NordVPN Promotion

Home / Industry

5 of the Biggest Cyber Attacks in 2026 So Far: DNS Deep Dive

CRN recently named the biggest cyber attacks and breaches the world has seen so far in 2026, and we zoomed in on five of them. We specifically tackled the attacks below.

CYBER ATTACKIoC SOURCETHREAT GROUPDATE PUBLISHED
Cisco SD-WAN AttacksZero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN ManagerUnknown06/25/26
Stryker Wiper AttackTimeline Reconstruction: Stryker Handala Threat Group Wiper AttackStryker Handala03/20/26
Ivanti EPMM AttacksCritical Vulnerabilities in Ivanti EPMM ExploitedUnknown02/17/26
ShinyHunters: Canvas BreachCanvas × ShinyHunters: Full Intelligence Report—May 2026ShinyHunters05/13/26
ShinyHunters: Broader Attacks(1 sample only)ShinyHunters Targets Education Sector with Oracle PeopleSoft ExploitShinyHunters06/12/26

We collated network IoCs comprising subdomains, domains, and IP addresses from the sources identified above.

Note that we extracted some domains from the subdomain IoCs then filtered out those that were owned by legitimate companies aided by the WhoisXML API MCP Server and one that was on the Tor network. After that, we ended up with 54 IoCs for our investigation comprising five subdomains, 14 domains, and 35 IP addresses. Take a look at a more detailed breakdown below.

CYBER ATTACKSUBDOMAIN IoCDOMAIN IoCIP IoC
Cisco SD-WAN AttacksNANA8
Stryker Wiper AttackNA34
Ivanti EPMM Attacks51417
ShinyHunters: Canvas BreachNA21
ShinyHunters: Broader Attacks(1 sample only)NA15

Our analysis of the five attacks led to these discoveries:

  • Four unique client IP addresses that communicated with three domain IoCs
  • Three domain IoCs that appeared in one typosquatting group
  • 161 distinct IP addresses potentially owned by victims that communicated with 20 IP IoCs
  • Six email-connected domains
  • 13 additional IP addresses, nine were confirmed malicious
  • 132 IP-connected domains
  • 753 string-connected domains, two were confirmed malicious

A sample of the additional artifacts obtained from our analysis is available for download from our website.

Seeking More Information about the Subdomain IoCs Affiliated with the 5 Attacks

We kicked off our analysis by zooming in on the five subdomain IoCs, all connected to the Ivanti EPMM attacks. We summed up the results of our WhoisXML API MCP Server queries below.

SUBDOMAIN IoCWXA MCP SERVER FINDING
ddns[.]1433[.]eu[.]orgHas no WHOIS data; registered with four other subdomains; no threat intelligence hits for the apex domain but public sandboxes flag sibling *[.]dns[.]1433[.]eu[.]org hosts as malicious; most suspicious subdomain
e598292a5fbd[.]ngrok-free[.]appHas a masked registrant; no threat intelligence hits though 25 sibling *[.]ngrok-free[.]app hosts were tagged as malware
interact[.]gateway[.]horizon3ai[.]comNo threat intelligence hits; most benign subdomain
main[.]interacth3[.]ioHas nine other subdomains; no threat intelligence hits
zeetcckhtudizieudqyck5o4ez16y973h[.]oast[.]funNo threat intelligence hits though 42 *[.]oast[.]fun subdomains were tagged as malware

Diving Deeper into the Domain IoCs Associated with the 5 Attacks

After learning more about the subdomain IoCs, we then turned our attention toward the 14 domain IoCs.

Looking at sample network traffic data from the IASC, we found out that four unique client IP addresses communicated with three of the domain IoCs via 12 DNS queries between 16 June and 19 July 2026.

All three domain IoCs that continued to record hits—oast[.]fun, oast[.]site, and oast[.]me—were associated with the Ivanti EPMM attacks. It is also interesting to see communications since the attacks were reported as far back as February 2026.

We queried the domain IoCs on Typosquatting API and discovered that three—oast[.]site, oast[.]live, and oast[.]fun—were all connected to the Ivanti EPMM attacks. They were bulk-registered with one other domain—oast[.]online—on 11 January 2022.

Next, we queried the domain IoCs on WHOIS API and completed missing data points with the help of Domain Info API. We learned that:

  • They were a mix of aged and new domains created between 13 May 2016 (ceye[.]io; Ivanti EPMM Attacks) and 27 May 2026 (azurenetfiles[.]net; ShinyHunters: Broader Attacks).
  • While one domain did not have a registrar on record, the remaining 13 were administered by four registrars.

  • While two domains did not have a registrant country on record, the remaining 12 were registered in two countries.

Finally, we queried the domain IoCs on DNS Chronicle API and learned that 13 recorded 2,201 historical domain-to-IP resolutions over time. Here are more details for four examples, one for each attack.

ATTACKDOMAIN IoCNUMBER OF DOMAIN-TO-IP RESOLUTIONSDATES SEEN
Ivanti EPMM Attacksoast[.]fun36007/28/21–07/12/26
Stryker Wiper Attackhandala-hack[.]to6010/12/24–07/02/26
ShinyHunters: Canvas Breachshinyhunte[.]rs3505/29/24–04/06/26
ShinyHunters: Broader Attacksazurenetfiles[.]net205/28/26–07/14/26

Investigating the IP IoCs Related to the 5 Attacks

Here, we sought more information on the 35 IP IoCs.

First off, we learned that 161 unique IP addresses that could belong to victims communicated with 20 IP IoCs between 22 January and 17 July 2026 after looking at sample network traffic data from the IASC.

We then queried the IP IoCs on Bulk IP Geolocation Lookup and discovered that:

  • They were geolocated in 12 countries, including one of the registrant countries named earlier—the U.S.
  • While eight IP IoCs did not have ISPs on record, the remaining 27 were administered by 19 ISPs.

Lastly, we queried the IP IoCs on DNS Chronicle API and found out that 30 posted 9,031 IP-to-domain resolutions over time. Take a look at more details for five examples below.

ATTACKIP IoCNUMBER OF IP-TO-DOMAIN RESOLUTIONSDATES SEEN
Cisco SD-WAN Attacks23[.]245[.]7[.]17864605/19/1–02/04/22
Stryker Wiper Attack82[.]25[.]35[.]2557102/05/1–07/20/26
Ivanti EPMM Attacks152[.]32[.]173[.]1381,00007/09/2–08/18/25
ShinyHunters: Canvas Breach91[.]215[.]85[.]103503/22/2–07/09/26
ShinyHunters: Broader Attacks142[.]11[.]200[.]1861,00002/06/17–1/04/20

Hunting for New Artifacts Connected to the 5 Attacks

After learning more about the network IoCs, we searched for new connected artifacts next.

We began by querying the domain IoCs on WHOIS History API and found out that five had 12 unique email addresses in their historical WHOIS records. Further scrutiny revealed that two were public email addresses.

We queried the public email addresses on Reverse WHOIS API and uncovered six unique email-connected domains.

Next, we queried the domain IoCs on DNS Lookup API, which led to the discovery of 13 unique additional IP addresses.

This post only contains a snapshot of the full research. Download the complete findings and a sample of the additional artifacts on our website or contact us to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

Disclaimer: We take a cautionary stance toward threat detection and aim to provide relevant information to help protect against potential dangers. Consequently, it is possible that some entities identified as “threats” or “malicious” may eventually be deemed harmless upon further investigation or changes in context. We strongly recommend conducting supplementary investigations to corroborate the information provided herein.

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By WhoisXML API, A Domain Research, Whois, DNS, and Threat Intelligence API and Data Provider

Whois API, Inc. (WhoisXML API) is a big data and API company that provides domain research & monitoring, Whois, DNS, IP, and threat intelligence API, data and tools to a variety of industries.

Visit Page

Filed Under

Comments

Commenting is not available in this channel entry.
CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

IPv4 Markets

Sponsored byIPv4.Global

DNS Security

Sponsored byWhoisXML API

Cybersecurity

Sponsored byVerisign

Domain Names

Sponsored byVerisign

New TLDs

Sponsored byRadix

DNS

Sponsored byDNIB.com

Brand Protection

Sponsored byCSC

NordVPN Promotion