Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Chonburi Provincial Administration

Group: Thegentlemen

Discovered by ransomware.live: 2026-02-06

Estimated attack date: 2026-02-06

Country: TH

Description:

chon.go.th official website for the Chonburi Provincial Administration in Thailand. This local government organization manages the Chonburi Province, an area that includes the popular city of Pattaya. Its core functions involve providing local civil services, infrastructure planning, public health initiatives, and promoting regional tourism and the economy.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 21

Compromised Users: 9

Third Party Employee Credentials: 1


External Attack Surface: 10


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • staff@thnic.co.th
MX Records
  • mailgw.chon.go.th.
  • webmail.chon.go.th.
TXT Records
  • v=spf1 a mx ip4:61.19.155.12 include:webmail.chon.go.th ~all
  • google-site-verification=0ff25tBQwGaBpEmOAkTLD_jYhKN5WmaUMA-hO8wLkZc
  • v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEApOEBzhcB+4YslWOFQ2Y3ttYNAeHGTJdGlAWbjHL4KZnf3+9KzulqzvxgEWcuwSCSjlFOUl9re7xNJD466LBz4c/tVvYmrovhA2204TBk0e5fSeupzE5zDn4cDhSdgtEs+n9SAngqLTz8ZGTw12U/HRZlDedGNp/YjwbCZ5/oiaioWynSXVVST2VTlvIQRQjyX" "34eILVXYSEkC75oqsVsnG79VmBD4iJvkO/Qh/I/9rkPpBG20HGAfG1dBq1HrVCpQS2M8ZE+XbENavBqtfw7qgqnZxh1x+eVPrdJzSlgn0nbxEvuZPm+HzUQKjCrw3uwZelEBxPD4THPRUxihXBfGwIDAQAB
  • apple-domain-verification=jn9JIPFwNSB2vDdb
  • _globalsign-domain-verification=bNvo1jsZAembU9u1KJgZhz28FPPzhXipaS6Pr34WRn
  • MS=64D94699CEABF2E3E9F1120A3DE5437F86A4D974
Cloud / SaaS Services Detected
Apple

Leak Screenshot:

Leak Screenshot