The article analyzes network IoCs linked to five notorious ransomware families—LockBit, Cl0p, Akira, Medusa, and Qilin—using WHOIS, DNS, and traffic data to uncover additional infrastructure and related artifacts. It highlights 84 network IoCs, thousands of connected domains and IPs, and several potentially compromised or malicious assets, including answersite[.]com and Medusa-related subdomains. #LockBit #Cl0p #Akira #Medusa #Qilin #answersitecom
Keypoints
- The Swiss Cyber Institute identified five of the most notorious ransomware groups as of April 2026: LockBit, Cl0p, Akira, Medusa, and Qilin.
- The analysis started with 85 network IoCs and was refined to 84 usable IoCs after filtering legitimate infrastructure.
- The final dataset included three subdomains, eight domains, and 73 IP addresses.
- Medusa was associated with three subdomain IoCs that appeared to be legitimate services potentially compromised at the time of use.
- LockBit and Cl0p were linked to domain IoCs, including 59 client IPs communicating with LockBit-related domains and 421 historical domain-to-IP resolutions for Cl0p domains.
- The IP IoC analysis found 19,360 distinct victim-associated IPs contacting 55 IP IoCs and 13,899 historical IP-to-domain resolutions across 57 IPs.
- WHOIS and reverse WHOIS enrichment uncovered 5,100 unique email-connected domains, with two already weaponized and one example being answersite[.]com.
MITRE Techniques
- [T1583.001 ] Acquire Infrastructure: Domains – The actors relied on domains for command or supporting infrastructure, including aged and wildcard domains analyzed in the report (‘the five domain IoCs related to Cl0p’ and ’59 unique client IP addresses communicated with three of the domain IoCs’).
- [T1584.001 ] Compromise Infrastructure: Domains – Some infrastructure may have been compromised and repurposed by the threat actors, especially the Medusa-related subdomains (‘all three could have been compromised at the time they were utilized by Medusa threat actors’).
- [T1021 ] Remote Services – Network traffic showed large-scale communication between many client/victim IPs and the ransomware infrastructure, indicating remote network interaction (‘communicated with three of the domain IoCs’ and ‘communicated with 55 of the IP IoCs’).
- [T1589.002 ] Gather Victim Identity Information: Email Address – The research pivoted from WHOIS records to public email addresses to discover connected infrastructure (‘we discovered 5,100 unique email-connected domains’).
- [T1590.005 ] Gather Victim Network Information: IP Addresses – The analysis centered on victim-associated IP communications and historical IP-to-domain relationships to map infrastructure (‘19,360 distinct IP addresses that could belong to victims’ and ‘historical IP-to-domain resolutions’).
Indicators of Compromise
- [Domains ] Cl0p and LockBit domain infrastructure – zoom[.]voyage, jirostrogud[.]com, and 2 more domains
- [Subdomains ] Medusa-related subdomains assessed for potential compromise – erp[.]ranasons[.]com, pruebas[.]pintacuario[.]mx, and wizarr[.]manate[.]ch
- [IP addresses ] ransomware-related IP infrastructure and historical resolutions – 174[.]169[.]162[.]62, 185[.]181[.]230[.]103, and 71 more IPs
- [Email addresses ] historical WHOIS email artifacts used to discover related domains – 37 distinct email addresses, 10 public email addresses
- [Domains ] email-connected domains derived from reverse WHOIS – 5,100 unique domains, including answersite[.]com and 5,099 more domains
- [ASNs ] network attribution context for observed communications – six ASNs for LockBit-related domain traffic, 531 unique ASNs for victim-associated IP traffic
Read more: https://circleid.com/posts/dns-spotlight-2026s-5-most-notorious-ransomware