<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:admin="http://webns.net/mvcb/"
	xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
	xmlns:content="http://purl.org/rss/1.0/modules/content/">

	<channel>

	<title>&#45; CircleID</title>
	<link>https://www.circleid.com/blogs/</link>
	<description>Postings from  on CircleID</description>
	<dc:language>en</dc:language>
	<dc:rights>Copyright 2026, unless where otherwise noted.</dc:rights>
	<dc:date>2026-06-12T18:38:00+00:00</dc:date>

	
	<item>
		<title> DNS Deep Dive: Pushpaganda Network IoCs (Featured Blog)</title>
		<guid isPermaLink="true">https://circleid.com/postsdns-deep-dive-pushpaganda-network-iocs</guid>
		<link>https://circleid.com/postsdns-deep-dive-pushpaganda-network-iocs</link>
		<description><![CDATA[A DNS investigation into Pushpaganda, an AI-powered scam network that infiltrated Google Discovery feeds, uncovered more than 1,000 connected domains, 162 linked IP addresses, and evidence that several infrastructure assets were registered with malicious intent. <a href="https://circleid.com/postsdns-deep-dive-pushpaganda-network-iocs">More...</a>]]></description>
		<dc:date>2026-06-12T11:38:00-07:00</dc:date>
	</item>
	
	<item>
		<title> The DNS Anatomy of the Axios Supply Chain Attack (Featured Blog)</title>
		<guid isPermaLink="true">https://circleid.com/poststhe-dns-anatomy-of-the-axios-supply-chain-attack</guid>
		<link>https://circleid.com/poststhe-dns-anatomy-of-the-axios-supply-chain-attack</link>
		<description><![CDATA[A DNS-focused investigation into the Axios NPM supply chain attack uncovered typosquatting networks, victim-linked infrastructure, and hundreds of connected domains, revealing how malicious actors built and sustained a sprawling cyber campaign around compromised software dependencies. <a href="https://circleid.com/poststhe-dns-anatomy-of-the-axios-supply-chain-attack">More...</a>]]></description>
		<dc:date>2026-06-12T11:38:00-07:00</dc:date>
	</item>
	
	<item>
		<title> An Analysis of the AtlasCross RAT Network IoCs (Featured Blog)</title>
		<guid isPermaLink="true">https://circleid.com/postsan-analysis-of-the-atlascross-rat-network-iocs</guid>
		<link>https://circleid.com/postsan-analysis-of-the-atlascross-rat-network-iocs</link>
		<description><![CDATA[Hexastrike traced an AtlasCross RAT campaign linked to Silver Fox, uncovering spoofed domains, victim infrastructure, and malicious network artifacts that reveal how attackers exploited trusted software brands to widen compromise and persistence. <a href="https://circleid.com/postsan-analysis-of-the-atlascross-rat-network-iocs">More...</a>]]></description>
		<dc:date>2026-06-12T11:38:00-07:00</dc:date>
	</item>
	
	<item>
		<title> Global Domain Activity Trends Seen in Q1 2026 (Featured Blog)</title>
		<guid isPermaLink="true">https://circleid.com/postsglobal-domain-activity-trends-seen-in-q1-2026</guid>
		<link>https://circleid.com/postsglobal-domain-activity-trends-seen-in-q1-2026</link>
		<description><![CDATA[Q1 2026 domain activity showed registrations concentrated in a handful of TLDs, with 6.7 million new domains flagged as malicious, offering fresh insight into global DNS patterns and cybersecurity risks as shifting registration trends reshape. <a href="https://circleid.com/postsglobal-domain-activity-trends-seen-in-q1-2026">More...</a>]]></description>
		<dc:date>2026-06-12T11:38:00-07:00</dc:date>
	</item>
	
	<item>
		<title> A Look Back at the Top 10 Ransomware of 2025 (Featured Blog)</title>
		<guid isPermaLink="true">https://circleid.com/postsa-look-back-at-the-top-10-ransomware-of-2025</guid>
		<link>https://circleid.com/postsa-look-back-at-the-top-10-ransomware-of-2025</link>
		<description><![CDATA[A retrospective analysis of 2025's top ransomware groups reveals how DNS traces, historical WHOIS records, and network IoCs exposed hidden infrastructure, affiliate activity, and thousands of potential victim connections linked to major cybercriminal operations. <a href="https://circleid.com/postsa-look-back-at-the-top-10-ransomware-of-2025">More...</a>]]></description>
		<dc:date>2026-06-12T11:38:00-07:00</dc:date>
	</item>
	
	<item>
		<title> A Network IoC Analysis for 8 Iran-Affiliated APT Groups (Featured Blog)</title>
		<guid isPermaLink="true">https://circleid.com/postsa-network-ioc-analysis-for-8-iran-affiliated-apt-groups</guid>
		<link>https://circleid.com/postsa-network-ioc-analysis-for-8-iran-affiliated-apt-groups</link>
		<description><![CDATA[An analysis of 191 network indicators tied to eight Iran-affiliated APT groups uncovered malicious domains, active infrastructure, thousands of victim-linked IP interactions, and coordinated DNS activity, revealing the breadth and persistence of Tehran-linked cyber operations amid escalating regional tensions. <a href="https://circleid.com/postsa-network-ioc-analysis-for-8-iran-affiliated-apt-groups">More...</a>]]></description>
		<dc:date>2026-06-12T11:38:00-07:00</dc:date>
	</item>
	
	<item>
		<title> Unearthing DNS Facts about UAT-8099 (Featured Blog)</title>
		<guid isPermaLink="true">https://circleid.com/postsunearthing-dns-facts-about-uat-8099</guid>
		<link>https://circleid.com/postsunearthing-dns-facts-about-uat-8099</link>
		<description><![CDATA[WhoisXML API analysis deepens understanding of the UAT-8099 campaign, uncovering expanded DNS infrastructure, early indicators of malicious intent, and thousands of linked artifacts, underscoring the group's evolving tactics and regional focus across Asia. <a href="https://circleid.com/postsunearthing-dns-facts-about-uat-8099">More...</a>]]></description>
		<dc:date>2026-06-12T11:38:00-07:00</dc:date>
	</item>
	
	<item>
		<title> ForceMemo in the DNS Spotlight (Featured Blog)</title>
		<guid isPermaLink="true">https://circleid.com/postsforcememo-in-the-dns-spotlight</guid>
		<link>https://circleid.com/postsforcememo-in-the-dns-spotlight</link>
		<description><![CDATA[Researchers tracing the ForceMemo campaign uncover a sprawling DNS footprint, linking compromised GitHub repositories to suspicious domains, shared infrastructure and fresh artifacts, suggesting a coordinated operation that continues to evolve despite partial attribution. <a href="https://circleid.com/postsforcememo-in-the-dns-spotlight">More...</a>]]></description>
		<dc:date>2026-06-12T11:38:00-07:00</dc:date>
	</item>
	
	<item>
		<title> DNS Analysis of the Keenadu Backdoor Network (Featured Blog)</title>
		<guid isPermaLink="true">https://circleid.com/postsdns-analysis-of-the-keenadu-backdoor-network</guid>
		<link>https://circleid.com/postsdns-analysis-of-the-keenadu-backdoor-network</link>
		<description><![CDATA[Keenadu backdoor embedded in Android firmware exploits supply chains and OTA updates, while DNS analysis of its infrastructure reveals coordinated domains, IP links, and early warning signals pointing to premeditated, scalable cybercriminal operations globally distributed. <a href="https://circleid.com/postsdns-analysis-of-the-keenadu-backdoor-network">More...</a>]]></description>
		<dc:date>2026-06-12T11:38:00-07:00</dc:date>
	</item>
	
	<item>
		<title> A DNS Exploration of Operation Olalampo (Featured Blog)</title>
		<guid isPermaLink="true">https://circleid.com/postsa-dns-exploration-of-operation-olalampo</guid>
		<link>https://circleid.com/postsa-dns-exploration-of-operation-olalampo</link>
		<description><![CDATA[MuddyWater's Operation Olalampo targets MENA entities using new malware and Telegram-based control, as DNS analysis uncovers fresh infrastructure, thousands of linked domains, and expanded indicators pointing to a broader, coordinated campaign. <a href="https://circleid.com/postsa-dns-exploration-of-operation-olalampo">More...</a>]]></description>
		<dc:date>2026-06-12T11:38:00-07:00</dc:date>
	</item>
	
	<item>
		<title> DNS Deep Dive: LummaStealer + CastleLoader = Larger Threat (Featured Blog)</title>
		<guid isPermaLink="true">https://circleid.com/postsdns-deep-dive-lummastealer-castleloader-larger-threat</guid>
		<link>https://circleid.com/postsdns-deep-dive-lummastealer-castleloader-larger-threat</link>
		<description><![CDATA[LummaStealer's revival, paired with CastleLoader, reveals a more evasive malware ecosystem, leveraging obfuscation, DNS agility and vast infrastructure to reach over 100,000 potential victims while spawning hundreds of linked malicious domains and IPs globally observed. <a href="https://circleid.com/postsdns-deep-dive-lummastealer-castleloader-larger-threat">More...</a>]]></description>
		<dc:date>2026-06-12T11:38:00-07:00</dc:date>
	</item>
	
	<item>
		<title> A Look Back at 11 of the Red Report 2026 Featured Threats (Featured Blog)</title>
		<guid isPermaLink="true">https://circleid.com/postsa-look-back-at-11-of-the-red-report-2026-featured-threats</guid>
		<link>https://circleid.com/postsa-look-back-at-11-of-the-red-report-2026-featured-threats</link>
		<description><![CDATA[An analysis of 11 cyber threats from Red Report 2026 reveals how attackers exploit core MITRE ATT&CK techniques, with DNS and IoC data exposing early warning signals, infrastructure scale, and evolving tactics across campaigns globally. <a href="https://circleid.com/postsa-look-back-at-11-of-the-red-report-2026-featured-threats">More...</a>]]></description>
		<dc:date>2026-06-12T11:38:00-07:00</dc:date>
	</item>
	
	<item>
		<title> A Close Look under the DNS Hood of CoolClient (Featured Blog)</title>
		<guid isPermaLink="true">https://circleid.com/postsa-close-look-under-the-dns-hood-of-coolclient</guid>
		<link>https://circleid.com/postsa-close-look-under-the-dns-hood-of-coolclient</link>
		<description><![CDATA[Security researchers trace an updated CoolClient backdoor used by HoneyMyte, uncovering malicious domains, subdomains and IP links, and revealing a wider infrastructure of email and DNS-connected assets tied to data theft operations globally active. <a href="https://circleid.com/postsa-close-look-under-the-dns-hood-of-coolclient">More...</a>]]></description>
		<dc:date>2026-06-12T11:38:00-07:00</dc:date>
	</item>
	
	<item>
		<title> Probing the DNS Depths of PeckBirdy (Featured Blog)</title>
		<guid isPermaLink="true">https://circleid.com/postsprobing-the-dns-depths-of-peckbirdy</guid>
		<link>https://circleid.com/postsprobing-the-dns-depths-of-peckbirdy</link>
		<description><![CDATA[An analysis of DNS and WHOIS data tied to the PeckBirdy C&C framework uncovers expanded infrastructure, linking known IoCs to malicious domains, IPs, and email-connected assets across years of activity. <a href="https://circleid.com/postsprobing-the-dns-depths-of-peckbirdy">More...</a>]]></description>
		<dc:date>2026-06-12T11:38:00-07:00</dc:date>
	</item>
	
	<item>
		<title> What Remains of Black Basta Now That Alleged Gang Leader Joined the Most Wanted List? (Featured Blog)</title>
		<guid isPermaLink="true">https://circleid.com/postswhat-remains-of-black-basta-now-that-alleged-gang-leader-joined-the-most-wanted-list</guid>
		<link>https://circleid.com/postswhat-remains-of-black-basta-now-that-alleged-gang-leader-joined-the-most-wanted-list</link>
		<description><![CDATA[As authorities pursue Black Basta's alleged leader, new analysis of campaign indicators reveals sprawling infrastructure, thousands of linked domains, and persistent ransomware tactics that rely on phishing, known vulnerabilities, and double-extortion pressure. <a href="https://circleid.com/postswhat-remains-of-black-basta-now-that-alleged-gang-leader-joined-the-most-wanted-list">More...</a>]]></description>
		<dc:date>2026-06-12T11:38:00-07:00</dc:date>
	</item>
	

	</channel>
</rss>