Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo ENVOY.COM

Group: Clop

Discovered by ransomware.live: 2025-11-21

Estimated attack date: 2025-11-21

Country: US

Description:

[AI generated] Envoy.com is a provider of technology services designed to modernize and streamline office operations. The firm offers software solutions including Envoy Visitors, Deliveries and Protect, which automate sign-in processes for visitors and packages, and screen staff for COVID symptoms. The company's overall goal is to create safe, efficient workspaces.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 511

Third Party Employee Credentials: 5


External Attack Surface: 32


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse support.gandi.net
  • 9020c455286627e436e8f63131b825b7-4231526 contact.gandi.net
MX Records
  • alt1.aspmx.l.google.com.
  • alt2.aspmx.l.google.com.
  • aspmx.l.google.com.
  • alt3.aspmx.l.google.com.
  • alt4.aspmx.l.google.com.
TXT Records
  • google-site-verification=MUPNGBfhTk1c52bUY8JPFECJTx05e2AN4fItQdf7fbw
  • google-site-verification=KIvwqRtYqxC51iZXYkoNa7G4kZJzD3uSFAeBYYey2eM
  • smartsheet-site-validation=fAwG-5HX02-QXWJdyi4sPqC2hAPXNMUg
  • ZOOM_verify_adSFJkkMQLaDm5wL7UdW8g
  • zapier-domain-verification-challenge=8bf7818c-f91c-4fc2-b175-1d60c42f1c9c
  • MS=ms35993171
  • v=spf1 include:sendgrid.net include:mail.zendesk.com include:_spf.google.com include:spf.mail.intercom.io include:servers.mcsv.net -all
  • astro-domain-verification=cmavf8foj24nd01ogvu0gpyh6
  • apple-domain-verification=Lf8mopan9g5HrkXW
  • atlassian-domain-verification=ET+0cP-Ec+Vi0IMZTDMPAZ5LbYuUl9wxeBxNcGSVZMYhEHD+TFcdjMVIg74qYCAp
  • drift-domain-verification=91d9bc0b8e949caeff9ff9e5dc22869757fda4bf2d6c892c9cdf5314e4f3b36e
  • docusign=bb7435c3-82a2-49c0-a80a-7e492c617992
  • google-site-verification=evYlQu6cTGTkoHIYW1tMQrzyeY18Pt1LDBHS5XM0fV8
  • postman-domain-verification=8282375de34cbbb28cb10de030e9b992028c691d57da6330be4a295121f57ff825ed360227d40791d10023f88b8ad1b6bbfedf37838be89922da3f6a7d48fea9
  • adobe-idp-site-verification=1e82124beb386dbc8a7ce80a0b24ba2e99fba6bee37d09e758217181317be6d8
  • google-site-verification=8NWg-rxdGZlat7VZhBnG1hf4efHaq8HIsuY08Ob81xY
  • MS=ms79809396
  • segment-site-verification=TQD1hAWtFtI9fn8GJS6eNL4e1veQbWCP
  • tinfoil-site-verification: 1847524321ba0eb9e79d58c237b47a9f64d6aeb8=0feaf53166bf2f72687887e66ed75150d0ba8971
  • google-site-verification=ZO19Wpi_jL4RXd09DQ4yJpAUUf5tAfaFQNU_Af_zIxg
  • status-page-domain-verification=74384sff723y
  • google-site-verification=R2uC2H2hp6tbHaut1GREX6T_a2iN7lyQXMXhY3Z5_Vk
  • google-site-verification=MRmPMFzdZqpyZ_YbWHxLjfWkPb0RZFSUMP56L3lYZgc
  • apple-domain-verification=MLPN3mwonJGSQuY3
  • atlassian-domain-verification=+FWFsYTEh4UAyTJqp6XDCVOPMkvHyGL8Z92KvgVuDginWzSuxaSc2onn8rdH90jo
  • google-site-verification=Wati1L8xiY-0pugIh-cQP_WmP1RmxrZhnX2_PfUIguU
  • cnyh1cg91yr09f04gvjhpz18wkpw69p1
Cloud / SaaS Services Detected
Adobe Apple Atlassian Mailchimp Microsoft 365 Zendesk Segment SendGrid DocuSign Zoom

Leak Screenshot:

Leak Screenshot