Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Qilin
Discovered 2026-05-11 21:55 UTC
Est. attack date 2026-05-11
Country CA

Description:

N/A

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 114

Third Party Employee Credentials: 10


External Attack Surface: 39


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • icann-abuse-reportstierra.net
  • whoisemailaddressprotection.com
MX Records
  • aspmx3.googlemail.com. Google Workspace
  • aspmx4.googlemail.com. Google Workspace
  • aspmx5.googlemail.com. Google Workspace
  • aspmx.l.google.com. Google Workspace
  • alt1.aspmx.l.google.com. Google Workspace
  • alt2.aspmx.l.google.com. Google Workspace
  • aspmx2.googlemail.com. Google Workspace
TXT Records
  • zendeskverification=e17cc91a8f432144
  • stripe-verification=effd433279e51a965aac2593c3344c9f099b264a103b0ef35904af59198330a3
  • zoom-site-verification=ecc14ac9ba18432bbbd877d70a4e3d04
  • arcules-domain-verification=axzVjEVPni4TFOLQrVG2honTghUQTXl7HY79JxSqRea
  • smartsheet-site-validation=SdVbox9cq_8IL0Gd3YzRx5BgONMbmTAc
  • wiz-domain-verification=cb7c1abc690cdefa8f5b084510b4f3bf5621911d1975b86510e280a0a3a05559
  • docusign=511c5e77-69a2-4a5c-a234-965a4c16c526
  • pardot856853=21b06ed98c2adc16d53c5c864d49b6f6b2e0d55d94a2bfeeb166f837c16ec8e2
  • v=spf1 ip4:173.241.44.15 ip4:107.20.210.250 ip4:52.1.14.157 ip4:173.241.45.15 include:sendgrid.net include:_spf.google.com include:docebosaas.com include:aspmx.pardot.com include:mail.zendesk.com ~all
  • mixpanel-domain-verify=e7730992-eb03-4fc0-8303-96fd50759441
  • globalsign-domain-verification=a46d5a53f27edebe63ad70408592a108
  • 2b3bf3eee2475e03885a110e9acaab61
  • MS=ms53674838
  • google-site-verification=Zsk1JzXKXiIhM_SPonZot26aTg-COD0cYoRStyNdbnw
  • ca3-eb8648a5819a435a85c257c073ff0ee0
  • pendo-domain-verification=a568aadd-2b07-42dc-88f8-9d74cb341215
  • google-site-verification=CTPbQRHzf7h9a1_6C4eWndSA-W73UkiStTXqoOOGGHs
  • teamviewer-sso-verification=dfb874f3521749cb9cedaefb3e00c6ae
  • google-site-verification=5DTsfk6zYMvsK7kvLdqBAseknoFxsbNquQNB35hUP9I
  • adobe-idp-site-verification=1ba013a0f454f8c58a5d2ca7331fec0d3d49b7eb5804b5d414323c2e19fd9dab
  • adobe-sign-verification=eb9cd6098776387ac7908ac19d1cbbed
  • atlassian-domain-verification=Gs1clXmVuYbym5MenzkD3kzdVzC59wXFLciOW6Cz4f2LCG/7KVQDY1qYz4nBHLEH
  • google-site-verification=xVOl-s85o70UK_1YvlSVqNp8le0bClvPV6DPYfYypyU
  • apple-domain-verification=ugQpvTuh68MzXM93
  • cursor-domain-verification-mnry45=Leh3pCWgNhfXxQefxfk47NfiG
  • _globalsign-domain-verification=lJiMTBl58P7tMCeQ-XNERAXoxceZp40SSIecGBQHfC
  • ca3-3645a03caf01487ca16a84e1638c9966
  • google-site-verification=9UT1ZBtm4UvloeL8GpCRtod8SkkSqWOBgpPeL_efsC8
  • google-site-verification=dy6R3rtELuC6m8j1ZfA8A1USGdAD9ORsDE3aNxuWEl4
  • miro-verification=0b80ce0cec16f6bc22b6dbe7a371589c793aa7cb
  • stripe-verification=ef62615628c5bbe34179aa78216f32d4c4f0d402b7f5b775e185d6bef2855268
  • stripe-verification=ED2F55416F8B74F3E6CFAC1D0D16C154011C5DDFC47C9B84A91D99E9F68C78C3
  • globalsign-domain-verification=637cd34791ba00124fd2f0e519560060
  • logmein-verification-code=c1e94cb4-dccf-4697-949f-07344eee1d8d
  • lovable_verification=LkG1GusePYR08UvK07PT
  • stripe-verification=428b2fb9317c540f70b0cec6226ab94b5ef741b74eede137b4ab3994dad8a382
  • docker-verification=8bff4c8a-f20c-4f9a-959a-cfa102796c62
  • atlassian-sending-domain-verification=df5a947d-0b41-42f0-a66b-08237654dafc
  • slack-domain-verification=vIUYGxN5AD4i2nKcSMypvlrxSTEB2j2w2QZnJSwX
  • twilio-domain-verification=8fbb671e6386807bd62f5a9434ff0076
  • convex-domain-verification-g0avt6=ZorGJC8RipPZqhdtk7VzgTw72
  • sending_domain856853=7a63ae86e0792f0aefbe3c9d6da30c7c7ebad8ab7c74af7b7926e2f30abe4791
  • sending_domain885773=7d8a969c03e39d95fd73c8aea1bdb1da55af4b763a5fef7a8a7387ac5d827967
  • ZOOM_verify_h7iUTkWWqeKLA5pJ49yeFl
Cloud / SaaS Services Detected
Adobe Apple Atlassian Docker Global Sign Microsoft 365 Salesforce Slack Stripe Miro LogMeIn Teamviewer Zendesk SendGrid Twilio DocuSign Zoom

Leak Screenshot:

Leak Screenshot