DNS Spotlight: 2026’s 5 Most Notorious Ransomware | #ransomware | #cybercrime


The Swiss Cyber Institute named the most notorious ransomware as of April 2026. We zoomed into five of them—LockBit, Cl0p, Akira, Medusa, and Qilin—in a bid to know more about their network IoCs and identify new artifacts.

Since the report did not go into detail about the malware’s IoCs, we obtained them from the sources enumerated below instead.

We collated a total of 85 network IoCs from the five sources above. After extracting domains from the subdomain IoCs and filtering out those that belonged to legitimate entities aided by the WhoisXML API MCP Server, we ended up with 84 network IoCs comprising three subdomains, eight domains, and 73 IP addresses for our analysis.

Our DNS infrastructure analysis for the five most notorious ransomware led to these findings:

  • 59 unique client IP addresses that communicated with three of the domain IoCs
  • 19,360 distinct IP addresses that could belong to victims that communicated with 55 of the IP IoCs
  • 5,100 email-connected domains, two were confirmed malicious
  • Two additional IP addresses, both were confirmed malicious
  • 60 IP-connected domains, four were confirmed malicious
  • 15,664 string-connected domains, 31 were confirmed malicious

A sample of the additional artifacts obtained from our analysis is available for download from our website.

3 Ransomware Subdomain IoCs Scrutinized

We kicked our investigation off by looking more closely at the three subdomain IoCs, all of which were related to Medusa. The WhoisXML API MCP Server had these revelations.

SUBDOMAIN IoCWXA MCP SERVER FINDING
erp[.]ranasons[.]comDid not have public WHOIS details; likely served as an ERP application host for a retail/e-commerce business; parent domain is approximately 27 years old
pruebas[.]pintacuario[.]mxLikely serves as a staging/test environment for an Odoo ERP deployment; the very short TTL suggests frequent repointing
wizarr[.]manate[.]chLikely serves as an open-source invite/user-management frontend for a private Plex/Jellyfin media server

As shown above, all three could have been compromised at the time they were utilized by Medusa threat actors since none of them were categorized as malicious at the time of writing.

8 Ransomware Domain IoCs Dissected

We then focused on the eight domain IoCs associated with LockBit (3 domains) and Cl0p (5 domains).

Sample network traffic data from the IASC revealed that 59 unique client IP addresses communicated with three of the domain IoCs connected to LockBit via 16,400 DNS queries between 24 May and 22 July 2026. These IP addresses fell under six ASNs.

At this point, we analyzed the five domain IoCs related to Cl0p only since those connected to LockBit were wildcards. We queried them on WHOIS API next and filled in missing details using Domain Info API. We learned that:

Next, we queried the five nonwildcard domain IoCs related to Cl0p on DNS Chronicle API and discovered that they posted 421 historical domain-to-IP resolutions over time. Take a look at more information for three examples below.

DOMAIN IoCNUMBER OF DOMAIN-TO-IP RESOLUTIONSDATES SEEN
zoom[.]voyage18712/28/19–06/24/26
jirostrogud[.]com11410/07/22–07/17/25
hiperfdhaus[.]com8110/06/22–07/17/25

The first resolution dates of the domain IoCs were all aged.

73 Ransomware IP IoCs Investigated

This time, we zoomed in on the 73 IP IoCs.

Sample network traffic data from the IASC for one showed that 19,360 distinct IP addresses potentially owned by victims communicated with 55 of the IP IoCs between 24 January and 22 July 2026. They fell under 531 unique ASNs.

We also queried the IP IoCs for the five ransomware on Bulk IP Geolocation Lookup and discovered that:

Next, we queried the IP IoCs on DNS Chronicle API and found out that 57 recorded 13,899 historical IP-to-domain resolutions over time. Here are more details for five examples.

RANSOMWAREIP IoCNUMBER OF IP-TO-DOMAIN RESOLUTIONSDATES SEEN
LockBit174[.]169[.]162[.]6228902/06/17–02/04/22
Cl0p185[.]181[.]230[.]1031,00012/21/18–09/29/20
Akira104[.]194[.]8[.]581,00012/01/20–01/15/21
Medusa31[.]220[.]45[.]1201,00002/05/17–09/11/20
Qilin82[.]29[.]54[.]14088302/05/17–08/10/24

Like the domain IoCs, which first resolved years ago, 52 IP IoCs with historical IP-to-domain resolutions did so, too.

Thousands of New Artifacts Amassed

We started our hunt for new artifacts by querying the domain IoCs on WHOIS History API and learned that six had 37 distinct email addresses in their historical records. Further scrutiny revealed that 10 were public email addresses. Of these, however, one did not appear in any other WHOIS record, while two could belong to domainers, leaving us with seven for the next step.

After querying the public email addresses on Reverse WHOIS API, we discovered 5,100 unique email-connected domains after those tagged as IoCs were filtered out.

Threat Intelligence API queries for the email-connected domains showed that two have already been weaponized for various campaigns. One example is answersite[.]com, which has been associated with malware distribution.

This post only contains a snapshot of the full research. Download the complete findings and a sample of the additional artifacts on our website or contact us to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

Disclaimer: We take a cautionary stance toward threat detection and aim to provide relevant information to help protect against potential dangers. Consequently, it is possible that some entities identified as “threats” or “malicious” may eventually be deemed harmless upon further investigation or changes in context. We strongly recommend conducting supplementary investigations to corroborate the information provided herein.

NORDVPN DISCOUNT – CircleID x NordVPN
Get NordVPN
 [74% +3 extra months, from $2.99/month]





Click Here For The Original Source.

——————————————————–

..........

.

.