Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Cal Spas, Inc.

Group: Qilin

Discovered by ransomware.live: 2026-01-04

Estimated attack date: 2026-01-04

Country: US

Description:

N/A


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 9

Third Party Employee Credentials: 3


External Attack Surface: 8


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • mx-02-us-west-2.prod.hydra.sophos.com.
  • mx-01-us-west-2.prod.hydra.sophos.com.
TXT Records
  • v=spf1 include:_spf_uswest2.prod.hydra.sophos.com ~all
  • MS=142869861550F16A33C72B3E8C4FF907C31ACEDC
  • sophos-domain-verification=278f51e276f6833e4917d3e5935c0d2438a729d829f621c8afff2434bf0db754
  • v=DMARC1; p=none; rua=mailto:dmarcreports@calspas.com
Cloud / SaaS Services Detected
Sophos

Leak Screenshot:

Leak Screenshot