#domaintools
First they came for PassiveTotal. Then for Censys V2. 😭 I'M JUST A GIRL! I JUST WANT TO DO INFRASTRUCTURE RESEARCH! (You can pry DomainTools from my cold, dead hands.)
September 24, 2026 at 9:42 PM
Igor is a notorious spreader of misinformation and disinformation, and the article he screenshotted has already been deleted, but the fact that Elon is responding this way to a negative story about the White House Personnel Director is noteworthy.
June 20, 2025 at 5:00 PM
Both DomainTools and Resecurity have recently covered last year's KnownSec's data leak

dti.domaintools.com/the-knownsec...

www.resecurity.com/es/blog/arti...

tl;dr: This is not your typical govt cyber contractor
THE KNOWNSEC LEAK: Yet Another Leak of China’s Contractor-Driven Cyber-Espionage Ecosystem - DomainTools Investigations | DTI
Leaked Knownsec documents reveal China’s cyberespionage ecosystem. Analyze TargetDB, GhostX, and 404 Lab’s role in global reconnaissance and critical infrastructure targeting.
dti.domaintools.com
January 10, 2026 at 2:46 PM
More proof he's a fucking Ruzzian:
June 20, 2025 at 3:13 PM
To the trolls on here claiming otherwise, it is TOTALLY believable that the guy is a KGB-GRU plant. We might have just discovered Krasnov's controller & back-channel to Pootin. More believable than him being from Malta.
June 20, 2025 at 3:10 PM
DomainTools Investigations worked with OSINT analysts & journalists to help uncover the connections between websites involved in the harassment of Ukrainian personnel and their families, and the people and infrastructure involved.

Technical writeup below!

www.domaintools.com/resources/bl...
RDAP and BGP in Investigative Journalism - DomainTools | Start Here. Know Now.
One of the things we’re most proud of at DomainTools is our Grants program. We offer free access and training to investigative journalists, as well as security researchers involved in community-benefi...
www.domaintools.com
July 8, 2025 at 7:30 AM
Humbled to have been presented @domaintools.bsky.social "Bad Actors Badger" Award this evening!

Truth is, I am only the last mile, and can't do it w/o everyone in the chain - every bit of dev, every doc, every sale, every customer, we're all badgers.

We are the adversaries - let's never let up.
September 24, 2026 at 2:32 AM
The DomainTools security team has published a comprehensive report on the current 2026 infrastructure of Russian disinformation group Doppelgänger (aka RRN) and their latest operational priorities

They also have a new RSS feed, so update that too

dti.domaintools.com/research/dop...
March 5, 2026 at 6:35 PM
New from @DomainTools: Inside the Great Firewall Part 1: The Dump
https://dti.domaintools.com/inside-the-great-firewall-part-1-the-dump/
October 30, 2025 at 7:30 PM
The DomainTools security team looks at recent APT35 leaks showing how the group operates with extreme government oversight and bureaucracy, rather than a group of loose canon hackers

dti.domaintools.com/the-apt35-du...
The APT35 Dump Episode 4: Leaking The Backstage Pass To An Iranian Intelligence Operation - DomainTools Investigations | DTI
APT35/Charming Kitten's leaked documents expose the financial machinery behind state-sponsored hacking. Learn how bureaucracy, crypto micro-payments, and administrative ledgers sustain Iranian cyber o...
dti.domaintools.com
December 18, 2025 at 1:07 PM
The DomainTools Investigations crew will be out at Sleuthcon this week, either kicking around the DomainTools table or roaming around the con looking to talk shop. Sleuthcon is one of our favorites.

(Please don't seek us out for sales pitches, we have no available budget and it makes us sad.)
June 1, 2026 at 10:34 PM
The DomainTools security team looks at a cluster of over 100 websites peddling malicious Chrome extensions

dti.domaintools.com/dual-functio...
Hidden Threats of Dual-Function Malware Found in Chrome Extensions - DomainTools Investigations | DTI
Malicious Chrome extensions mimic tools to steal data, inject code, and hijack sessions. Learn how to spot and avoid these evolving threats.
dti.domaintools.com
May 20, 2025 at 6:11 PM
🎯 Principal Product Manager
🏢 DomainTools

Instant alerts for jobs like this → gigsniper.net

#RemoteJobs #Hiring #RemoteWork #Productmanager #Exec
Principal Product Manager
DomainTools · via RemoteOK · Apply now — found by GigSniper
remoteok.com
September 17, 2026 at 3:01 AM
Lastly, the gang at domaintools found a bunch of related infrastructure w/ a metric ton of typosquatted domains

but whats odd about this? we haven't seen those mailservers used at all to hit the same targets (or anyone at all)

keep an eye on this crew

dti.domaintools.com/phishing-cam...
Phishing Campaign Targets Defense and Aerospace Firms Linked to Ukraine Conflict - DomainTools Investigations | DTI
DomainTools Investigations identified a large-scale phishing infrastructure heavily focused on defense and aerospace entities with links to the conflict in Ukraine.
dti.domaintools.com
April 17, 2025 at 12:33 PM
DomainTools has a good profile on Salt Typhoon, the Chinese APT that hacked over a dozen US telcos at the end of last year. It's actually a very old and sprawling APT, involving everything from MSS supervisors to front companies and contractors.

dti.domaintools.com/inside-salt-...
September 25, 2025 at 10:25 AM
On the pod, @craigsilverman.bsky.social, Craig’s cat Rosie, and I walked thru these investigations with Kolina.

Kolina showed us how she uses tools like DNSlytics, DomainTools, and OpenCorporates to connect nefarious websites together and reveal their ultimate owner(s).

Check it out!
Unmasking AI Nudifier Networks: OSINT Techniques from Bellingcat's Kolina Koltai
YouTube video by Indicator
youtu.be
April 2, 2026 at 11:41 AM
This new analysis from DomainTools on a recent trove of data regarding the Great Firewall is your must-read this week.
Inside the Great Firewall Part 1: The Dump - DomainTools Investigations | DTI
Analysis of the 500GB+ Great Firewall data breach revealing China’s state censorship network, VPN evasion tactics, and the operators behind it.
dti.domaintools.com
October 30, 2025 at 8:42 PM
Introducing the new DomainTools 🔎

20+ years of DNS intelligence, now with a digital presence to match. We’ve evolved our look and feel for 2026 to ensure our platform is as precise and streamlined as our data.
New look. Same mission.
See what’s new: domaintools.com

DomainTools
DomainTools is the global leader in Internet intelligence. Learn how our products and data are fundamental to best-in-class security programs.
domaintools.com
January 12, 2026 at 5:01 PM
DomainTools looks at Iran's Intelligence Group 13, "one of the most operationally aggressive and ideologically fortified units within the Islamic Revolutionary Guard Corps (IRGC) cyber arsenal"

dti.domaintools.com/irans-intell...
Iran's Intelligence Group 13 - DomainTools Investigations | DTI
Intelligence Group 13, embedded within the Shahid Kaveh Cyber Group, represents one of the most operationally aggressive and ideologically fortified units within the Islamic Revolutionary Guard Corps ...
dti.domaintools.com
July 3, 2025 at 7:34 PM
Bellingcat is always worth boosting anyway, but Bellingcat citing DomainTools data on a Monday morning just made my week! World-class investigators doing the Good Work.
Bellingcat’s @koltai.bsky.social uncovers the Hungarian national behind two deepfake porn websites. The key figure rakes in profits and vacations in luxury hotels in Dubai and Bali, whilst website visitors create sexually explicit images and videos.
www.bellingcat.com/news/2025/12...
How We Found the Man Behind Two Deepfake Porn Sites
Business documents, website code and leaked data all led us back to one person profiting off non-consensual sexual imagery of women.
www.bellingcat.com
December 15, 2025 at 3:41 PM
DomainTools has attributed an APT campaign targeting the Pakistan Navy as described by a recent BlackBerry report to SloppyLemming, an Indian cyber-espionage group

cti-grapevine.com/blackberry-s...

blogs.blackberry.com/en/2024/11/s...

www.cloudflare.com/threat-intel...
BlackBerry, SloppyLemming, and Guess Who...Cloudflare - CTI Grapevine
BlackBerry’s threat research team reported on a cyber espionage campaign targeting the Pakistan Navy. Subsequent analysis by DomainTools revealed significant overlaps in TTPs and targeting scope with ...
cti-grapevine.com
December 12, 2024 at 10:17 AM
I'm very grateful to DomainTools for providing access to their instruments to analyse web domains. Thanks to this tool I have just found two hijacked journals which will be added to the Retraction Watch Hijacked Journal Checker during the next update.
October 30, 2025 at 9:44 PM