|
||
|
||
The Swiss Cyber Institute named the most notorious ransomware as of April 2026. We zoomed into five of them—LockBit, Cl0p, Akira, Medusa, and Qilin—in a bid to know more about their network IoCs and identify new artifacts.
Since the report did not go into detail about the malware’s IoCs, we obtained them from the sources enumerated below instead.
| RANSOMWARE | NETWORK IoC SOURCE | NUMBER OF NETWORK IoCs PUBLISHED(Limited to domains, subdomains, URLs, hostnames, and IPs) |
|---|---|---|
| LockBit | Seeking Counsel: Ongoing Targeted Campaign Against U.S. Law Firms | 3 domains 7 IPs TOTAL = 10 |
| Cl0p | Clop Ransomware: Inside the US$500-Million Cybercrime Empire Driving February 2026’s Breach Surge | 5 domains 14 IPs TOTAL = 19 |
| Akira | The Akira Ransomware Syndicate: A Comprehensive Strategic Assessment, Operational Analysis, and Threat Trajectory (2023—2026) | 17 IPs TOTAL = 17 |
| Medusa | Under Medusa’s Gaze: How Darktrace Uncovers RMM Abuse in Ransomware Campaigns | 3 subdomains 1 domain 13 IPs TOTAL = 17 |
| Qilin | Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware | 22 IPs TOTAL = 22 |
We collated a total of 85 network IoCs from the five sources above. After extracting domains from the subdomain IoCs and filtering out those that belonged to legitimate entities aided by the WhoisXML API MCP Server, we ended up with 84 network IoCs comprising three subdomains, eight domains, and 73 IP addresses for our analysis.
Our DNS infrastructure analysis for the five most notorious ransomware led to these findings:
A sample of the additional artifacts obtained from our analysis is available for download from our website.
We kicked our investigation off by looking more closely at the three subdomain IoCs, all of which were related to Medusa. The WhoisXML API MCP Server had these revelations.
| SUBDOMAIN IoC | WXA MCP SERVER FINDING |
|---|---|
| erp[.]ranasons[.]com | Did not have public WHOIS details; likely served as an ERP application host for a retail/e-commerce business; parent domain is approximately 27 years old |
| pruebas[.]pintacuario[.]mx | Likely serves as a staging/test environment for an Odoo ERP deployment; the very short TTL suggests frequent repointing |
| wizarr[.]manate[.]ch | Likely serves as an open-source invite/user-management frontend for a private Plex/Jellyfin media server |
As shown above, all three could have been compromised at the time they were utilized by Medusa threat actors since none of them were categorized as malicious at the time of writing.
We then focused on the eight domain IoCs associated with LockBit (3 domains) and Cl0p (5 domains).
Sample network traffic data from the IASC revealed that 59 unique client IP addresses communicated with three of the domain IoCs connected to LockBit via 16,400 DNS queries between 24 May and 22 July 2026. These IP addresses fell under six ASNs.

At this point, we analyzed the five domain IoCs related to Cl0p only since those connected to LockBit were wildcards. We queried them on WHOIS API next and filled in missing details using Domain Info API. We learned that:

They were administered by four registrars.

Next, we queried the five nonwildcard domain IoCs related to Cl0p on DNS Chronicle API and discovered that they posted 421 historical domain-to-IP resolutions over time. Take a look at more information for three examples below.
| DOMAIN IoC | NUMBER OF DOMAIN-TO-IP RESOLUTIONS | DATES SEEN |
|---|---|---|
| zoom[.]voyage | 187 | 12/28/19–06/24/26 |
| jirostrogud[.]com | 114 | 10/07/22–07/17/25 |
| hiperfdhaus[.]com | 81 | 10/06/22–07/17/25 |
The first resolution dates of the domain IoCs were all aged.
This time, we zoomed in on the 73 IP IoCs.
Sample network traffic data from the IASC for one showed that 19,360 distinct IP addresses potentially owned by victims communicated with 55 of the IP IoCs between 24 January and 22 July 2026. They fell under 531 unique ASNs.

We also queried the IP IoCs for the five ransomware on Bulk IP Geolocation Lookup and discovered that:

While 11 did not have ISPs on record, the remaining 62 were administered by 34 ISPs.

Next, we queried the IP IoCs on DNS Chronicle API and found out that 57 recorded 13,899 historical IP-to-domain resolutions over time. Here are more details for five examples.
| RANSOMWARE | IP IoC | NUMBER OF IP-TO-DOMAIN RESOLUTIONS | DATES SEEN |
|---|---|---|---|
| LockBit | 174[.]169[.]162[.]62 | 289 | 02/06/17–02/04/22 |
| Cl0p | 185[.]181[.]230[.]103 | 1,000 | 12/21/18–09/29/20 |
| Akira | 104[.]194[.]8[.]58 | 1,000 | 12/01/20–01/15/21 |
| Medusa | 31[.]220[.]45[.]120 | 1,000 | 02/05/17–09/11/20 |
| Qilin | 82[.]29[.]54[.]140 | 883 | 02/05/17–08/10/24 |
Like the domain IoCs, which first resolved years ago, 52 IP IoCs with historical IP-to-domain resolutions did so, too.
We started our hunt for new artifacts by querying the domain IoCs on WHOIS History API and learned that six had 37 distinct email addresses in their historical records. Further scrutiny revealed that 10 were public email addresses. Of these, however, one did not appear in any other WHOIS record, while two could belong to domainers, leaving us with seven for the next step.
After querying the public email addresses on Reverse WHOIS API, we discovered 5,100 unique email-connected domains after those tagged as IoCs were filtered out.
Threat Intelligence API queries for the email-connected domains showed that two have already been weaponized for various campaigns. One example is answersite[.]com, which has been associated with malware distribution.
This post only contains a snapshot of the full research. Download the complete findings and a sample of the additional artifacts on our website or contact us to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.
Disclaimer: We take a cautionary stance toward threat detection and aim to provide relevant information to help protect against potential dangers. Consequently, it is possible that some entities identified as “threats” or “malicious” may eventually be deemed harmless upon further investigation or changes in context. We strongly recommend conducting supplementary investigations to corroborate the information provided herein.
Sponsored byDNIB.com
Sponsored byIPv4.Global
Sponsored byVerisign
Sponsored byVerisign
Sponsored byRadix
Sponsored byWhoisXML API
Sponsored byCSC