5 of the Biggest Cyber Attacks in 2026 So Far: DNS Deep Dive

5 of the Biggest Cyber Attacks in 2026 So Far: DNS Deep Dive
The article analyzes five major 2026 cyber attacks, focusing on network and WHOIS artifacts tied to Ivanti EPMM, Cisco SD-WAN, Stryker, and multiple ShinyHunters-related breaches. It highlights dozens of domains, subdomains, and IPs, including typosquatting clusters, historical DNS resolutions, and newly discovered email-connected infrastructure. #IvantiEPMM #CiscoSDWAN #Stryker #ShinyHunters #oastfun #shinyhuntersrs #azurenetfilesnet

Keypoints

  • CRN highlighted five of the biggest cyber attacks and breaches seen so far in 2026, and the article zooms in on those cases.
  • The investigation produced 54 IoCs in total: five subdomains, 14 domains, and 35 IP addresses after filtering out legitimate and Tor-owned artifacts.
  • Ivanti EPMM attacks accounted for all five subdomain IoCs, with the most suspicious being ddns[.]1433[.]eu[.]org and several sibling subdomains flagged by public sandboxes.
  • Network traffic showed four unique client IPs communicating with three domain IoCs through 12 DNS queries, including oast[.]fun, oast[.]site, and oast[.]me.
  • Typosquatting analysis linked oast[.]site, oast[.]live, oast[.]fun, and oast[.]online to the Ivanti EPMM attacks, with the domains bulk-registered in 2022.
  • The researchers found 161 potential victim IPs communicating with 20 IP IoCs, 13 additional IPs, six email-connected domains, and 2,201 historical domain-to-IP resolutions.
  • Further enrichment revealed 12 historical email addresses across five domains, two public emails, and six additional domains connected through reverse WHOIS analysis.

MITRE Techniques

  • [T1583 ] Acquire Infrastructure – The actors appear to have registered and used multiple domains and subdomains to support the attacks, including bulk registration and related infrastructure (‘They were bulk-registered with one other domain—oast[.]online—on 11 January 2022.’)
  • [T1584 ] Compromise Infrastructure – The article describes infrastructure that was tied to attacks and later observed in public sandboxes or threat intelligence, suggesting operational use of compromised or repurposed assets (‘public sandboxes flag sibling *[.]dns[.]1433[.]eu[.]org hosts as malicious’)
  • [T1071.004 ] Application Layer Protocol: DNS – The investigation heavily relied on DNS activity, including DNS queries and domain-to-IP/IP-to-domain resolutions (‘communicated with three of the domain IoCs via 12 DNS queries’; ‘2,201 historical domain-to-IP resolutions’)
  • [T1596 ] Search Open Websites/Domains – The researchers used WHOIS, DNS Chronicle, Reverse WHOIS, and Typosquatting API to enumerate related assets and historical records (‘We queried the domain IoCs on Typosquatting API’; ‘WHOIS History API’)

Indicators of Compromise

  • [Domains ] Attack infrastructure and historical resolution targets – oast[.]fun, oast[.]site, and 2 more domains
  • [Subdomains ] Ivanti EPMM-related subdomain infrastructure – ddns[.]1433[.]eu[.]org, e598292a5fbd[.]ngrok-free[.]app, and 3 more subdomains
  • [IPs ] IP infrastructure and communication targets – 23[.]245[.]7[.]178, 82[.]25[.]35[.]255, and 33 more IPs
  • [Email Addresses ] Historical WHOIS contacts linked to domains – 12 unique email addresses, including 2 public email addresses
  • [File Names / Artifacts ] Additional connected artifacts available for download – sample of additional artifacts, full research dataset


Read more: https://circleid.com/posts/5-of-the-biggest-cyber-attacks-in-2026-so-far-dns-deep-dive