Making COVID-19 Threat Intelligence Actionable

Last week, DomainTools, one of our strategic threat intelligence partners, made available a free, curated list of high-risk COVID-19-related domains. This is an admirable move by DomainTools and their desire “to support the community during the Coronavirus crisis.”
As a service to our customers and consistent with our vision of making threat intelligence actionable, we have quickly moved to integrate this threat intelligence into the Threater Threat Intelligence Protection Platform. As such, we are pleased to announce that this threat intelligence is now available as an automatic, domain blacklist. We are also pleased to announce that this threat intelligence is available to all Threater customers (note that threat intelligence from DomainTools is typically only available as part of our Enterprise Subscription).
In this blog we will take a look at:
As highlighted in our recent blog “The Very Real Impact of COVID-19 Cyber Threats”, threat actors are taking advantage of the COVID-19 pandemic to launch cyberattacks, including phishing campaigns. This is validated by data from DomainTools which shows a significant increase in domain name registrations per day related to COVID-19 terms. The data shows a massive uptick in domain registrations that started March 14, with more than 3,500 new domains being registered on a daily basis thereafter. While recent data shows a decline in the volume of daily registrations from peak levels, they remain at elevated levels. According to DomainTools, the list has proven to be quite volatile and immediately responsive to changing news regarding COVID-19.
In response to the increase in COVID-19-related threats, DomainTools launched a free, curated list of high-risk COVID-19-related domains. These domains have a “high probability” of being associated with COVID-19 related threats.
In order to identify and categorize threat intelligence specifically related to COVID-19, DomainTools took into account four distinct considerations:
Consistent with our mission of making threat intelligence actionable, we’ve made the DomainTools’ COVID-19 threat intelligence available to all Threater customers. Specifically, we’ve made available two automatic domain blacklists.
We recommend that customers treat the blacklist with Risk Scores of 99 and higher as a blacklist and treat the broader list with Risk Scores of 70 and higher as more of a “watch” list.
Threater customers can access these lists via Global Management Center by clicking Blacklist on the left menu and then Domains.
Summary
Threat actors are clearly looking to take advantage of the COVID-19 pandemic, which is supported by threat intelligence from leading providers like DomainTools. DomainTools move to make COVID-19 threat intelligence freely available is a great move to help organizations improve protection and increase visibility into threats during a time of need. At Threater, our mission is to make threat intelligence actionable and we’re proud that we are able to quickly mobilize to enable our customers to take advantage of COVID-19-related threat intelligence to increase network protection and increase visibility into COVID-19-related threats.
For more information about Threater visit Threater.com
For more information about DomainTools visit Domaintools.com
For more information about how Threater aggregates, integrates, and acts on DomainTools threat intelligence, see our joint solution brief located here.
To start protecting your network with actionable threat intelligence today, call 1.855.765.4925 or email sales@threater.com.