Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group: Coinbasecartel

Discovered by ransomware.live: 2026-04-08

Estimated attack date: 2026-04-08

Country: BR

Description:

[AI generated] Correios, officially known as Empresa Brasileira de Correios e Telégrafos, is the Brazilian state-owned postal service company. Operating under the federal government of Brazil, it provides mail delivery, logistics, and financial services across the country. Founded in 1969, Correios handles package shipping, express delivery, money orders, and e-commerce logistics, serving millions of customers nationwide through thousands of agencies and distribution centers.

Infostealer activity detected by HudsonRock

Compromised Employees: 420

Compromised Users: 429864

Third Party Employee Credentials: 377


External Attack Surface: 165


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • correios-com-br.mail.protection.outlook.com.
TXT Records
  • globalsign-domain-verification=Dmqwl5n2NjS3n0PNfcJV1juLpeRxmkeyCyW-gOSfJK
  • MS=ms24967708
  • MS=29C126E6850B5CBE7C210125FA2E751926849962
  • google-site-verification=80BfDQu4N5U9hKTms4bM9q5UF3FzOpmgoZ3PzexUcvQ
  • S1H24bt45BKOdzQSNJxdQcLEKKvEF/r3bM+v1UZ+NtlUd9KFHEKSKTjLD3ZBqtEqfqg9iAB8cwExffGBkVLjKA==
  • v=spf1 mx include:spf.protection.outlook.com a:mx1.correios.com.br a:mx2.correios.com.br ip4:201.48.198.27 ip4:201.48.198.26 -all
  • Dynatrace-site-verification=79b80282-44b0-4146-9b2d-43bc1b3ac606__qsqu821ai1ido281u1bc4rlfd6
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot