Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo GoHighLevel

Group: Nightspire

Discovered by ransomware.live: 2026-02-28

Estimated attack date: 2026-02-21

Country: US

Description:

Data is not available now.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 13

Compromised Users: 7626

Third Party Employee Credentials: 15


External Attack Surface: 105


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@godaddy.com
MX Records
  • alt1.aspmx.l.google.com.
  • aspmx.l.google.com.
  • aspmx2.googlemail.com.
  • aspmx3.googlemail.com.
  • alt2.aspmx.l.google.com.
TXT Records
  • cloudflare_dashboard_sso=6ca005c42a40dcb27261770ea16e0fea
  • google-site-verification=RfbhXPugyR0u-bLb97J0JxN3pSZokimuZwwpo2-06hE
  • google-site-verification=Tv9culM0dSFxyXdzzgq0bHUIAC3m8CTurbELxiVQ32A
  • 1509782814
  • miro-verification=cb3b010b48ec18e3d7f9df0177f3eb5387211166
  • apple-domain-verification=_bm3jYSdU0uCrCwcdCM4JMsGjrLKTRIpvsq7Uh5eOmM
  • sinch-domain-verification=c6c157c7-78eb-406d-b328-1d64e2e5b50d
  • OneIDP=a9f4c4e2c6406fdbdcfdc5836fe1a99f
  • instatus-domain-verification-t3dnzt=AhR7AcPbX0oDDy2b9HIRxWLR7
  • bw=ljVS8qBNBcE9iCIa2xJC6ofkGcLOdF2RydyuoHVU6P7I
  • mongodb-site-verification=xLCzJtaKmyqISvuP10AsHvJWGFADOJiG
  • postman-domain-verification=190451f6c8bd6a126c8c1a0db1638b6a4cdfb751cb1cca7dab06b31be6dc153ebcf574c154efe616c73af395c2951ac97c7be3b9071f1e36b311cebad7ffc7cc
  • v=spf1 include:_spf.google.com include:mailgun.org include:spf.tipalti.com include:sendgrid.net +a +mx ip4:66.147.238.90 ip4:161.38.196.192 -all
  • google-site-verification=HZkZtpn3pjD69nBCk-t3J_BsmemzYCEKVXQMo3cTwLg
  • MS=7958BA48666C92C551607C0262ADC83616A77191
  • stripe-verification=a80076e3b4627053e8d0f972282f9a32f3e4878225d8bbefa17fc6505e2f97de
  • yahoo-verification-key=X8dCr+EA1Jcyi+R4BK5k5mi8WZfC61a7heiRUR9XWJs=
  • google-site-verification=tZFKGjMbztQ-zMYcOHtoQQwvcN_l-yabYzL_rUtH0hA
  • ZOOM_verify_Ba9X9NDY0mnJqDdvTItgdC
  • openai-domain-verification=dv-bQUjkzhajPDJn5ToTdAuBaaQ
  • cursor-domain-verification-rhzw0n=piy1Pgo0ElshlDZffnjAe6rzY
  • google-site-verification=n6TQthLMWHOcN6ccVnd6rVIArBS45KrswnUgBjuspeg
  • 4042F58073
  • google-site-verification=YWA8Zfooo1wJm875P6mgEJDMoz_rS3A6EroBFoJNSEY
  • google-site-verification=EDNpX_CHJfgcJHJWe2mhhH_rBI1PeTqUiCQ_B83NcpM
  • facebook-domain-verification=wlzdputt16fjgn1w2cm9kq0g0p78ok
  • zoho-verification=zb84057158.zmverify.zoho.in
  • stripe-verification=3D7EB09E187614598E5E6D063943EBCB61108555D1A8FDA6AA8B1C25A63AE945
  • google-site-verification=7-m-AlNZ_YUgIUmL7F2a_2zyFusijbRAHcNRx69nCVY
  • google-site-verification=9oDEXrJ9vkBoeMSfNpZ9ScUeFEDI8c8uwybV0PdBVOA
  • apple-domain-verification=J1lKhowNIEOcDq0l
Cloud / SaaS Services Detected
Apple Stripe Miro Mailgun Zoho Campaigns SendGrid Zoom