Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group: Coinbasecartel

Discovered by ransomware.live: 2026-03-19

Estimated attack date: 2026-03-19

Country: IT

Description:

[AI generated] Ariston is a renowned Italian company that manufactures state-of-the-art home appliances such as heating systems and water heaters. Established in 1930, Ariston is recognized for its quality products worldwide, especially its flagship water heating products. It is a part of the Ariston Thermo Group, which is a global leader in thermal comfort solutions for domestic, commercial, and industrial spaces.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 115

Third Party Employee Credentials: 16


External Attack Surface: 49


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • noc@fastnet.it
  • B0EF039EAA02176DF05C051AA5FE7196_1384725_a@whoisprivacy.com
  • legalservices@eurodns.com
  • m-b@ariston.com
MX Records
  • mxa-004bb102.gslb.pphosted.com.
  • mxb-004bb102.gslb.pphosted.com.
TXT Records
  • google-site-verification=YJ22e6HDw7yfwyvCS7PdPHBlI2CvewCpzzJoLILkROI
  • successfactors-site-verification=ODVhYjFkNjZlZWViOGQ1OTAzYjA1ZGRhZTE2ZmU2ODQyZmMyZDIyY2FkOWRkYzJkYzFiN2IzN2ViZTA2ODE5NQ==
  • google-gws-recovery-domain-verification=52419108
  • miro-verification=2405797a2d7dad9fcfd69e466ab73dc7c289f3d6
  • 5pf9m72g3764hi9nr2n1v5bgg7
  • pardot967093=c8e36a1c8ce56fbe5507ced1240db8160eb1ba5a95756a8c23469428198d6c1a
  • google-site-verification=xQg7J7r_b3uhTxaJGOwYhYcNVNNKowAgfGMfC4WoiW0
  • facebook-domain-verification=vh1kbo6sbeydosm4icgkuop40m5t1h
  • google-site-verification=PJfOJd-hwJ3HeDwXWeqPnmmFgTw4fi8KGVD1zXDGBQg
  • 3fh0pqt2fpg25cq6g85inlm3re
  • biTQwWeYYAWYkWA+qAtseAKQn+kWJocshuxOw627uxtV1ndFfzC8g9KpX2CW7kWN4IEi4WsKBl7ewLsbRDwaLA==
  • v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -all
  • google-site-verification=S6BP2pA9rquSglJtNzW6TpAqWq6KpcUqveE28ttXe9s
  • MS=ms55345362
  • workplace-domain-verification=ErgVKlTAi2Wlk33R5eSbywrXaM3dJX
  • google-site-verification=Rcwyld9qCxI8QnIha-yGQ75NFr6fARPzxjm7JVofEPI
Cloud / SaaS Services Detected
Microsoft 365 Salesforce Miro Proofpoint

Leak Screenshot:

Leak Screenshot