Valid Points · April 2026
Advanced Search, Search Sessions, and UNC1069 Research
New Advanced Search beta, updated search workflows, UNC1069 investigation, and recent threat hunting examples.
Welcome back to Validin’s monthly newsletter and thank you for inviting us into your inbox. As always, we appreciate any feedback! - The Validin Team
PLATFORM UPDATES
💬 Introducing an Improved Search Experience
Validin has introduced an updated Advanced Search experience, now available in beta to enterprise customers. The new workflow makes it easier for analysts to combine search criteria across host response, registration, and DNS data. The updated experience includes: autocomplete, syntax highlighting, inline help, and query validation and correction.
Validin has also introduced Search Sessions, a new way to organize and interact with your search history. Start a new session whenever you work on a new investigation, and your search history will automatically be associated with that session. Stop and start sessions as you jump between investigations.

IN CASE YOU MISSED IT
👋 See you at PIVOTcon in Málaga
The Validin Team will be in Málaga, Spain for PIVOTcon 2026, where Validin is a Gold sponsor. Founder Kenneth Kinion and founding engineer Sreekar Madabushi will be attending. Reach out to us if you'll be there, we'd love to connect!
Guest Research: Investigating UNC1069
Validin was joined by two guest researchers last month, Efstratios Lontzetidis and Christos Fotopoulos, who investigated UNC1069, a North Korean campaign that targets individuals by luring them to fake meetings. Read their full research here.
Aye-Coruna! Tracking an iOS Exploit Kit
Last month, Validin researched Coruna, a widely deployed iOS exploit kit, and discovered malicious domains using lures themed around the wars in Ukraine and Iran.
SPOT VALIDIN IN...
📰 May the Hunts Be With You | Substack
A security researcher received a highly personalized phishing email, likely from a North Korean-linked threat group posing as a recruiter. Using Validin and other platforms, they uncovered a sprawling network of 22 fraudulent domains across 9 IPs. Read the full Substack here.
🕸️ Pulling the Thread - Invite Only
A researcher discovered sites impersonating Zoom and Microsoft Teams, and used Validin's DNS history to discover a misconfigured SOA record that exposed a cluster of nearly 1,500 domains. Read the full writeup now.
BY THE NUMBERS
Top-viewed threat actor profiles and their position changes from last month. If you're logged into Validin, view the full profiles:
- Fake Software Downloads (+1)
- ClickFix (+2)
- Kimsuky (+2)
- Lumma Stealer (new)
- Lazarus Group (-4)
Get in touch
Contact us
Validin is the first tab I open every morning.