Domain Tools
Blog
DomainTools helps organizations and security analysts create a forensic map of criminal activity, assess threats and prevent future attacks. Source
Actions
Media Outlet details
| Scope | International |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesSpetsvuzavtomatika Leak Exposes an SVR Cyber Development Ecosystem
Published on: September 30, 2026 Executive summary The Spetsvuzavtomatika leak found on the darknet exposes a broad Russian cyber research and development program, with seven named projects defining its work. Two of the projects, Felix-23 and HAD, focus on target discovery, scanning, enrichment, and active testing. Another project, Putnik, supports internal-network access and credential theft.
More Breadth for Cortex with DomainTools IP Risk Feeds
Published on: Sep 21, 2026 Essential Context from DomainTools In Your Cortex Environment Cortex by Palo Alto gives teams a unified way to quickly view, identify, and respond to relevant indicators. The broader the data Cortex can reach and the richer that context, the sooner a threat can be assessed, investigated, and stopped. The DomainTools App for Cortex already gives users in-depth DNS indicators and domain risk.
Lemmings: A Russian Industrialized Persona Provisioning And Management for Active Measures Campaigns
Published on: September 16, 2026 Executive summary Data posted to a darknet forum by an account named okenit_hackers in October 2025 reveals that Russian actors have potentially upgraded their disinformation methods through the automated creation and management of fake personae.The files leaked contained a specific program set, written in Python, that is named “Lemmings” (Лемминги).
Investigate with Splunk 5.8
The Essential Context Layer in Your Splunk Environment Context, speed, and precision that helps investigators find what they’re after more quickly is exactly why we launched IrisQL (Iris Query Language), a powerful, text-based evolution of Iris Investigate’s Advanced Search into a structured, readable format. Because a single domain is often just the tip of an iceberg hosted alongside hundreds of other hidden threats, rapid searching must be paired with deep infrastructure context.
Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline
Executive Summary Recently leaked records show that Bauman Moscow State Technical University’s Department No. 4 operated as a long-term training pipeline for Russian military intelligence and cyber operations.
Chinese Malware Delivery Domains Part V
Introduction In Parts I-IV of this series, we reported on a large-scale malware delivery network targeting Chinese speaking users. This cluster is frequently associated with the Silver Fox threat group and relies on thousands of typo-squatted domains. We noted previously that this infrastructure appeared to operate under an affiliate or Malware as a Service (MaaS) model. In mid June 2026, Chinese law enforcement reportedly arrested several individuals connected to Silver Fox operations.
Hey Nineteen (Newsletters)
Published on: August 14, 2026 For once, I am *not* starting this newsletter by talking about the weather. The weather in Seattle that is, instead let’s talk about what passes for “ weather” in Las Vegas! Astute readers may notice that this edition of my newsletter is coming out a week later than usual.
SecuritySnack - Account Farmers and Sellers
In December 2024 we reported on account trafficking websites, and since then we’ve observed a continued expansion of these openly fraudulent account reseller markets. Almost every digital service, from cloud infrastructure to payment processors and AI platforms, requires an email address to sign up. Unfortunately, major email providers have notoriously lax fraud prevention.
Intelligence Report: The Zedxion Corporate Nexus for Illicit Iranian Financial Funds Transfer for IRGC Entities.
Published on: July 23, 2026 Foreword DomainTools Investigations began investigating the Zedxion Cryptocurrency Exchange in July 2025 thanks to an external partner coming to us with the question “Does anything look strange about this domain?” We continued our investigation into the Zedxion Exchange in partnership with TRM Labs who first published their own research on the Exchange in January 2026. Publishing in threat intelligence can be a tough balance to navigate.
DomainTools Investigations | Scarcity Scams
Whenever a government service has constrained supply (slot scarcity, queue, complexity, deadline pressure) against motivated demand, an arbitrage opportunity exists. Citizens are willing to pay extra to jump the queue, get a faster slot, or take a shortcut. Where official supply doesn't expand to meet that willingness to pay, someone fills the gap. Sometimes it's a legitimate expediter, but more often, it's a scam.