Group:
Fog
Discovered by ransomware.live: 2025-02-07
Estimated attack date:
2025-02-07
Country:
Description:
Extract from Gitlabs: Chalmers tekniska högskola, Fligno, 3SS
Infostealer activity detected by HudsonRock
Compromised Employees: 192
Compromised Users: 92
Third Party Employee Credentials: 76
External Attack Surface:
137
DNS Records:
The following DNS records were found for the victim's domain.
- chalmers-se.mail.protection.outlook.com.
- apple-domain-verification=MvsPYqcOzN5YzbCH
- v=spf1 ip4:129.16.226.128/26 ip4:129.16.226.155 ip4:129.16.226.153 ip4:129.16.226.249 ip4:129.16.226.250 ip4:129.16.226.251 ip4:129.16.226.252 ip4:129.16.222.145 ip4:129.16.222.36 ip4:129.16.227.69 ip4:129.16.222.81 ip4:129.16.222.137 " "ip4:129.16.222.107 ip4:129.16.4.104 ip4:129.16.222.112 ?ip4:129.16.0.0/16 include:spf.protection.outlook.com " "ip4:62.181.197.26 ip4:193.75.93.154 ip4:91.123.56.128 include:_spf.ungapped.com include:spf.topdesk.net include:spf.bngaged.io " "include:auth.msgapp.com -all
- ZOOM_verify_VzM3LmjDRKajK0r6i4U8Nw
- adobe-idp-site-verification=2f08bb719e96ca4f9b05dde868ad04193eb3ace7052d0cdc1bebcd0183115fb0
- UINFO: Chalmers Tekniska H\246gskola (ISO-8859-1) [sv]
- mentimeter-cbc62098-17f2-4a14-986a-fd42319f0835
- mindmanager-verification=21d5ed4f63465e42d1177116f4cc2b85eed35edebc0a35c829f145a5d47221e2
- UINFO: Chalmers University of Technology [en]
- IxQ32Cp0vVZHXqLp2pA8M7ySB2BiQVcrf5ECEAXEEP25nH4PbnhVTyLDYDY3/dUH58Gt2SVA5HWpxV/0n3OqbQ==
- google-site-verification=oF0feLOFPGBIp7_IyITWLdXTKcGDXbc4CbPGH2qu-z8
- MS=ms47016442
- UINFO: Chalmers Tekniska Hogskola [sv]
- facebook-domain-verification=9d92s277ebot36swusg8xt09am32zh
- HARICA-UNAwJdkNljBQp3EtETZ
- UINFO: Chalmers Tekniska H\195\182gskola (UTF-8) [sv]
Cloud / SaaS Services Detected
Adobe
Apple
Microsoft 365
Zoom
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.