Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2026-06-16 04:26 UTC
Est. attack date 2026-06-01
Country CN

Description:

ECOVACS is a highly successful Chinese robotics company founded in 1998 in Suzhou. It has grown into a global leader in smart home cleaning solutions, with its products sold in over 145 countries and trusted by tens of millions of users worldwide.The company is best known for its award-winning DEEBOT robot vacuums, WINBOT window cleaners, GOAT robotic lawn mowers, and other intelligent cleaning devices powered by advanced AI and navigation technologies.Driven by the vision “Robotics for All”, ECOVACS continues to innovate and expand rapidly, making premium home robotics accessible and effective for everyday consumers.About 2 TB of stolen data. https://www.***.com/

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 1062

Third Party Employee Credentials: 4


External Attack Surface: 100


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • DomainAbuseservice.aliyun.com
MX Records
  • cnc.biz-email.net.
  • mail.biz-email.net.
  • cdn.corp-email.cn.
  • cdn.corpemail.net.
TXT Records
  • GhIbC0DIP6CXXBLwVhLAmYGstdSV96bitNYPmdhBZuFWU2zHIwXdbA0iR2v7vzIUKGbuL3CetxiYgk97oSJd3A==
  • verification-code-site-App_feishu=U970FLj8UiWgjglCryTp
  • MS=ms45211187
  • stripe-verification=dc0070119943333f9f4007eec2ef3fa7bd1a4b93aae2b7e3ba7a3cde22b60611
  • successfactors-site-verification=NjY4Y2I3Zjg2NDk4NWYwMGQ2MzgxODkzNWU1NGZhMmYwYmIxYzNhOGNiZjZmYTBmMDQyOWFiNDMxNjNiNWY3Zg==
  • klaviyo-site-verification=Y2CCDw
  • v=spf1 include:_s.corp-email.com include:spf.protection.outlook.com include:_spf1.ecovacs.com include:mail.zendesk.com include:amazonses.com include:_spf.salesforce.com -all
Cloud / SaaS Services Detected
Amazon SES/WorkMail Microsoft 365 Salesforce Stripe Zendesk

Leak Screenshot:

Leak Screenshot