A DNS investigation into indicators linked to three Russian threat groups uncovered potentially victim-owned IP addresses and thousands of connected domains, including infrastructure already associated with malicious activity.