All Posts
Cyber Threat Intelligence
Research
1
min read

Why Domain Analysis and Credential Leakage Is Important Intelligence

Published on
October 28, 2016
Table of Contents
<p>The power of threat intelligence is that it can help organizations understand how they are targeted by attackers. This knowledge can then be used to apply defensive measures against those threat vectors. In this way, organizations can address certain attacks before they happen.</p><p>For instance, monitoring newly observed domains for names that are similar to a company's existing domain name could be an indicator that an adversary is preparing for an attack. Leveraging a domain name that looks very similar to the company's real domain name to craft a malicious link could trick users into clicking and installing malware.</p><p>By generating permutations of a domain name in advance of an attack, companies can gain valuable threat intelligence and insight into the potential attack surface. When used in combination with a long URL, it can be difficult to distinguish the legitimacy of a typo-domain at first glance. If one of these domains is then observed in network traffic, it can be highlighted and action taken before serious damage is done.</p><p><img src="https://cdn.filestackcontent.com/6AAVSy8UQpevcKBIuXtx"/><br/> <em>Figure 1. – Example of possible “typo” domain combinations generated</em></p><p>Another angle to consider is leaked credentials. Employees may use their work email address to register for websites on the Internet for personal or company use. Regardless of the reason, if that website is compromised and the credentials leaked to the Internet, attackers may have everything they need to login as that user on other websites - including company assets if they used the same password for corporate resources as they did on the compromised website. Monitoring credential dumps for corporate email addresses is a way to address this problem potentially before attackers have attempted to utilize the credentials. Reaching out to users to have them change their passwords or forcing password resets for any compromised accounts are ways this can be addressed once known.</p><p>Anomali Labs has done research on newly registered domains and credential dumps for the companies in the Stockholm OMX 30 stock index. The results showed that 90% of the OMX 30 companies had at least one potentially malicious domain registered and 70% of them had at least one email and password shared in plain text. These are items that could certainly be used to stage attacks against these organizations.</p><p>Turning threat intelligence into actionable defenses should be the goal of any threat intelligence program and is the heart of what Anomali brings to the table. <strong><a href="https://wwwlegacy.anomali.com/files/anomali-labs-reports/OMX-30.pdf" target="_blank">Click here to see the Anomali Labs report on the OMX 30</a></strong>.</p>

FEATURED RESOURCES

January 13, 2026
Anomali Cyber Watch

Anomali Cyber Watch: Cisco ISE Flaw, Ni8mare, N8scape, Zero-Click Prompt Injection and more

Anomali Cyber Watch: Cisco ISE Flaw Enables Arbitrary File Read via Administrative Access. Ni8mare and N8scape Vulnerabilities Expose n8n Automation Platforms to Full Compromise. Zero-Click Prompt Injection Abuse Enables Silent Data Exfiltration via AI Agents. Phishing Attacks Exploit Misconfigured Email Routing to Spoof Internal Domains. Ransomware Activity in the U.S. Continued to Rise in 2025. Android Ghost Tap Malware Drives Remote NFC Payment Fraud Campaigns. Black Cat SEO Poisoning Malware Campaign Exploits Software Search Results. MuddyWater Upgrades Espionage Arsenal with RustyWater RAT in Middle East Spear-Phishing. China-Linked ESXi VM Escape Exploit Observed in the Wild. Instagram Denies Data Breach Despite Claims of 17.5 Million Account Data Leak
Read More
January 6, 2026
Anomali Cyber Watch

Anomali Cyber Watch: OWASP Agentic AI, MongoBleed, WebRAT Malware, and more

Real-World Attacks Behind OWASP Agentic AI Top 10. MongoDB Memory Leak Vulnerability “MongoBleed” Actively Exploited. WebRAT Malware Spread via Fake GitHub Proof of Concept Exploits. Trusted Cloud Automation Weaponized for Credential Phishing. MacSync macOS Stealer Evolves to Abuse Code Signing and Swift Execution. Claimed Resecurity Breach Turns Out to Be Honeypot Trap. Cybersecurity Professionals Sentenced for Enabling Ransomware Attacks. Google Tests Nano Banana 2 Flash as Its Fastest Image AI Model. RondoDox Botnet Exploits React2Shell to Hijack 90,000+ Systems. Critical n8n Expression Injection Leads to Arbitrary Code Execution
Read More
December 23, 2025
Anomali Cyber Watch

Anomali Cyber Watch: SantaStealer Threat, Christmas Scams of 2025, React2Shell Exploit, Phishing via ISO, and more

SantaStealer Infostealer Threat Gains Traction in Underground Forums. From Fake Deals to Phishing: The Most Effective Christmas Scams of 2025. React2Shell Exploitation Expands With New Payloads and Broader Targeting. Russian Phishing Campaign Delivers Phantom Stealer via ISO Attachments. And More...
Read More
Explore All