IOC Radar
DomainHighVerifiedSignal 75/100

planet.news

Location
United StatesUnited States
First Seen
Apr 17, 2026
Last Seen
May 10, 2026
Apr 17
First Seen
71d ago
May 10
Last Seen
47d ago
5
Reports
source reports
75%
Confidence
high
Found in 5 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
75%
Signal Score
75 / 100
IDS Rule
No
Threat Context
Tags

Feed Intelligence Summary

5 reports75% confidence
5
Source reports
75%
Confidence score
Category tags
cryptocryptocurrencyfinance and insuranceindicatornetworknorth americaresearchedunited states

Activity Timeline

1 total obs
May 10May 10

Threat Activity Heatmap

· Peak: 2026-05-10
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated

The domain **planet.news** has emerged as a significant indicator of compromise (IOC) linked to cryptocurrency-related threats originating from the United States. First observed on April

Threat ScoreHigh Risk
75
SIGNAL
Signal Score
75%
Confidence
5
Reports
First seenApr 17, 2026
Last seenMay 10, 2026
Verified IOC

VirusTotal

Not checked

WHOIS

description
We identified a phishing domain impersonating Bitso that operates as part of a broader malicious advertising and traffic distribution network targeting fintech and Web3 users. The infrastructure chains together multiple redirectors, disposable domains and ad distribution services to deliver highly variable content. Observed payloads include AI-generated fake news websites featuring synthetic imagery, ClickFix-style landing pages designed to trick users into enabling browser push notifications for large-scale advertising spam, and fully AI-generated YouTube channels focused on music, philosophy and storytelling. In edge cases, the infrastructure redirects victims to low-visibility Spotify tracks that also appear to be AI-generated. We refer to this ecosystem as “AI-dvertiser”, an emerging model where generative AI is combined with ad fraud, social engineering and automated content farms to create scalable and low-cost malicious engagement infrastructure.
domain rank
-1
raw
Administrative country: Czech Republic Administrative email: [email protected] Billing country: Czech Republic Billing email: [email protected] Create date: 2024-04-30 00:00:00 Domain name: planet.news Domain registrar id: 1505.0 Domain registrar url: https://rdap.regtons.com Expiry date: 2026-04-30 00:00:00 Name server 1: aspen.ns.cloudflare.com Name server 2: cleo.ns.cloudflare.com Query time: 2026-01-31 03:36:19 Registrant country: Czech Republic Registrant email: [email protected] Technical country: Czech Republic Technical email: [email protected] Update date: 2026-01-30 00:00:00
subdomains count
30

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 2 months ago · Last seen 1 month ago
Appeared in 5 threat reports