Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Amla Commerce

Group: Dragonforce

Discovered by ransomware.live: 2025-12-17

Estimated attack date: 2025-12-16

Country: US

Description:

Amla Commerce develops ecommerce software platforms. Architected with a focus on long-term sustainability, the platforms offer unmatched flexibility and scalability, as well as premium feature sets and deep functionality proven to enable growth and support even the most complex operational needs for mid-market and enterprise-level companies. Amla Commerce is the parent company of Artifi Labs, an enterprise product customization platform, and Znode, a .NET ecommerce platform with headless architecture and multi-store capabilities. Artifi and Znode power the ecommerce experiences of hundreds of companies across dozens of industries including apparel and soft goods, promotional products, uniforms, CPG and retail. Amla Commerce is a privately-held company, headquartered in Milwaukee, WI.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 33

Third Party Employee Credentials: 4


External Attack Surface: 5


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • amla-io.mail.protection.outlook.com.
TXT Records
  • v=spf1 include:spf.protection.outlook.com include:_spf.google.com ~all
  • MS=ms36308826
  • MS=ms66441113
  • atlassian-domain-verification=66cf8h1E2b7OcDjz8mvNx2saB4zXjTX/nU1AL9zcw2Mf/IoUgC5pbjfTpSb0T8eU
  • atlassian-domain-verification=Ff4hpnqUpueobZXaFmH9Z1XpczvwL0pracOexSzuxeRuYflBaov0IEj0wimbUzVt
  • google-site-verification=92X05OYFk0Q32LPczle2h_WCxqCCFIRMDDlPVIXFb4M
  • google-site-verification=jHi7YQj41z4gR8bTI-3bDcvX2BAMzK0VyyWgWtMJanI
  • new-relic-domain-verification=8de9e5e13cbb4fcf8617098d866710df
Cloud / SaaS Services Detected
Atlassian Microsoft 365

Leak Screenshot:

Leak Screenshot