Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo CFM Mozambique

Group: Qilin

Discovered by ransomware.live: 2026-01-16

Estimated attack date: 2026-01-16

Country: MZ

Description:

N/A


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 8

Compromised Users: 13

Third Party Employee Credentials: 5


External Attack Surface: 13


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • antonio@uem.mz
MX Records
  • mx02.cfm.co.mz.
  • mx01.cfm.co.mz.
  • smtp.teledata.mz.
  • relay.cfm.co.mz.
TXT Records
  • google-site-verification=XKMLP-HzT-q_X57EijX3U5fV7a5FTKiYxfk2OYKN7SI
  • dpoqph12ma98khorqm74519shp
  • v=spf1 mx ip4:41.76.150.161 ip4:196.22.53.28 ip4:169.255.133.20 include:outbound.mailhop.org include:spf.protection.outlook.com -all
  • google-site-verification=-Kei3UamDHBno0i9pt8DKN1EgqM0YHG5AFxP_kevwJY
  • MS=84F4B20746B715D9BE8BF10BBD071DAC8AB3F357
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.

Leak Screenshot:

Leak Screenshot