<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
  xmlns:admin="http://webns.net/mvcb/"
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
  xmlns:content="http://purl.org/rss/1.0/modules/content/">

Third segment: whois
  
  <channel>

  <title><![CDATA[CircleID]]></title>
  <link>https://circleid.com/topics/whois</link>
  <description>CircleID - Whois</description>
  <dc:language>en</dc:language>
  <dc:rights>Copyright 2026, unless where otherwise noted.</dc:rights>
  <dc:date>2026-09-22T18:08:00+00:00</dc:date>

  
    <item>
      <title><![CDATA[DNS Spotlight: Silver Fox Strikes Anew with a Fake Installer Campaign]]></title>
      <link>https://circleid.com/posts/dns&#45;spotlight&#45;silver&#45;fox&#45;strikes&#45;anew&#45;with&#45;a&#45;fake&#45;installer&#45;campaign</link>
      <guid isPermaLink="true">https://circleid.com/posts/dns&#45;spotlight&#45;silver&#45;fox&#45;strikes&#45;anew&#45;with&#45;a&#45;fake&#45;installer&#45;campaign</guid>

      <description><![CDATA[A Silver Fox-style fake installer campaign used deceptive software download sites to distribute malware, while DNS and WHOIS analysis uncovered typosquatting domains, potential victim traffic and more than 1,500 campaign-connected artifacts.]]></description>
      <dc:date>2026-10-02T08:48:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Jewelbug Targets the Middle East and Asia via Cyber Espionage and Crypto Fraud Campaigns]]></title>
      <link>https://circleid.com/posts/jewelbug&#45;targets&#45;the&#45;middle&#45;east&#45;and&#45;asia&#45;via&#45;cyber&#45;espionage&#45;and&#45;crypto&#45;fraud&#45;campaigns</link>
      <guid isPermaLink="true">https://circleid.com/posts/jewelbug&#45;targets&#45;the&#45;middle&#45;east&#45;and&#45;asia&#45;via&#45;cyber&#45;espionage&#45;and&#45;crypto&#45;fraud&#45;campaigns</guid>

      <description><![CDATA[Researchers linked Jewelbug's cyber espionage and crypto fraud operations to shared infrastructure, while DNS analysis uncovered thousands of connected domains, hundreds of potential victim IP addresses and additional malicious artifacts.]]></description>
      <dc:date>2026-09-28T10:51:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[3 Russian Threat Groups Target Persons of Interest]]></title>
      <link>https://circleid.com/posts/3&#45;russian&#45;threat&#45;groups&#45;target&#45;persons&#45;of&#45;interest</link>
      <guid isPermaLink="true">https://circleid.com/posts/3&#45;russian&#45;threat&#45;groups&#45;target&#45;persons&#45;of&#45;interest</guid>

      <description><![CDATA[A DNS investigation into indicators linked to three Russian threat groups uncovered potentially victim-owned IP addresses and thousands of connected domains, including infrastructure already associated with malicious activity.]]></description>
      <dc:date>2026-09-21T08:49:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Project Jake: A New Model for Domain Registration Data Disclosure]]></title>
      <link>https://circleid.com/posts/project&#45;jake&#45;a&#45;new&#45;model&#45;for&#45;domain&#45;registration&#45;data&#45;disclosure</link>
      <guid isPermaLink="true">https://circleid.com/posts/project&#45;jake&#45;a&#45;new&#45;model&#45;for&#45;domain&#45;registration&#45;data&#45;disclosure</guid>

      <description><![CDATA[Project Jake proposes a voluntary, group-based framework for domain registration data disclosure, giving registrars and registries control over access while establishing standardized agreements, requester validation and sensitivity levels to balance privacy with legitimate data needs.]]></description>
      <dc:date>2026-09-14T08:54:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[DNS Footprinting: SourTrade Distributes Unfinished Malware through Malvertising]]></title>
      <link>https://circleid.com/posts/dns&#45;footprinting&#45;sourtrade&#45;distributes&#45;unfinished&#45;malware&#45;through&#45;malvertising</link>
      <guid isPermaLink="true">https://circleid.com/posts/dns&#45;footprinting&#45;sourtrade&#45;distributes&#45;unfinished&#45;malware&#45;through&#45;malvertising</guid>

      <description><![CDATA[DNS analysis of 96 SourTrade domains uncovered hundreds of connected domains and IP addresses, many flagged as malicious, while identifying indicators that appeared months before researchers formally linked them to the malvertising campaign.]]></description>
      <dc:date>2026-09-11T08:33:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[DNS Spotlight: 2026&#8217;s 5 Most Notorious Ransomware]]></title>
      <link>https://circleid.com/posts/dns&#45;spotlight&#45;2026s&#45;5&#45;most&#45;notorious&#45;ransomware</link>
      <guid isPermaLink="true">https://circleid.com/posts/dns&#45;spotlight&#45;2026s&#45;5&#45;most&#45;notorious&#45;ransomware</guid>

      <description><![CDATA[DNS analysis of 84 network indicators tied to LockBit, Cl0p, Akira, Medusa, and Qilin uncovered thousands of connected domains and IP addresses, including additional artifacts already identified as malicious.]]></description>
      <dc:date>2026-09-08T07:59:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Thirty-Five Years Later, Moscow Comes Looking for the Soviet Union&#8217;s Domain]]></title>
      <link>https://circleid.com/posts/thirty&#45;five&#45;years&#45;later&#45;moscow&#45;comes&#45;looking&#45;for&#45;the&#45;soviet&#45;unions&#45;domain</link>
      <guid isPermaLink="true">https://circleid.com/posts/thirty&#45;five&#45;years&#45;later&#45;moscow&#45;comes&#45;looking&#45;for&#45;the&#45;soviet&#45;unions&#45;domain</guid>

      <description><![CDATA[Russia is imposing state identity verification on .su, the Soviet Union's surviving domain, as researchers uncover criminal infrastructure across the namespace and ICANN pursues a retirement process that could eventually remove it from the global root.]]></description>
      <dc:date>2026-09-01T08:35:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[A DNS Infrastructure Analysis of a Microsoft 365 Device Code Phishing Campaign]]></title>
      <link>https://circleid.com/posts/a&#45;dns&#45;infrastructure&#45;analysis&#45;of&#45;a&#45;microsoft&#45;365&#45;device&#45;code&#45;phishing&#45;campaign</link>
      <guid isPermaLink="true">https://circleid.com/posts/a&#45;dns&#45;infrastructure&#45;analysis&#45;of&#45;a&#45;microsoft&#45;365&#45;device&#45;code&#45;phishing&#45;campaign</guid>

      <description><![CDATA[A DNS investigation into a Microsoft 365 device code phishing campaign uncovered coordinated, disposable infrastructure, including 290 indicators of compromise, 87 malicious IP addresses and hundreds of connected domains, suggesting the operation remains active.]]></description>
      <dc:date>2026-08-28T11:59:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[5 of the Biggest Cyber Attacks in 2026 So Far: DNS Deep Dive]]></title>
      <link>https://circleid.com/posts/5&#45;of&#45;the&#45;biggest&#45;cyber&#45;attacks&#45;in&#45;2026&#45;so&#45;far&#45;dns&#45;deep&#45;dive</link>
      <guid isPermaLink="true">https://circleid.com/posts/5&#45;of&#45;the&#45;biggest&#45;cyber&#45;attacks&#45;in&#45;2026&#45;so&#45;far&#45;dns&#45;deep&#45;dive</guid>

      <description><![CDATA[A DNS deep dive into five major cyber attacks of 2026 uncovers infrastructure linked to Cisco, Ivanti, Stryker and ShinyHunters incidents, revealing hundreds of connected domains and IP addresses that could sharpen threat detection efforts.]]></description>
      <dc:date>2026-08-24T11:43:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Beyond Protocol and Policy: Why Project Jake is Reshaping the Architecture of Internet Trust]]></title>
      <link>https://circleid.com/posts/beyond&#45;protocol&#45;and&#45;policy&#45;why&#45;project&#45;jake&#45;is&#45;reshaping&#45;the&#45;architecture&#45;of&#45;internet&#45;trust</link>
      <guid isPermaLink="true">https://circleid.com/posts/beyond&#45;protocol&#45;and&#45;policy&#45;why&#45;project&#45;jake&#45;is&#45;reshaping&#45;the&#45;architecture&#45;of&#45;internet&#45;trust</guid>

      <description><![CDATA[Project Jake aims to bridge the divide between internet protocols and policy, offering registries, law enforcement and rights holders a decentralised framework for accessing domain-registration data securely while navigating privacy laws and institutional gridlock.]]></description>
      <dc:date>2026-08-24T10:49:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Massive Photo ZIP Campaign Targets Booking.com Partner and Other Hotels across Japan and Europe]]></title>
      <link>https://circleid.com/posts/massive&#45;photo&#45;zip&#45;campaign&#45;targets&#45;booking&#45;dot&#45;com&#45;partner&#45;and&#45;other&#45;hotels</link>
      <guid isPermaLink="true">https://circleid.com/posts/massive&#45;photo&#45;zip&#45;campaign&#45;targets&#45;booking&#45;dot&#45;com&#45;partner&#45;and&#45;other&#45;hotels</guid>

      <description><![CDATA[A sprawling phishing campaign targeting hotels in Japan and Europe used deceptive photo ZIP files and legitimate web services to establish persistent access, while researchers uncovered thousands of potentially connected infrastructure artifacts and victim IP addresses.]]></description>
      <dc:date>2026-08-18T11:18:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Global Domain Activity Trends Seen in Q2 2026]]></title>
      <link>https://circleid.com/posts/global&#45;domain&#45;activity&#45;trends&#45;seen&#45;in&#45;q2&#45;2026</link>
      <guid isPermaLink="true">https://circleid.com/posts/global&#45;domain&#45;activity&#45;trends&#45;seen&#45;in&#45;q2&#45;2026</guid>

      <description><![CDATA[WhoisXML API's Q2 2026 analysis reveals rising domain registrations, shifting TLD rankings, growing DNS infrastructure concentration, and evolving malicious domain activity, based on billions of DNS records and millions of newly registered and confirmed malicious domains.]]></description>
      <dc:date>2026-08-13T07:43:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[APT37 Strikes Again, This Time with NarwhalRAT]]></title>
      <link>https://circleid.com/posts/apt37&#45;strikes&#45;again&#45;this&#45;time&#45;with&#45;narwhalrat</link>
      <guid isPermaLink="true">https://circleid.com/posts/apt37&#45;strikes&#45;again&#45;this&#45;time&#45;with&#45;narwhalrat</guid>

      <description><![CDATA[North Korea's APT37 has launched a new NarwhalRAT campaign using spearphishing emails and malicious LNK files to deploy data-stealing malware. Researchers also uncovered infrastructure links and fresh indicators that expand the group's known operational footprint.]]></description>
      <dc:date>2026-08-07T08:38:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[A DNS Investigation of LenAI&#8217;s ErrTraffic ClickFix Distribution Network]]></title>
      <link>https://circleid.com/posts/a&#45;dns&#45;investigation&#45;of&#45;lenais&#45;errtraffic&#45;clickfix&#45;distribution&#45;network</link>
      <guid isPermaLink="true">https://circleid.com/posts/a&#45;dns&#45;investigation&#45;of&#45;lenais&#45;errtraffic&#45;clickfix&#45;distribution&#45;network</guid>

      <description><![CDATA[An analysis of LenAI's ErrTraffic ClickFix infrastructure uncovered new DNS links, exposing malicious domains, IPs, typosquatting clusters, and email connections that broaden threat visibility and support stronger detection and incident response through expanded network intelligence.]]></description>
      <dc:date>2026-07-31T08:39:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Inside a TDS-Powered ClickFix Malware Ecosystem: A DNS Deep Dive]]></title>
      <link>https://circleid.com/posts/inside&#45;a&#45;tds&#45;powered&#45;clickfix&#45;malware&#45;ecosystem&#45;a&#45;dns&#45;deep&#45;dive</link>
      <guid isPermaLink="true">https://circleid.com/posts/inside&#45;a&#45;tds&#45;powered&#45;clickfix&#45;malware&#45;ecosystem&#45;a&#45;dns&#45;deep&#45;dive</guid>

      <description><![CDATA[DNS analysis of a malware distribution ecosystem uncovered thousands of linked artifacts, exposing typosquatting, malicious infrastructure and victim connections that broaden detection opportunities beyond Check Point Research's original indicators through expanded DNS intelligence correlation efforts.]]></description>
      <dc:date>2026-07-27T12:51:00-07:00</dc:date>
    </item>
  

  </channel>
  

</rss>