NordVPN Promotion

Home / Industry

DNS Spotlight: 2026’s 5 Most Notorious Ransomware

The Swiss Cyber Institute named the most notorious ransomware as of April 2026. We zoomed into five of them—LockBit, Cl0p, Akira, Medusa, and Qilin—in a bid to know more about their network IoCs and identify new artifacts.

Since the report did not go into detail about the malware’s IoCs, we obtained them from the sources enumerated below instead.

RANSOMWARENETWORK IoC SOURCENUMBER OF NETWORK IoCs PUBLISHED(Limited to domains, subdomains, URLs, hostnames, and IPs)
LockBitSeeking Counsel: Ongoing Targeted Campaign Against U.S. Law Firms3 domains
7 IPs
TOTAL = 10
Cl0pClop Ransomware: Inside the US$500-Million Cybercrime Empire Driving February 2026’s Breach Surge5 domains
14 IPs
TOTAL = 19
AkiraThe Akira Ransomware Syndicate: A Comprehensive Strategic Assessment, Operational Analysis, and Threat Trajectory (2023—2026)17 IPs
TOTAL = 17
MedusaUnder Medusa’s Gaze: How Darktrace Uncovers RMM Abuse in Ransomware Campaigns3 subdomains
1 domain
13 IPs
TOTAL = 17
QilinCookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware22 IPs
TOTAL = 22

We collated a total of 85 network IoCs from the five sources above. After extracting domains from the subdomain IoCs and filtering out those that belonged to legitimate entities aided by the WhoisXML API MCP Server, we ended up with 84 network IoCs comprising three subdomains, eight domains, and 73 IP addresses for our analysis.

Our DNS infrastructure analysis for the five most notorious ransomware led to these findings:

  • 59 unique client IP addresses that communicated with three of the domain IoCs
  • 19,360 distinct IP addresses that could belong to victims that communicated with 55 of the IP IoCs
  • 5,100 email-connected domains, two were confirmed malicious
  • Two additional IP addresses, both were confirmed malicious
  • 60 IP-connected domains, four were confirmed malicious
  • 15,664 string-connected domains, 31 were confirmed malicious

A sample of the additional artifacts obtained from our analysis is available for download from our website.

3 Ransomware Subdomain IoCs Scrutinized

We kicked our investigation off by looking more closely at the three subdomain IoCs, all of which were related to Medusa. The WhoisXML API MCP Server had these revelations.

SUBDOMAIN IoCWXA MCP SERVER FINDING
erp[.]ranasons[.]comDid not have public WHOIS details; likely served as an ERP application host for a retail/e-commerce business; parent domain is approximately 27 years old
pruebas[.]pintacuario[.]mxLikely serves as a staging/test environment for an Odoo ERP deployment; the very short TTL suggests frequent repointing
wizarr[.]manate[.]chLikely serves as an open-source invite/user-management frontend for a private Plex/Jellyfin media server

As shown above, all three could have been compromised at the time they were utilized by Medusa threat actors since none of them were categorized as malicious at the time of writing.

8 Ransomware Domain IoCs Dissected

We then focused on the eight domain IoCs associated with LockBit (3 domains) and Cl0p (5 domains).

Sample network traffic data from the IASC revealed that 59 unique client IP addresses communicated with three of the domain IoCs connected to LockBit via 16,400 DNS queries between 24 May and 22 July 2026. These IP addresses fell under six ASNs.

At this point, we analyzed the five domain IoCs related to Cl0p only since those connected to LockBit were wildcards. We queried them on WHOIS API next and filled in missing details using Domain Info API. We learned that:

  • They were created between 28 December 2022 and 6 November 2025, making them all relatively old when they were used for the campaigns.
  • They were administered by four registrars.

  • All five were registered in the U.S.

Next, we queried the five nonwildcard domain IoCs related to Cl0p on DNS Chronicle API and discovered that they posted 421 historical domain-to-IP resolutions over time. Take a look at more information for three examples below.

DOMAIN IoCNUMBER OF DOMAIN-TO-IP RESOLUTIONSDATES SEEN
zoom[.]voyage18712/28/19–06/24/26
jirostrogud[.]com11410/07/22–07/17/25
hiperfdhaus[.]com8110/06/22–07/17/25

The first resolution dates of the domain IoCs were all aged.

73 Ransomware IP IoCs Investigated

This time, we zoomed in on the 73 IP IoCs.

Sample network traffic data from the IASC for one showed that 19,360 distinct IP addresses potentially owned by victims communicated with 55 of the IP IoCs between 24 January and 22 July 2026. They fell under 531 unique ASNs.

We also queried the IP IoCs for the five ransomware on Bulk IP Geolocation Lookup and discovered that:

  • They were geolocated in 21 countries. Almost half of them, 35 to be exact, originated in the U.S., the sole registrant country of the domain IoCs we identified earlier.
  • While 11 did not have ISPs on record, the remaining 62 were administered by 34 ISPs.

Next, we queried the IP IoCs on DNS Chronicle API and found out that 57 recorded 13,899 historical IP-to-domain resolutions over time. Here are more details for five examples.

RANSOMWAREIP IoCNUMBER OF IP-TO-DOMAIN RESOLUTIONSDATES SEEN
LockBit174[.]169[.]162[.]6228902/06/17–02/04/22
Cl0p185[.]181[.]230[.]1031,00012/21/18–09/29/20
Akira104[.]194[.]8[.]581,00012/01/20–01/15/21
Medusa31[.]220[.]45[.]1201,00002/05/17–09/11/20
Qilin82[.]29[.]54[.]14088302/05/17–08/10/24

Like the domain IoCs, which first resolved years ago, 52 IP IoCs with historical IP-to-domain resolutions did so, too.

Thousands of New Artifacts Amassed

We started our hunt for new artifacts by querying the domain IoCs on WHOIS History API and learned that six had 37 distinct email addresses in their historical records. Further scrutiny revealed that 10 were public email addresses. Of these, however, one did not appear in any other WHOIS record, while two could belong to domainers, leaving us with seven for the next step.

After querying the public email addresses on Reverse WHOIS API, we discovered 5,100 unique email-connected domains after those tagged as IoCs were filtered out.

Threat Intelligence API queries for the email-connected domains showed that two have already been weaponized for various campaigns. One example is answersite[.]com, which has been associated with malware distribution.

This post only contains a snapshot of the full research. Download the complete findings and a sample of the additional artifacts on our website or contact us to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

Disclaimer: We take a cautionary stance toward threat detection and aim to provide relevant information to help protect against potential dangers. Consequently, it is possible that some entities identified as “threats” or “malicious” may eventually be deemed harmless upon further investigation or changes in context. We strongly recommend conducting supplementary investigations to corroborate the information provided herein.

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By WhoisXML API, A Domain Research, Whois, DNS, and Threat Intelligence API and Data Provider

Whois API, Inc. (WhoisXML API) is a big data and API company that provides domain research & monitoring, Whois, DNS, IP, and threat intelligence API, data and tools to a variety of industries.

Visit Page

Filed Under

Comments

Commenting is not available in this channel entry.
CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

DNS

Sponsored byDNIB.com

IPv4 Markets

Sponsored byIPv4.Global

Domain Names

Sponsored byVerisign

Cybersecurity

Sponsored byVerisign

New TLDs

Sponsored byRadix

DNS Security

Sponsored byWhoisXML API

Brand Protection

Sponsored byCSC

NordVPN Promotion