Top Highlights
- The Ivanti EPMM attacks involved malicious subdomains and domains with links to typosquatting, enabling persistent command and control communication over years, highlighting sophisticated domain fraud to facilitate malware delivery.
- Attackers utilized IP and domain IoCs connected to compromised or malicious infrastructure, with evidence of long-term DNS resolutions, indicating sustained malicious activity and potential data exfiltration channels.
- The campaign exploited DNS-based exfiltration and command channels, with IPs communicating with hundreds of DNS queries and resolving to numerous malicious domains, posing significant risks of data theft and persistent malware presence.
Threat, Techniques, and Targets
The recent analysis highlights five major cyber attacks in 2026, focusing mainly on Ivanti EPMM, Cisco SD-WAN, Stryker Wiper, and ShinyHunters breaches. The attacks involved the use of malicious subdomains, domains, and IP addresses. For example, the Ivanti EPMM attacks used subdomains like e598292a5fbd.ngrok-free.app and domains such as oast.fun. Attackers often registered domains on platforms like bulk registration services, sometimes years before the attacks. Communication between victim IPs and malicious domains was frequent over a period of months. Attack techniques included DNS queries, typosquatting, and malware hosting on subdomains. Victim targets ranged from enterprise network infrastructure like SD-WAN to data breaches involving organizations like Stryker and breaches by ShinyHunters. The attackers relied heavily on DNS manipulation and domain hosting to facilitate their operations.
Impact, Security Implications, and Remediation Guidance
The attacks resulted in widespread threat activity, including malware deployment, data breaches, and infrastructure disruption. The presence of malicious subdomains and domains on public registries suggests that attackers are using common hosting platforms for their operations. Such activity poses serious security risks, including data theft, system compromise, and persistent access. Notably, many malicious domains are connected through typosquatting and DNS resolutions, making detection challenging. As a remediation step, organizations should monitor DNS traffic for suspicious queries linked to known malicious IoCs. It is essential to consult vendor-specific security advisories or trusted cybersecurity authorities for detailed mitigation strategies. Continuous threat intelligence gathering and domain/IP filtering are recommended to limit attacker access and prevent future breaches.
Continue Your Tech Journey
Learn how the Internet of Things (IoT) is transforming everyday life.
Discover archived knowledge and digital history on the Internet Archive.
ThreatIntel-V1
