Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Allegis Group

allegisgroup.com

Group Everest
Discovered 2025-09-09 22:13 UTC
Est. attack date 2025-09-08
Country US

Description:

[AI generated] Allegis Group is a privately-held global talent solutions provider. The company offers a wide range of services, such as staffing and recruitment, workforce management, and talent advisory. Their expertise includes IT & communications, aerospace, biopharmaceuticals, energy, financial services, and more. Allegis was founded in 1983 and has its headquarters in Hanover, Maryland, USA.

Infostealer activity detected by HudsonRock

Compromised Employees: 27

Compromised Users: 2583

Third Party Employee Credentials: 59


External Attack Surface: 112


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mxb-002d4f01.gslb.pphosted.com. Proofpoint
  • mxa-002d4f01.gslb.pphosted.com. Proofpoint
TXT Records
  • adobe-sign-verification=248942193172560a48d1cf47a432a4c
  • dc93lv1nkkgto3151n6f9sncoi
  • google-site-verification=uk0lvp6irse8t7ja82qpe2c8nr
  • google-site-verification=llk6nar7mkkohqfieoe5a8bibd
  • google-site-verification=SczhfRIbd18V2Q6vOMMKomzESxEkArwNOPLbVt4R8DM
  • apple-domain-verification=sqZrCVmy5iiEOruI
  • jamf-site-verification=-BJ8Pe1nrds-2a9q1udpLQ
  • miro-verification=0006f8de4c90acbe05b5aa56e2b340727fd0b303
  • ZOOM_verify_8TKKJSFOLVr1AYobkpLwZ3
  • v=spf1 include:direct2u.spf.dt.com include:spf-002d4f01.pphosted.com include:cust-spf.exacttarget.com include:spf.protection.outlook.com include:a._spf.allegisgroup.com include:b._spf.allegisgroup.com include:spf_c.oraclecloud.com ip4:66.159.240.106 -all
  • amazonses:8bN+BZFb5T0xE5Ob7AEZm5lq931GMhPbPPixTnJ+1ak=
  • openai-domain-verification=dv-os7ZVUvyprpcYhV06IwA5MRQ
  • ibmid=2c5a88a1-d48c-4baf-8723-a7708731ad00
  • teamviewer-sso-verification=7de92e35ec034f0187591e049070c528
  • jio1v1lr776n07012riulf6oua-test
  • 4lcbnia3linsv8f640jf5qdir6
  • google-site-verification=896aa1brr7rt41enm0s6upi305
  • 7sbc9tsu5ot3lv8o11o4i3e4ss
  • q4b5drclks0ndl9zpt5g4w558036w6s8
  • 75EFD29F21EDCD2582DA1744F8FBBDD5E2A17DAE2D67DDD122BC4A8BA9AA6227
  • 7ihl9afrj3n8pakqqvdv2dbcsb
  • FeOV0SnCYga9ImMszpISmodHr3aSlJZEdAbNp28piBTVISwdV0Gx+BTZxkariZgviJfLgJ0s7Kk7qA9ForGQ8Q==
  • 96hf563f2vjvv5d5cvgeb7sm3b
  • 86h9namd8g5u1j15s1v86lu68d
  • onetrust-domain-verification=355f1de78adf46d5bbd55004149359aa
  • lq4e9sskaqtcjbqajsjrg398dg
  • anthropic-domain-verification-f0b0w1=jjZrsmdrFvU72T0LyOx8k7dmI
  • 896aa1brr7rt41enm0s6upi305
  • 21fb71b2-a7a6-4ffc-873c-957a95d7c06f
  • tdpne6h5q3vahrn6lnjq0ee1si
  • nfj2qoccf7h69pbsmigi1pc76g
  • facebook-domain-verification=dp4263mtvgmsm8f96vauem6f31dadu
  • 7hj8dfmj3q5c9cm5r9ltjglgb6
  • docusign=d5843398-e75d-4126-809c-b06557edcff4
  • nt41k7324ep0v9s9gqfdejp6u
  • o7fe101lc5kptbignmkb0s9jt7
  • 1kmhbootqs1abtd7kbq2f0ipjv
  • 1cm9s2bam7fk4vi23rfdga4g7c
  • _0qgjm2umyvoat5owjnyq7olfx8f690l
  • perplexity-ai-domain-verification-5njshg=F7KQQ1kyzTBfcAqHjKNUXN1CT
  • oj3enie4gurab59uakdv8g5oo7
  • docusign=b285cb7d-06d8-495b-859f-6da2b9421125
  • vaj4gk9eo7u23l23390a6mhb8n
  • uco4thsfp33bt4uivga612l2r6
  • jio1v1lr776n07012riulf6oua
  • 2og4udjvqsb570r9hon70an1t6
  • atlassian-domain-verification=0dftaw5Vq0uVrv7Wk01GFJbQFOsYNa9fhWRUXEtHA1vaTJqXadaDNM8gMPueKHB6
  • apple-domain-verification=MlW3T0R7FVfpY62H
  • u3ligdqdvnulv0hm2nb7n6dmt0
  • cisco-ci-domain-verification=3173c88562a8501ad149d268e7c597effbf1fd4c4410b3581fc009da820cc859
Cloud / SaaS Services Detected
Apple Atlassian Amazon SES/WorkMail Anthropic OpenIA Miro Teamviewer Oracle Cloud JamF Cisco OneTrust DocuSign Proofpoint Zoom

Leak Screenshot:

Leak Screenshot