logo

Finding Additional Indicators With a SeaTurtle Deep Dive in Passive DNS Within DomainTools Iris

ID: f235b78e-63f4-556d-8981-6d71960ef140

STIX ID: report--f235b78e-63f4-556d-8981-6d71960ef140

Feed Name: DomainTools

Threat Score
90/100

Date Published: 2026-02-22

Date Updated: 2026-04-27

Author: domaintools.com

...
...

This report examines the SeaTurtle DNS hijacking campaign, detailing how attackers compromised tertiary DNS vendors to steal signing certificates and flip NS/A records to actor-controlled nameservers and man-in-the-middle servers. Using passive DNS and DomainTools Iris data the authors expand Cisco Talos IoCs, listing additional malicious nameservers, domains, and IPs used across many governments and infrastructure providers, and recommend DNS monitoring, DNSSEC, and MFA to mitigate such attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.