Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Gemini Group

geminigroup.net

Group Rhysida
Discovered 2025-10-28
Est. attack date 2025-10-28
Country US
City Verona Township

Description:

Gemini Group

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 1

Third Party Employee Credentials: 1


External Attack Surface: 1


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • geminigroup-net.mail.protection.outlook.com.
TXT Records
  • k8et34j9efp692f8134qtsceel
  • opech5027kutmrm3gd9eotjgba
  • os04073hr2glrcljecfg05p0cg
  • v=spf1 ip4:64.90.209.162 ip4:208.99.235.10 ip4:216.25.179.10 include:spf.protection.outlook.com include:aspmx.pardot.com -all
  • alrds93oehj8akbgaoiu10ojvl
  • duo_sso_verification=mzkUKKDQGmfFcAwU6o9jxVwBLHmGRrIcL1gr75iDJytOtKPDVZruWclDrlPiDdWQ
  • pardot919543=2e6fd86e0cf4f5ba9bcdf9c94292e554076eb9d7000282e0fda5a348fa7f1ec8
  • google-site-verification=WefZs75vt6X7j4NshEEC8ndhvtkYfok43TIKVgRoUKc
  • MS=ms47497342
  • e06acchi3agkm3de226n0frqfs
  • 20nfh5ve29kq1ith30j49fd775
  • 1ed5d3dc-21b0-4e48-9e6c-719645b52945
  • 1h52qrb50183hi1ldd61iqlftf
  • 4fs7md+9h2yXxTBntSDvTAlzSYrTH4dDYKqBjb63S26h4lr43H3dm+gCq2C3vtte8vbD1POgb1jp3sWoGl9Aig==
  • tthmnavkkdl45tq8ic3il5cmr
  • mmtub06qo74ukbo2ujv3bb9n1
  • k4280eqgcl5ah4hbph46fkskfj
  • l4se5dq9gmpe7c6lsoaidqjrh4
Cloud / SaaS Services Detected
Microsoft 365 Salesforce Cisco Duo