WhoisXML API is a cyber intel provider that has been gathering, analyzing, and correlating domain, IP, and DNS data for a more secure and transparent Internet.

Covina CA
What if #UNC6293, #UNC7005, and #UNC5976 were using fake domains to track and target high-value individuals? Thanks to @Google Threat Intelligence Group (#GTIG) for the initial threat report and 33 network #IoCs linked to these three Russian threat groups, expanding which we uncovered 2,689 new artifacts → 317 potential victim IPs, 2,494 email-connected domains, 15 additional IPs, 29 IP-connected domains, and 151 string-connected domains. Download the full report → main.whoisxmlapi.com/threat-… #ThreatIntelligence #CyberSecurity #DNSIntel #Infosec #CTI #ThreatResearch
1
1
357
WXA Tokyo Forum is back for 2026! On November 19, we’re bringing #cybersecurity leaders from across Japan and APAC together in Tokyo for an invitation-only executive luncheon on the next generation of threat intelligence. New research. Real-world cases. Focused discussion. Request an invitation now: join.whoisxmlapi.com/wxa-for… #WXATokyoForum #WXATokyo2026 #ThreatIntelligence
44
A registrant’s domain footprint can change quickly. Registrant Monitor helps track domains tied to #WHOIS registrant details and sends daily alerts for newly registered, updated, or expired domains. Explore: drs.whoisxmlapi.com/registra… #ThreatIntelligence #DomainIntelligence #OSINT #CyberSecurity
51
Scammers were building #iPhone18 phishing sites before #Apple even unveiled the phones. @Forbes @happygeek spoke with our Alexandre François (@detectiveDNS) about #phishing sites built weeks in advance, weekend security gaps, and a major red flag: the standard iPhone 18 isn’t even on sale yet. Read the full piece here: forbes.com/sites/daveywinder… #CyberSecurity #ThreatIntelligence #BrandImpersonation #iPhone18Pro #iPhone18ProMax
1
101
🚨 August 2026 Domain Activity Highlights: main.whoisxmlapi.com/blog/au… We analyzed 11.6M+ new domains: • 3.0M+ flagged with malicious intent • 1.097M+ confirmed malicious See how #TLD trends and attacker behavior are evolving! #threatintelligence #cybersecurity #domainintel #infosec
60
WhoisXML API is joining #RightsConContinues 2026! Alexandre François, Director of Product Marketing / Research & Media Collaboration, will facilitate a table during the Private Sector Meetup. We’re looking forward to bringing perspectives from our work in Internet infrastructure intelligence and threat research into the wider digital rights conversation. @rightscon @accessnow Sept. 22 | 18:45–19:45 CAT #RightsCon #RightsCon2026 #DigitalRights #ThreatIntelligence
56
What if #malvertising delivered #malware that security tools had never seen before? #SourTrade mimicked TradingView, Solana, and Luno to target retail traders and crypto investors. We expanded 96 know #IoCs and uncovered 1,262 new possibly connected artifacts→ 4 #typosquatting groups, 14 likely malicious domains, 348 email-connected domains, 186 IPs, and 728 string-connected domains. Download the full SourTrade report → main.whoisxmlapi.com/threat-… #ThreatIntel #Cybersecurity
65
WhoisXML API intelligence is now integrated into @MalforsHQ, a modern investigation platform for threat intelligence, #OSINT, and security research teams. Analysts can enrich investigations with WHOIS, DNS, IP, subdomain, and geolocation intelligence—directly within their investigation graph. Learn more: main.whoisxmlapi.com/success… #ThreatIntelligence #CyberSecurity
1
4
113
We’re heading to Bali for the #ICANN87 Annual General Meeting. Ching Chiao will represent WhoisXML API, bringing 20+ years across #DNS, Internet infrastructure, #cybersecurity, and governance. Connect with Ching at @ICANN87: join.whoisxmlapi.com/upcomin… #ICANN #InternetGovernance #DomainNames #ThreatIntelligence
73
WhoisXML API just added two new ways to control your account: API IP allowlists and per-member usage monitoring. Restrict API access to a list of trusted IP addresses so a leaked key alone can't get anyone in, and see exactly how much each team member's Child API key is using, all at no extra cost. Learn more in: whoisxmlapi.com/blog/new-acc… #APIsecurity #DataProtection
54
One week to CYBR.SEC.CON. 2026. Ed Gibbs and Michael Kaparos are bringing the data—you bring the questions. Meet them and talk NetFlow, AI, and threat hunting. Request a time to connect at @CybrSecEvents: join.whoisxmlapi.com/upcomin… #CYBRSECCON #CYBRSECCommunity #InfoSec #NetFlow #ThreatHunting
57
#TA4922 is going global—and its #phishing operations are expanding well beyond its traditional targets. Our latest DNS investigation traces the infrastructure behind the threat actor’s campaigns, uncovering connected domains, malicious IPs, and previously unseen artifacts that reveal a broader operational footprint. 🔎 Explore the investigation: circleid.com/posts/dns-inves… #ThreatIntelligence #CyberSecurity #DNS #ThreatResearch
1
79
🔎 Uncover domains, subdomains, lookalikes, and hidden infrastructure tied to any keyword or string. Domains & Subdomains Discovery searches across 50B+ domains and subdomains, with filters to help narrow in on the assets that matter. Get free instant access: drs.whoisxmlapi.com/domains-… #ThreatIntel #CyberSecurity #DomainDiscovery #OSINT
129
105 IPs attacked a honeypot. Then showed up in production traffic. That’s one of the findings behind Needles in the Flow: Using AI to Hunt Threat Signals in #NetFlow! At #CYBRSECCON, Ed & Michael will show how we turned 679M+ flows into focused investigations. If you’ll be at @CybrSecEvents leave a request to connect: join.whoisxmlapi.com/upcomin… #CYBRSECCommunity #Cybersecurity #InfoSec #ThreatIntelligence #AI
51
#81 in Security — a #milestone we’re especially proud of this year. WhoisXML API has once again been named to the 2026 #Inc5000 list of America’s fastest-growing private companies. A big thank you to our team, customers, and partners who continue to make this possible. @Inc #CyberSecurity #ThreatIntelligence #DomainIntel
1
55
A suspicious indicator is only useful if you can quickly understand what you're looking at. With Threat Intelligence Lookup Investigate domains, IPs, URLs, CIDRs, and hashes against multi-source intelligence to uncover threat type, IoC type, and first- and last-seen dates. Explore: threat-intelligence.whoisxml… #ThreatIntelligence #ThreatHunting #CyberSecurity
1
85
We’re heading to #PWNEDCR0x9! Ed Gibbs will be joining Costa Rica’s #cybersecurity community to connect on threat research, DNS intelligence, and the infrastructure behind real-world attacks. Request to connect at @pwnedcr : join.whoisxmlapi.com/upcomin… #PWNEDCR #ThreatIntelligence #InfoSec
1
2
82
Fake AI tools. Compromised WordPress sites. Blockchain-backed C2. Starting with 71 IoCs, our investigation into LenAI’s #ErrTraffic ClickFix network uncovered 1,200+ potentially connected artifacts—and domains flagged by First Watch months before public reporting. 🔎 circleid.com/posts/a-dns-inv… #ThreatIntelligence #ClickFix #Malware
1
75
What if a "photo" ZIP file was actually a hotel intrusion toolkit? A multistage campaign targeted hotels in Japan and Europe using photo-themed ZIP archives, fake image shortcuts, obfuscated #PowerShell, and a Node.js implant. Thanks to @msftsecurity for the 77 network IoCs, expanding which we uncovered 3,202 new artifacts → 2 client IPs, 5 #typosquatting domains, 1 likely malicious domain, 2,357 potential victim IPs, 2,840 email-connected domains, 123 malicious IPs, 144 IP-connected domains, and 95 string-connected domains. Download the full Photo ZIP report → main.whoisxmlapi.com/threat-… #ThreatIntelligence #CyberSecurity#HospitalitySecurity#DNSIntel #Infosec #CTI #ThreatResearch
66
What other domains are connected to an IP you’re investigating? 🔎 Reverse IP Lookup finds domains resolving to the same IP, with first- and last-seen dates to help uncover infrastructure connections and expand investigations. Explore: reverse-ip.whoisxmlapi.com/l… #ReverseIP #ThreatIntelligence #DNSIntel
54