DomainTools
banner
domaintools.bsky.social
DomainTools
@domaintools.bsky.social
A global leader for internet #intel that enables security practitioners to proactively defend their organization in a constantly evolving threat landscape.
🪷 The Petals of Espionage: DomainTools Investigations’ latest research analyzes the “who”, “how”, and “why” behind Lotus Blossom’s compromise of Notepad++.

Read the investigation: https://dti.domaintools.com/research/lotus-blossom-and-the-notepad-supply-chain-espionage-campaign
February 11, 2026 at 8:45 PM
It’s Day # 2 of #AFCEAWest, and DomainTools Federal is here at the San Diego Convention Center. Stop by Booth # 2309 to talk to our team about how we give you the offensive edge against state sponsored adversaries.

#CyberDefense #ThreatHunting #Federal #DomainTools
February 11, 2026 at 6:27 PM
DomainTools Federal is at #AFCEAWest at the San Diego Convention Center! Stop by Booth # 2309 to learn how we’re giving bad actors more bad days.
February 10, 2026 at 5:01 PM
January has come to a close, which means Daniel Schwalbe's newsletter is live! Get caught up on all our DTI team has been up to this last month 👇https://dti.domaintools.com/newsletters/thirteen-silver-newsletters
Thirteen Silver Newsletters - DomainTools Investigations | DTI
DomainTools Investigations kicks off 2026 with deep dives into the KnownSec leak exposing China's cyberespionage ecosystem, predatory online gambling apps, and a phishing campaign weaponizing fake job interviews.
dti.domaintools.com
February 5, 2026 at 8:51 PM
#AFCEAWest is next week!

The DomainTools Federal Team will be at the San Diego Convention Center, Booth #2309. Book a meeting with our team here or stop our booth to learn how we can help you give bad actors more bad days!
www.domaintools.com/demo
DomainTools | Demo
Request a demo from DomainTools to learn how our DNS intelligence platform can help you detect, identify, and monitor cyber threats.
www.domaintools.com
February 5, 2026 at 5:30 PM
Targeting the Talent: The Rise of "Phishing Interviews" 🎣
Job seekers are the latest target in scams uncovered by the DomainTools Investigations (DTI) team. Read our investigation here:https://dti.domaintools.com/securitysnacks/securitysnack-phishing-interviews
#CyberSecurity #Phishing #JobHunt
DomainTools Investigations | SecuritySnack: Phishing Interviews
Phishing campaign targets job seekers with fake career portals and interview invites, stealing ID.me credentials and deploying malware since August 2025.
dti.domaintools.com
January 30, 2026 at 8:04 PM
DomainTools will be at #AFCEAWest in San Diego from February 10-12.

Stop by our booth or book a meeting with our team to learn how we give defenders and threat hunters the offensive edge not just on land and in the air but across the sea as well.
https://www.domaintools.com/demo
DomainTools | Demo
Request a demo from DomainTools to learn how our DNS intelligence platform can help you detect, identify, and monitor cyber threats.
www.domaintools.com
January 27, 2026 at 6:01 PM
Take control of your data with DomainTools integration with Cribl Stream ⚡
Create a Real-Time DomainTools data feed integration with Cribl Stream.
Learn more: https://www.domaintools.com/blog/domaintools-cribl-continuous-enrichment-for-enhanced-intelligence
DomainTools | DomainTools & Cribl: Continuous Enrichment for Enhanced Intelligence
www.domaintools.com
January 26, 2026 at 11:51 PM
Play to Win or Pay to Lose? 💰
Our team at DomainTools Investigations identified three massive infrastructure clusters of online gambling and real-money games targeting users across various regions. Learn more ⬇️
https://dti.domaintools.com/securitysnacks/pay-to-lose-dubious-online-gambling-games
DomainTools Investigations | Pay to Lose: Dubious Online Gambling Games
Be wary of "real money" games this New Year. This report uncovers hundreds of fake Android gambling apps using spoofed reviews, fake win declarations, and "waistcoat" shells to trick users into sideloading unregulated, predatory gambling software.
dti.domaintools.com
January 22, 2026 at 8:02 PM
Faster pivots. Smarter hunting🛡️
We’ve leveled up the DomainTools for CrowdStrike app to give threat hunters more context without ever leaving their workflow. Learn how to turn a single indicator into a full-scale infrastructure map ⬇️
https://www.youtube.com/watch?v=NEf4hMR6qo8
January 21, 2026 at 9:32 PM
Introducing the new DomainTools 🔎

20+ years of DNS intelligence, now with a digital presence to match. We’ve evolved our look and feel for 2026 to ensure our platform is as precise and streamlined as our data.
New look. Same mission.
See what’s new: domaintools.com

DomainTools
DomainTools is the global leader in Internet intelligence. Learn how our products and data are fundamental to best-in-class security programs.
domaintools.com
January 12, 2026 at 5:01 PM
The December DTI newsletter is here! ☕️
We’re kicking off 2026 with a recap of last month’s research and our monthly reading list. Read the full briefing: https://dti.domaintools.com/rainy-day-newsletter-12-but-not-35/
#Infosec #ThreatIntel #AI #CyberSecurity #APT35
 Rainy Day Newsletter #12 (but not 35) - DomainTools Investigations | DTI
Explore how agentic AI accelerates threat hunting by 10x, a deep dive into APT35’s internal operations, and B2B2C supply chain attacks in the DTI December newsletter.
dti.domaintools.com
January 8, 2026 at 11:00 PM
DomainTools Investigations finds an attacker hijacking hotel accounts to send "verify booking" scams directly through official Booking[.]com messages.
Details: https://dti.domaintools.com/b2b2c-supply-chain-attack-hotels-booking-accounts-compromised-to-target-customers/

B2B2C Supply Chain Attack: Hotel’s Booking Accounts Compromised to Target Customers - DomainTools Investigations | DTI
New B2B2C supply chain attack targets Booking.com customers. Attackers are compromising hotel accounts to send "verify or cancel" phishing messages with dynamic booking data. Learn how to spot these fake domains and protect your payment info.
dti.domaintools.com
December 23, 2025 at 7:16 PM
🐈‍⬛ In our latest research, DomainTools Investigations covers APT35’s financial model and the administration behind both Charming Kitten and Moses Staff.
https://dti.domaintools.com/the-apt35-dump-episode-4-leaking-the-backstage-pass-to-an-iranian-intelligence-operation/

December 16, 2025 at 10:01 PM
Our Head of Investigations & CISO, Daniel Schwalbe, joined the CyberWire podcast for Research Saturday to discuss DomainTools Investigations’ GFW research.
Listen to the full interview⬇️
https://thecyberwire.com/podcasts/research-saturday/405/notes
#Cybersecurity #CyberWire #GreatFirewall #Podcast
December 16, 2025 at 6:28 PM
In part IV of our series analyzing Chinese malware delivery domains, DTI researchers deployed #AgenticAI to analyze 1,900 domains tied to the supercluster we have been tracking since June. https://dti.domaintools.com/chinese-malware-delivery-domains-part-iv/

Chinese Malware Delivery Domains Part IV - DomainTools Investigations | DTI
A massive crypto wallet-drain conspiracy links fake trading sites to a single criminal IP address. See our investigative deep dive into how these orchestrated scams are draining user funds.
dti.domaintools.com
December 8, 2025 at 9:30 PM
Don't miss this! DTI’s November newsletter covers research exposing two major nation-state operations:
🇨🇳 China's GFW and 🇮🇷 APT35 /Charming Kitten
https://www.linkedin.com/pulse/newsletter-11-could-take-forever-daniel-schwalbe-xy48c
#Cybersecurity #InfoSec #GreatFirewall #APT35 #China #Iran
Newsletter 11 Could Take Forever
The title of this month’s newsletter is a deep cut taken from the height of my favorite music genre, the admittedly awkwardly titled “Alternative Music.” What can I say, the 1990s in Seattle were wild, man - you had to be there.
www.linkedin.com
December 2, 2025 at 7:30 PM
😼 APT35/Charming Kitten Internal Documents Leaked

Our new DTI report analyzes the actor's methods.

Read the full analysis: https://dti.domaintools.com/threat-intelligence-report-apt35-internal-leak-of-hacking-campaigns-against-lebanon-kuwait-turkey-saudi-arabia-korea-and-domestic-iranian-targets/
November 21, 2025 at 8:00 PM
Enterprise Strategy group found that customers can expect up to a 17 times return on their initial investment in their first year when integrating DomainTools products with their existing solutions.

Ready to learn more? Book with a demo with us here: https://www.domaintools.com/demo/
Request a Demo | DomainTools - Start here. Know now.
Discover how DomainTools can enhance your organizations capabilities and stop threats before they happen. Request a DomainTools demo today.
www.domaintools.com
November 18, 2025 at 5:30 PM
🌎 Geopolitics and the Global Reach of the GFW
Part 3 dives into the Geopolitical and Societal Ramifications, revealing how China projects digital control abroad.
🧵 Read the final report: https://dti.domaintools.com/inside-the-great-firewall-part-3-geopolitical-and-societal-ramifications/
Inside the Great Firewall Part 3: Geopolitical and Societal Ramifications - DomainTools Investigations | DTI
Part 3 analyzes the GFW as geopolitical infrastructure: economic protectionism, the export of cyber sovereignty norms, and the emergence of an authoritarian coalition (Russia, Iran).
dti.domaintools.com
November 13, 2025 at 8:23 PM
Are your queries working as hard as they could be?

Using Iris Investigate + Farsight DNSDB in tandem gives you the fuller picture needed for better preventative decisions. Stop missing key pivots.

Read our latest blog post: https://bit.ly/3VzTr9V
How Domain Intelligence and Passive DNS create Full Profile
DomainTools walks users through how using domain intelligence and passive DNS tools together create a fuller picture of a domain profile
bit.ly
November 13, 2025 at 7:00 PM
Looking to get the most out of your year-end budget?

DomainTools integrations delivers best-in-class DNS intelligence directly into your security stack to enrich alerts, automate investigations, and enhance threat detection.

Request a demo today! https://www.domaintools.com/demo/
Request a Demo | DomainTools - Start here. Know now.
Discover how DomainTools can enhance your organizations capabilities and stop threats before they happen. Request a DomainTools demo today.
www.domaintools.com
November 12, 2025 at 7:00 PM
An independent study surveying DomainTools customers from Enterprise Strategy Group found DomainTools provided OEM partners 11 months faster time to value, reduced risk, and operational savings of 92%. Schedule a conversation with us here to learn more: https://www.domaintools.com/demo/

Request a Demo | DomainTools - Start here. Know now.
Discover how DomainTools can enhance your organizations capabilities and stop threats before they happen. Request a DomainTools demo today.
www.domaintools.com
November 11, 2025 at 7:00 PM
🧵DTI researchers leveraged the leaked data from China’s Great Firewall to map the core design of the censorship stack in Part 2 of Inside the Great Firewall.

Read the technical deep dive here: https://dti.domaintools.com/inside-the-great-firewall-part-2-technical-infrastructure/
Inside the Great Firewall Part 2: Technical Infrastructure - DomainTools Investigations | DTI
See the Great Firewall's technical blueprint. DomainTools Investigations details the TSG core, packet interception methods, and routines that detect tools like V2Ray/Psiphon.
dti.domaintools.com
November 6, 2025 at 8:29 PM
DomainTools customers report wins from cost savings & improved detection rates, identifying up to 83% more malicious domains up to 96% faster with DomainTools than with industry-standard blocklist sources.
Set up a conversation with us to learn more: https://www.domaintools.com/domaintools-demo/

DomainTools Demo - DomainTools | Start Here. Know Now.
www.domaintools.com
November 6, 2025 at 7:00 PM