The article analyzes five major 2026 cyber attacks, focusing on network and WHOIS artifacts tied to Ivanti EPMM, Cisco SD-WAN, Stryker, and multiple ShinyHunters-related breaches. It highlights dozens of domains, subdomains, and IPs, including typosquatting clusters, historical DNS resolutions, and newly discovered email-connected infrastructure. #IvantiEPMM #CiscoSDWAN #Stryker #ShinyHunters #oastfun #shinyhuntersrs #azurenetfilesnet
Keypoints
- CRN highlighted five of the biggest cyber attacks and breaches seen so far in 2026, and the article zooms in on those cases.
- The investigation produced 54 IoCs in total: five subdomains, 14 domains, and 35 IP addresses after filtering out legitimate and Tor-owned artifacts.
- Ivanti EPMM attacks accounted for all five subdomain IoCs, with the most suspicious being
ddns[.]1433[.]eu[.]organd several sibling subdomains flagged by public sandboxes. - Network traffic showed four unique client IPs communicating with three domain IoCs through 12 DNS queries, including
oast[.]fun,oast[.]site, andoast[.]me. - Typosquatting analysis linked
oast[.]site,oast[.]live,oast[.]fun, andoast[.]onlineto the Ivanti EPMM attacks, with the domains bulk-registered in 2022. - The researchers found 161 potential victim IPs communicating with 20 IP IoCs, 13 additional IPs, six email-connected domains, and 2,201 historical domain-to-IP resolutions.
- Further enrichment revealed 12 historical email addresses across five domains, two public emails, and six additional domains connected through reverse WHOIS analysis.
MITRE Techniques
- [T1583 ] Acquire Infrastructure – The actors appear to have registered and used multiple domains and subdomains to support the attacks, including bulk registration and related infrastructure (‘They were bulk-registered with one other domain—oast[.]online—on 11 January 2022.’)
- [T1584 ] Compromise Infrastructure – The article describes infrastructure that was tied to attacks and later observed in public sandboxes or threat intelligence, suggesting operational use of compromised or repurposed assets (‘public sandboxes flag sibling *[.]dns[.]1433[.]eu[.]org hosts as malicious’)
- [T1071.004 ] Application Layer Protocol: DNS – The investigation heavily relied on DNS activity, including DNS queries and domain-to-IP/IP-to-domain resolutions (‘communicated with three of the domain IoCs via 12 DNS queries’; ‘2,201 historical domain-to-IP resolutions’)
- [T1596 ] Search Open Websites/Domains – The researchers used WHOIS, DNS Chronicle, Reverse WHOIS, and Typosquatting API to enumerate related assets and historical records (‘We queried the domain IoCs on Typosquatting API’; ‘WHOIS History API’)
Indicators of Compromise
- [Domains ] Attack infrastructure and historical resolution targets – oast[.]fun, oast[.]site, and 2 more domains
- [Subdomains ] Ivanti EPMM-related subdomain infrastructure – ddns[.]1433[.]eu[.]org, e598292a5fbd[.]ngrok-free[.]app, and 3 more subdomains
- [IPs ] IP infrastructure and communication targets – 23[.]245[.]7[.]178, 82[.]25[.]35[.]255, and 33 more IPs
- [Email Addresses ] Historical WHOIS contacts linked to domains – 12 unique email addresses, including 2 public email addresses
- [File Names / Artifacts ] Additional connected artifacts available for download – sample of additional artifacts, full research dataset
Read more: https://circleid.com/posts/5-of-the-biggest-cyber-attacks-in-2026-so-far-dns-deep-dive