Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Eumetsat

Group: fog

Discovered by ransomware.live: 2025-03-06

Estimated attack date: 2025-03-05

Country: DE

Data exfiltrated: 291 GB

Description:

Extract from The 19 biggest gitlabs


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 817

Third Party Employee Credentials: 0


External Attack Surface: 50


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • noc eumetsat.int
MX Records
  • eumetsat-int.mail.protection.outlook.com.
TXT Records
  • google-site-verification=UTaPJOjaBpMUQcmyJDBncpmhjH_rK346IMY1oi8avII
  • v=spf1 include:spf.eumetsat.int include:spf.messagelabs.com include:_spf.mailspamprotection.com include:spf.protection.outlook.com a:mrelay.osn.de -all
  • apple-domain-verification=ELgIUpogxnaqnepf
  • google-site-verification=PL_3HqeYWshJDYt4rmwSUsRzkzT8i2qI8dKbs1dWcHw
  • _e8l1b86i6rwy2skfmpvzqyali57o8sk
  • teamviewer-sso-verification=224176aab4b94338a0c80109563f962b
  • facebook-domain-verification=ni3vwh8ros543uwwwv5gp4l2vjgr2u
  • qsg7gx1bxppzcxl6b6syyk0t5yj2b4fl
  • atlassian-domain-verification=187mhGMzXksEJ0hn4MVpazR3bdTtYXEfduIULNBY29OXJansaUUVhZoWB/vRvLUb
  • cisco-ci-domain-verification=84f7a00181754711b6536782b7c886ff1dff251e253d21e4280400605eb8409
  • MS=F85ABED9E88BEE4EFDBCD0116F847CF5FF653885
Cloud / SaaS Services Detected
Apple Atlassian Teamviewer Cisco

Leak Screenshot:

Leak Screenshot