Valid Points · August 2026
Russian Cyber Espionage Clusters, Regex in Advanced Search and the Validin team at LABScon
Expanding the infrastructure behind Russia-aligned clusters UNC6293, UNC7005, and UNC5976, regex domain filtering and browser-rendered live scans in Advanced Search, and where to find us at LABScon.
Welcome back to Validin’s monthly newsletter and thank you for inviting us into your inbox. In August, we investigated several Russia-aligned threat clusters expanding their known infrastructure, we introduced regex support for certain fields of our new advanced search experience and we've introduced a new type of live scans, allow for full renders & screenshots of a website's DOM. In two weeks, we'll be at LABScon, so make sure to come say hi to the team if you're also attending!
The Validin Team
FEATURED RESEARCH
🏨 Inhospitable: Tracking Russian Cyber Espionage Infrastructure
Building on Google Threat Intelligence Group’s reporting on Russian cyber espionage clusters UNC6293, UNC7005, and UNC5976, we expanded the known infrastructure using historical DNS and registration data, host-response similarities, header hashes, favicons, and other content pivots. We surfaced additional suspected domains and origin IPs, while using historical context to validate relationships, rule out incidental overlaps, and identify infrastructure worth monitoring as these campaigns evolve.
BY THE NUMBERS
Top-viewed threat actor profiles and how their ranking changed from last month. If you're logged into Validin, you can view the full profiles:
- MuddyWater (new)
- ClickFix (-1)
- Kimsuky
- Lazarus Group
- Sidewinder (new)
PLATFORM UPDATES
💬 Advanced Search and Live Scan Improvements
This August, we expanded Advanced Search with more granular registration criteria and regex-based domain filtering, enabling users to search across more registration fields and include or exclude domains based on lexicographic patterns. We also introduced a new behavioral live scan that captures browser-rendered screenshots, full request activity, and dynamically loaded resources.

IN CASE YOU MISSED IT
👋 See you at LABScon
Validin is sponsoring the final LABScon this September. The team will be in Arizona for the event. See you all there!
SPOT VALIDIN IN...
❄️ Investigating Midnight Blizzard's AI Powered Infrastructure
TLP-Unclear investigated Microsoft’s CaptiveCrunch reporting to expand infrastructure associated with Midnight Blizzard, pivoting across HTTP service fingerprints, certificates, historical DNS, registration data, and lure behavior. The analysis uncovered several previously unreported domains and IP addresses tied to phishing, DNS resolver, and C2 infrastructure, including additional hosts running the campaign’s CloudSync Console. Read the full analysis here.
Get in touch
Contact us
Validin is the first tab I open every morning.
