One client IP address that communicated with a domain IoC
  • One domain IoC that appeared in a typosquatting group with 10 members
  • One domain IoC that was likely registered with malicious intent
  • 317 unique potentially victim-owned IP addresses that communicated with five of the IP IoCs
  • 2,494 email-connected domains, three were confirmed malicious
  • 15 additional IP addresses, 14 were confirmed malicious
  • 29 IP-connected domains, 13 were confirmed malicious
  • 151 string-connected domains, one was confirmed malicious

A sample of the additional artifacts obtained from our analysis is available for download from our website.

The Subdomain IoCs in the Spotlight

We kicked off our investigation by zooming in on the two subdomain IoCs. Based on the results of our analysis via the WhoisXML API MCP Server, we learned that one posed great risk while the other was rated moderately risky. Here are more details about them.

SUBDOMAIN IoCWXA MCP SERVER FINDING
drive[.]google[.]verify-drive[.]comHigh risk; deceptive subdomain labeling (drive[.]google as subsubdomain of verify-drive[.]com) to impersonate Google Drive; brand new; privacy-protected WHOIS record; low-reputation leased netblock; co-hosted with Google-mimicking domains
mail[.]kiis[.]co[.]ukModerate risk; dropped and reregistered domain with prior reputation; configured email-only via registrar forwarding; no website; KIIS brand-adjacent; low-reputation NSP host

Overall, avoiding both subdomain IoCs may be warranted.

The Domain IoCs under the Microscope

Next, we took a closer look at the 26 domain IoCs. Sample network traffic data from the IASC revealed that one client IP address communicated with the IoC globsec[.]net via two DNS queries on 7 July 2026.

We queried the domain IoCs on Bulk Registration Risk API next and found out that wa-connect[.]net appeared in a typosquatting group along with nine lookalikes. While l-connect[.]io did not have a creation date, three domains (i.e., kmconnect[.]online, pmo-connect[.]com, and kmconnect[.]nl) were created on 11 May 2026 and the remaining six domains, including the IoC (i.e., ut-connect[.]net, msmconnect[.]org, go-connect[.]live, fm-connect[.]site, wa-connect[.]net, and gmo-connect[.]cloud) were created on 12 May 2026.

Next, we determined that the domain IoC miov2iaiaoubqosiqoiajwowiwjso[.]online appeared on the First Watch Malicious Domains Data Feed as soon as it was created on 20 November 2025, 274 days before GTIG dubbed it as an IoC.

After that, we queried the domain IoCs on WHOIS API and discovered that:

  • They were created between 27 June 2024 and 12 August 2026.
  • They were administered by seven registrars.

  • While three of them did not have registrant countries on record, the remaining 23 were registered in seven countries.

Finally, we queried the domain IoCs on DNS Chronicle API and learned that they recorded 614 historical domain-to-IP resolutions over time. Take a look at more information for five examples below.

DOMAIN IoCNUMBER OF DOMAIN-TO-IP RESOLUTIONSDATES SEEN
globsec[.]net26902/05/17–07/30/26
kiis[.]co[.]uk12002/06/17–07/29/26
wa-meeting[.]com6906/27/24–07/28/26
mioisiskwowiwjowuwjwolab[.]club3411/20/25–08/01/26
dosportal[.]app3011/22/25–08/17/26

The IP Address IoCs Take Center Stage

Next, we dove deeper into the DNS infrastructure of the five IP IoCs. From sample network traffic data from the IASC, we learned that 317 unique IP addresses potentially owned by victims communicated with the IP IoCs between 5 April to 23 August 2026. They were under 23 distinct ASNs.

We then queried the IP IoCs on Bulk IP Geolocation Lookup and discovered that:

  • They were geolocated in three countries, two of which—the Netherlands and the U.S.— also appeared in the list of domain IoC registration countries.
  • While two IP addresses did not have ISPs on record, each of the remaining three was administered by a different ISP.

We also queried the IP IoCs on DNS Chronicle API and found out that they posted 437 IP-to-domain resolutions over time. The IoC 104[.]194[.]159[.]150, for instance, recorded 385 resolutions from 16 August 2019 to 17 July 2026.

The Hunt for New Artifacts Bears Fruit

First, we queried the domain IoCs on WHOIS History API and learned that 25 had 34 unique email addresses in their historical WHOIS records. Further scrutiny revealed that nine were public email addresses.

We queried the public email addresses on Reverse WHOIS API, which led to the discovery of 2,494 unique email-connected domains after those already dubbed as IoCs were filtered out.

Threat Intelligence API queries for the email-connected domains revealed that three have already been weaponized for attacks. An example is dsapdlqpwd[.]icu, which has been associated with malware distribution between 26 April and 25 August 2026.

We also queried the email-connected domains on Domain Traffic API and identified the 10 with the highest number of visits since 1 January 2026.

This post only contains a snapshot of the full research. Download the complete findings and a sample of the additional artifacts on our website or contact us to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

Disclaimer: We take a cautionary stance toward threat detection and aim to provide relevant information to help protect against potential dangers. Consequently, it is possible that some entities identified as “threats” or “malicious” may eventually be deemed harmless upon further investigation or changes in context. We strongly recommend conducting supplementary investigations to corroborate the information provided herein.

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By WhoisXML API, A Domain Research, Whois, DNS, and Threat Intelligence API and Data Provider

Whois API, Inc. (WhoisXML API) is a big data and API company that provides domain research & monitoring, Whois, DNS, IP, and threat intelligence API, data and tools to a variety of industries.

Visit Page

Filed Under

Comments

Commenting is not available in this channel entry.
CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

New TLDs

Sponsored byRadix

Brand Protection

Sponsored byCSC

IPv4 Markets

Sponsored byIPv4.Global

DNS Security

Sponsored byWhoisXML API

DNS

Sponsored byDNIB.com

Domain Names

Sponsored byVerisign

Cybersecurity

Sponsored byVerisign

NordVPN Promotion