Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Group Medusa
Discovered 2025-10-27 11:05 UTC
Est. attack date 2025-10-22
Country FR
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

ATIRG (Association pour le Traitement de l’Insuffisance Rénale en Guyane) is a non-profit medical organization located in French Guiana, dedicated to providing dialysis treatment and kidney care for patients suffering from chronic renal failure. Established in 1981, ATIRG operates several autodialysis centers in Cayenne, Kourou, and Saint-Laurent-du-Maroni, offering patients the opportunity to manage their own dialysis under professional supervision. The organization focuses on improving patients’ quality of life through medical care, training, and nutritional support. ATIRG works closely with local hospitals and healthcare professionals to ensure safe, effective, and continuous kidney treatment across the region. company is headquartered in 1361 Route de Baduel, 97300 Cayenne, French Guiana.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 1

Third Party Employee Credentials: 0


External Attack Surface: 1


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • registry-relationsepag.de
  • domainshostpapasupport.com
  • aekiihgmail.com
MX Records
  • mail.atirg.fr.
TXT Records
  • v=spf1 ip4:190.180.145.171 ip4:66.102.132.190 ip4:76.74.128.248 +a +mx +ip4:76.74.242.180 +include:spf.hostpapa.com +include:relay.mailchannels.net ~all
  • @=ea18d2260f4dbbf1c202110281863b7e
  • www=148d552c1832cca3f5442baec52398e4
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.

Leak Screenshot:

Leak Screenshot