Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Anglo American plc

Group: Arkana

Discovered by ransomware.live: 2025-05-21

Estimated attack date: 2025-05-21

Country: GB

Description:

[AI generated] Anglo American plc is a multinational mining corporation based in Johannesburg, South Africa and London, UK. It is the world's largest platinum and diamond producer, with operations in more than 40 countries. Besides platinum and diamonds, it mines copper, nickel, iron ore, metallurgical and thermal coal. Founded in 1917, it is one of the world's top mining and natural resource companies.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 124

Compromised Users: 159

Third Party Employee Credentials: 441


External Attack Surface: 93


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse lexsynergy.com
MX Records
  • za-smtp-inbound-1.mimecast.co.za.
  • za-smtp-inbound-2.mimecast.co.za.
TXT Records
  • google-gws-recovery-domain-verification=56541847
  • openai-domain-verification=dv-4w8UAIqHSXcuaUs6c3CtiWjw
  • apple-domain-verification=gJlV79nQEBXxB29H
  • asv=0bb8f9926777d62179c4bb34fea20d6a
  • google-site-verification=NmVXYhNaKQGHu0qentVtibTG5rsHnKLsarDvWlDiJJ0
  • qhPyNfFaS05fAScUIxkN3ZMcff3FuN/rPOLU9H+RNqA=
  • flexera-domain-verification-zbofrhegmkufyhgt
  • _globalsign-domain-verification=eY66kPnBiSHa5RLQXayvccN-pQINBFplAOoAh1kfyK
  • asv=d60013ef54da1c8cd7b92c5e74aefb93
  • twilio-domain-verification=53976f1c552567e643b397e1b84e60a1
  • 1password-site-verification=7HEXHXQKIFDU3ANPLCADOHT73Q
  • canva-site-verification=7rbd_fRrydkSrSBDNFJEtA
  • miro-verification=9ef9c4534a25269aa4df6c4e5a8e489cec42a0d1
  • atlassian-domain-verification=siZ1uOON8GI5RLB4fy2z0ilSZQrsQXTdcAiH0vySxE5A8WdFRVvpV6EXvTqIsQM8
  • autodesk-domain-verification=MH9PmrJfp0l4DBjgYoJG
  • Z2Zt/tZBlIlpuEwX1K04muTuWzBZfNiYS1vz1uXPXAs=
  • docusign=5a7213bb-0615-44ec-ba2d-3a21e8308bb7
  • dtm-domain-verification=Uiu6V9AkCjLpYz82jMUwBXsd7PzgWzq__NAdjTpFb3o
  • adobe-idp-site-verification=d9a36a93fe71a3a9aa8eba01a724b3e78b250773a99477cb72fba996df8d0e0e
  • v=spf1 ip4:41.74.192.0/20 ip4:169.50.108.34 ip4:5.61.115.80/28 ip4:5.61.115.112/28 ip4:5.61.115.96/28 ip4:196.50.108.34/28 ip4:203.41.57.144/30 ip4:203.38.232.46 ip4:76.223.133.25 ip4:76.223.133.26 ip4:98.97.248.0/21 ip4:139.60.152.0/22 ip4:216.221.161.14" " ip4:216.221.161.15 include:za._netblocks.mimecast.com include:eu._netblocks.mimecast.com include:nw010.com include:nw011.com include:nw001.com include:_spf.qualtrics.com include:_spf.vivantio.com include:_spf.salesforce.com -all
  • atlassian-domain-verification=sPtxylF9sYh3s5Ml1KaEsCSh0plLJL6+jfPCYXLLnH0MSX3Zdni2nA6EIQaKDiLn
  • +zbyA9o8tag/032D/x33Gbplg7U9Hm8xomplQSSZ/5s=
  • astro-domain-verification=cmejqt4w20afx01l51ocm854h
Cloud / SaaS Services Detected
Adobe Apple Atlassian Salesforce Twilio Miro Autodesk Flexera Mimecast DocuSign

Leak Screenshot:

Leak Screenshot