When government backlogs meet desperate demand, cybercriminals see a premium business opportunity.💰 In our latest investigation, DTI dives into the mechanics of scarcity scams, starting with a years-long campaign targeting Mexican citizens with highly convincing, fake passport portals. What we found: 🔹Scammers target necessary services with bottlenecked access, upfront payments, and heavy PII harvesting. 🔹Attackers are using session-replay tools to steal credentials, PII, and MFA tokens in real-time. 🔹From visa systems in Europe to tax portals in Brazil, these scams follow the same strategy. Read the full analysis👇 https://lnkd.in/e8vG39YG #Cybersecurity #ThreatIntelligence #FraudPrevention #Phishing #IdentityTheft
About us
DomainTools is the global leader for internet intelligence and the first place security practitioners go when they need to know. The world's most advanced security teams use our solutions to identify external risks, investigate threats, and proactively protect their organizations in a constantly evolving threat landscape. DomainTools constantly monitors the Internet and brings together the most comprehensive and trusted domain, website and DNS data to provide immediate context and machine-learning driven risk analytics delivered in near real-time. Visit domaintools.com to experience firsthand why DomainTools is the first stop for advanced security teams when they need to know.
- Website
-
https://www.DomainTools.com
External link for DomainTools
- Industry
- Computer and Network Security
- Company size
- 51-200 employees
- Headquarters
- Seattle, WA, Washington
- Type
- Privately Held
- Founded
- 2004
- Specialties
- Domain Ownership Records, Brand Protection, Whois Records, Threat Investigation, Cybercrime Investigation, Cyber Security Investigation, Whois History, Reverse Whois Lookup, Name Server Monitoring, Online Fraud Detection, and Threat Intelligence
Locations
-
Primary
Get directions
2101 Fourth Avenue
Suite 1720
Seattle, WA, Washington 98121, US
-
Get directions
2101 4th Ave
Seattle, WA 98121, US
Employees at DomainTools
Updates
-
The DomainTools team is ready for #BlackHatUSA 🎩, are you? It’s not too late to book time with us to learn how we’re empowering defenders to: ▪️Map adversary infrastructure to triage indicators, assess risk, and prevent future attacks ▪️Automate workflows and speed up investigations by embedding DomainTools data into existing security platforms ▪️Leverage predictive threat intelligence feeds to block high-risk domains before they’re weaponized. 🗓️Book a meeting now: https://lnkd.in/guTBJts7
-
🚩 Cyber Jihad: Inside the Pro-Iran Hacktivist Ecosystem Our team at DomainTools Investigations (DTI) just released an analysis of the pro-Iran hacktivist ecosystem— a decentralized wartime cyber front that converges around shared adversaries rather than a single command structure. The research covers: 🔹How the ecosystem mobilizes through Telegram coordination, social-media amplification, and commercial DDoS-for-hire platforms 🔹Why these groups' low-sophistication tradecraft remains effective 🔹How pro-Iran groups converge with jihadist and Russian-aligned actors to form the appearance of a transnational cyber front Read the full investigation from DTI⬇️ https://lnkd.in/efxbutdT #ThreatIntel #CyberSecurity #Hacktivism #InfoSec #DomainTools
-
Black Hat USA is around the corner, and DomainTools is warming up for Vegas🔥 We’re hosting meetings all week to talk to you about how we help teams identify external risks, optimize resources, and stop attacks before they happen. Book a time with a member of our team here: https://lnkd.in/guTBJts7
-
We are proud to be one of the select companies supporting the U.S. Intelligence Community (IC) by improving capabilities for early detection, response, and remediation of cybersecurity incidents through our involvement in the the Office of the Director of National Intelligence's Sentinel Horizon Program. DomainTools is uniquely positioned to support this program through its enabling of security teams to identify and block connections to newly-created domains, build context around adversary-controlled infrastructure, identify clusters of malicious activity-based infrastructure patterns, and monitor emerging attack campaigns. The Sentinel Horizon Program integrates data collection and sharing across the IC through commercial cyber intelligence to better engage with the IC's initiative of reporting attack trends, tracking cyber actors, and informing key policy questions. We are honored to be a part of this program and its mission, and are committed to support the Intelligence Community in providing adversary infrastructure intelligence, critical against preventing and responding to malicious activity. Learn more: https://lnkd.in/gfYRHtkG
-
#BlackHatUSA 🕵️schedules are filling up fast, and the DomainTools team is heading to Vegas to meet with you! 🫵 This year, we’ve been busy giving bad actors more bad days with the launch of our MCP Server and Real-Time IP Risk feeds. Join us at Black Hat 2026 to learn more about how DomainTools can help you detect and predict emerging threats before they strike: https://lnkd.in/guTBJts7
-
DomainTools Investigations is back on the CyberWire! This Saturday, our Head of Investigations and CISO, Daniel Schwalbe, sat down with Dave Bittner for the N2K | CyberWire's Research Saturday Podcast to discuss our research on the ZionSiphon malware sample. Daniel breaks down the malware's architecture, its operational shortcomings, and how the sample is best classified. It's always great to talk about our research with our friends in the field. In case you missed it, give the podcast a listen on your favorite platform to learn about our team's research ⬇️ https://lnkd.in/gZuPM-kq
-
🚰Boiling Point: Iran, Russia, and China-Aligned Actors Recent Focus on Targeting Water Systems Our team at DomainTools Investigations (DTI) just released an analysis of nation-state targeting of water and wastewater systems from 2024 to the present. This sector has become a preferred gray-zone target because these systems hold immense strategic value, especially during wartime. They also provide an attack vector that can attain high public visibility through relatively unsophisticated attacks. The research covers: 🔹How Iran, Russia, and China each treat water infrastructure differently, from public fear to sabotage to long-term pre-positioning 🔹Confirmed incidents from Texas to Norway to Poland, and the systemic weaknesses they share 🔹Why the real risk is weak defensive practices, not Stuxnet-level malware Read the full investigation from DTI: https://lnkd.in/gGWW9YyR #ThreatIntel #CyberSecurity #ICS #CriticalInfrastructure #InfoSec #DomainTools
-
8 months later and we're still talking about #BSidesNOVA! DT'er Malachi Walker presented on how Formula 1 racing became a hotbed for cyber activity. In this most recent blog post, Malachi recapped his presentation starting from suspicious domains and subdomains tied to the D1 movie, races, and the cars themselves. Check out the blog to learn more about how bad actors leverage new domains for spam, malware, and botnet activity and how our team used DomainTools Newly Observed Domains feeds, Real-time Risk Scores, and Passive DNS to map the infrastructure behind the Formula 1 campaigns. Read the blog: https://lnkd.in/gbacYfRY #Cybersecurity #DNS #InfoSec #F1
-
DomainTools is coming to #BlackHatUSA in Las Vegas, August 1-6!🎩 We map the internet to make it a safer place for everyone by detecting and predicting threats before they happen. Meet with a member of our team to discuss how DomainTools can help you: 👉 Optimize resources by reducing context-switching 👉 Reduce cyber risk with precise attack pattern mapping 👉 Identify quickly-evolving threats in real-time 🗓️Book a time here: https://lnkd.in/guTBJts7