Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Qilin
Discovered 2025-11-23 17:11 UTC
Est. attack date 2025-11-23
Country CA

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 0

Third Party Employee Credentials: 2


External Attack Surface: 1


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • 4c101b1e1005054565cc3db2d9fd8b175d9840c065e67b42a0cd6192a2ef313dbertselectric.net.whoisproxy.org
  • trustandsafetysupport.aws.com
  • 4c101b1e1005054565cc3db2d9fd8b175ee878e80f93d2eee9acdf965126fbdbbertselectric.net.whoisproxy.org
  • 4c101b1e1005054565cc3db2d9fd8b17aabfdefd359cca4aa6c8623d846ee3efbertselectric.net.whoisproxy.org
  • 4c101b1e1005054565cc3db2d9fd8b17a81e1ff61f7306f960fc7c1b8cf68bd1bertselectric.net.whoisproxy.org
MX Records
  • bertselectric-net.mail.protection.outlook.com. Microsoft 365
TXT Records
  • L9fACiGjrVvDkjryIqxrhtrczgh9VOtFS82HR3mnNbuLVF7l69sKvF/++u/BskJkWzDaiDZfXAF/LiRUIxdP/w==
  • MS=ms37637356
  • apple-domain-verification=gBuhmDa2ov5guGkN
  • v=spf1 mx include:reflexion.net include:spf.protection.outlook.com include:relay.mailchannels.net ip4:162.243.130.109 ip4:96.55.122.110 ~all
Cloud / SaaS Services Detected
Apple Microsoft 365

Leak Screenshot:

Leak Screenshot