Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo CILI

Group: blacknevas

Discovered by ransomware.live: 2025-08-06

Estimated attack date: 2025-07-02

Description:

"cili.lt" is associated with Čili, a restaurant chain that operates in Lithuania and Latvia. It started as a pizza restaurant and has since expanded into various areas, including bistros, traditional Lithuanian-style restaurants, Chinese restaurants, coffee shops, and drive-ins. The website allows users to order pizza from Čili Pizza. Additionally, there is a mobile app available for ordering, which offers exclusive discounts.In stock, the database containing customer data, addresses, mail, mobile phones, shopping history and banking card


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 71

Third Party Employee Credentials: 1


External Attack Surface: 29


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • cili-lt.mail.protection.outlook.com.
TXT Records
  • v=spf1 include:spf.protection.outlook.com include:sendersrv.com include:mailgun.org ~all
  • 3UXL7/DQcD0G4X0s68vWA229gnJUW+L045VHnHVU41OEgzJ4NgEDEps0DEXgGIpQPKSWeMVhx7hxJwloSRm0rg==
  • MS=ms56413535
  • google-site-verification=9wFQFl_w4a-_YHXKGjkoZUPjJ1ZmZ865T-yPqLb0P9s
  • google-site-verification=DuEGh8w6Xv3jpYmTbGk5PUt4Mm-reNmKW6s4v8UzPNc
  • google-site-verification=E0-pELH8gR9CA9nYT3mB6sxHYF0S14kFMIIKcJKyfd8
Cloud / SaaS Services Detected
Mailgun

Leak Screenshot:

Leak Screenshot