|
||
|
||
CRN recently named the biggest cyber attacks and breaches the world has seen so far in 2026, and we zoomed in on five of them. We specifically tackled the attacks below.
| CYBER ATTACK | IoC SOURCE | THREAT GROUP | DATE PUBLISHED |
|---|---|---|---|
| Cisco SD-WAN Attacks | Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager | Unknown | 06/25/26 |
| Stryker Wiper Attack | Timeline Reconstruction: Stryker Handala Threat Group Wiper Attack | Stryker Handala | 03/20/26 |
| Ivanti EPMM Attacks | Critical Vulnerabilities in Ivanti EPMM Exploited | Unknown | 02/17/26 |
| ShinyHunters: Canvas Breach | Canvas × ShinyHunters: Full Intelligence Report—May 2026 | ShinyHunters | 05/13/26 |
| ShinyHunters: Broader Attacks(1 sample only) | ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit | ShinyHunters | 06/12/26 |
We collated network IoCs comprising subdomains, domains, and IP addresses from the sources identified above.
Note that we extracted some domains from the subdomain IoCs then filtered out those that were owned by legitimate companies aided by the WhoisXML API MCP Server and one that was on the Tor network. After that, we ended up with 54 IoCs for our investigation comprising five subdomains, 14 domains, and 35 IP addresses. Take a look at a more detailed breakdown below.
| CYBER ATTACK | SUBDOMAIN IoC | DOMAIN IoC | IP IoC |
|---|---|---|---|
| Cisco SD-WAN Attacks | NA | NA | 8 |
| Stryker Wiper Attack | NA | 3 | 4 |
| Ivanti EPMM Attacks | 5 | 14 | 17 |
| ShinyHunters: Canvas Breach | NA | 2 | 1 |
| ShinyHunters: Broader Attacks(1 sample only) | NA | 1 | 5 |
Our analysis of the five attacks led to these discoveries:
A sample of the additional artifacts obtained from our analysis is available for download from our website.
We kicked off our analysis by zooming in on the five subdomain IoCs, all connected to the Ivanti EPMM attacks. We summed up the results of our WhoisXML API MCP Server queries below.
| SUBDOMAIN IoC | WXA MCP SERVER FINDING |
|---|---|
| ddns[.]1433[.]eu[.]org | Has no WHOIS data; registered with four other subdomains; no threat intelligence hits for the apex domain but public sandboxes flag sibling *[.]dns[.]1433[.]eu[.]org hosts as malicious; most suspicious subdomain |
| e598292a5fbd[.]ngrok-free[.]app | Has a masked registrant; no threat intelligence hits though 25 sibling *[.]ngrok-free[.]app hosts were tagged as malware |
| interact[.]gateway[.]horizon3ai[.]com | No threat intelligence hits; most benign subdomain |
| main[.]interacth3[.]io | Has nine other subdomains; no threat intelligence hits |
| zeetcckhtudizieudqyck5o4ez16y973h[.]oast[.]fun | No threat intelligence hits though 42 *[.]oast[.]fun subdomains were tagged as malware |
After learning more about the subdomain IoCs, we then turned our attention toward the 14 domain IoCs.
Looking at sample network traffic data from the IASC, we found out that four unique client IP addresses communicated with three of the domain IoCs via 12 DNS queries between 16 June and 19 July 2026.

All three domain IoCs that continued to record hits—oast[.]fun, oast[.]site, and oast[.]me—were associated with the Ivanti EPMM attacks. It is also interesting to see communications since the attacks were reported as far back as February 2026.
We queried the domain IoCs on Typosquatting API and discovered that three—oast[.]site, oast[.]live, and oast[.]fun—were all connected to the Ivanti EPMM attacks. They were bulk-registered with one other domain—oast[.]online—on 11 January 2022.

Next, we queried the domain IoCs on WHOIS API and completed missing data points with the help of Domain Info API. We learned that:

While one domain did not have a registrar on record, the remaining 13 were administered by four registrars.

While two domains did not have a registrant country on record, the remaining 12 were registered in two countries.

Finally, we queried the domain IoCs on DNS Chronicle API and learned that 13 recorded 2,201 historical domain-to-IP resolutions over time. Here are more details for four examples, one for each attack.
| ATTACK | DOMAIN IoC | NUMBER OF DOMAIN-TO-IP RESOLUTIONS | DATES SEEN |
|---|---|---|---|
| Ivanti EPMM Attacks | oast[.]fun | 360 | 07/28/21–07/12/26 |
| Stryker Wiper Attack | handala-hack[.]to | 60 | 10/12/24–07/02/26 |
| ShinyHunters: Canvas Breach | shinyhunte[.]rs | 35 | 05/29/24–04/06/26 |
| ShinyHunters: Broader Attacks | azurenetfiles[.]net | 2 | 05/28/26–07/14/26 |
Here, we sought more information on the 35 IP IoCs.
First off, we learned that 161 unique IP addresses that could belong to victims communicated with 20 IP IoCs between 22 January and 17 July 2026 after looking at sample network traffic data from the IASC.

We then queried the IP IoCs on Bulk IP Geolocation Lookup and discovered that:

While eight IP IoCs did not have ISPs on record, the remaining 27 were administered by 19 ISPs.

Lastly, we queried the IP IoCs on DNS Chronicle API and found out that 30 posted 9,031 IP-to-domain resolutions over time. Take a look at more details for five examples below.
| ATTACK | IP IoC | NUMBER OF IP-TO-DOMAIN RESOLUTIONS | DATES SEEN |
|---|---|---|---|
| Cisco SD-WAN Attacks | 23[.]245[.]7[.]178 | 646 | 05/19/1–02/04/22 |
| Stryker Wiper Attack | 82[.]25[.]35[.]25 | 571 | 02/05/1–07/20/26 |
| Ivanti EPMM Attacks | 152[.]32[.]173[.]138 | 1,000 | 07/09/2–08/18/25 |
| ShinyHunters: Canvas Breach | 91[.]215[.]85[.]103 | 5 | 03/22/2–07/09/26 |
| ShinyHunters: Broader Attacks | 142[.]11[.]200[.]186 | 1,000 | 02/06/17–1/04/20 |
After learning more about the network IoCs, we searched for new connected artifacts next.
We began by querying the domain IoCs on WHOIS History API and found out that five had 12 unique email addresses in their historical WHOIS records. Further scrutiny revealed that two were public email addresses.
We queried the public email addresses on Reverse WHOIS API and uncovered six unique email-connected domains.
Next, we queried the domain IoCs on DNS Lookup API, which led to the discovery of 13 unique additional IP addresses.
This post only contains a snapshot of the full research. Download the complete findings and a sample of the additional artifacts on our website or contact us to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.
Disclaimer: We take a cautionary stance toward threat detection and aim to provide relevant information to help protect against potential dangers. Consequently, it is possible that some entities identified as “threats” or “malicious” may eventually be deemed harmless upon further investigation or changes in context. We strongly recommend conducting supplementary investigations to corroborate the information provided herein.
Sponsored byIPv4.Global
Sponsored byWhoisXML API
Sponsored byVerisign
Sponsored byVerisign
Sponsored byRadix
Sponsored byDNIB.com
Sponsored byCSC