Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

HYPERTHERM.COM

HYPERTHERM.COM

Group Clop
Discovered 2025-11-21 17:37 UTC
Est. attack date 2025-11-21
Country US

Description:

[AI generated] Hypertherm is a global organization based in New Hampshire, USA. Founded in 1968, the company specializes in the design and manufacture of advanced cutting systems such as plasma, laser, and waterjet cutting solutions. Hypertherm products are employed in sectors like construction, shipbuilding, and manufacturing. They provide software, controls, and consumables for cutting applications. The company is also known for its employee ownership model.

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 342

Third Party Employee Credentials: 2


External Attack Surface: 81


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaintsmarkmonitor.com
  • whoisrequestmarkmonitor.com
MX Records
  • hypertherm-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • 3b8cf9ad2376d9b8a95c73a989d4b3263167bba6
  • sending_domain298082=6215419e02b6ad674550d6858374fa7ee9be098224c16392778eba18a8d4fb09
  • d365mktkey=NwvlxCwJWEl39ZwwOxfRkeOBCzg2tVI1NTOTZFwQG8Ax
  • apple-domain-verification=oe3ykvFQM34GQ9M9
  • intersight=19874c999cf9b37ec1344ee7e7eaad1c6ddc97e30d04a712ef4b612d5319549c
  • v=spf1 a mx include:spf.exclaimer.net ip4:72.236.28.8 ip4:72.73.127.3 include:spf.protection.outlook.com include:sendgrid.net -all
  • citrix-verification-code=7f08171a-32c0-460a-8978-a7b0ae0d0886
  • unity-sso-verification=806c0bad-018c-4c01-ba15-b80866649b94
  • google-site-verification=iIvKHOub-MV_L0F00PT5DvUHFgWTztCfERmAcjk8mPs
  • zapier-domain-verification-challenge=0408651c-81f4-44f7-8a85-3caaec664edd
  • ms-domain-verification=f133d354-f249-4cd0-a673-5699c1faa74f
  • 0Z9ow3XUvVrZtlUkbdwJ9CnR05KaJHBjb0Uh77S4jDBXKEGbRz47s2M7WCxcDUNRAbl+YC7UXzJVxP8EkZ9TZg==
  • d365mktkey=obUZvf6GTG8Tf4R16z0dV7opX1opuMrl6zXhtyWGKgIx
  • MS=ms17587318
  • bKB9sJ2viNh1O2PE0/52LavrM2bVTfdsK0QF9wpQwd5fRmL7E6NP002WDoKOqI+oDLy103G8u2nemp8sA5sF3A==
  • google-site-verification=d2VYWyl0O3UAcvYYp9X1sXjyTxNhVqAE7C33T2iB6OM
  • docker-verification=81c42ee8-fec2-4d18-bd31-ee9a38b3ce7d
  • Oz8dldCs5WpdgtwY9W+8osSt4TvzNU8EAPflYpT7xp7esNk8ToXrQWzhJi1znNZDZVMCs1CS7NP1GbpXw3Sihw==
  • docusign=2d324e9b-6d4c-464d-a8ae-7f482149d279
  • atlassian-domain-verification=xxqQZdLaPY6LjOCJCeesc0DBhv0OjdtylsrQyYgGbzBLZ03RaJR8WTA2MrDN+Z0B
  • asv=dfd4bdc7f7c440aecf9da05378cd7b51
  • d365mktkey=cisHStQJ10hlwkGxHCgAzlgXrJzNkU5yCMG0H7nBNlQx
  • onetrust-domain-verification=ab032896f2c34288ae2cd463bed05d35
Cloud / SaaS Services Detected
Apple Atlassian Docker Microsoft 365 SendGrid OneTrust DocuSign

Leak Screenshot:

Leak Screenshot