Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

LOGITECH.COM

LOGITECH.COM

Group Clop
Discovered 2025-11-07
Est. attack date 2025-11-07
Country CH
City Ecublens

Description:

[AI generated] Logitech.com is the official website of Logitech International S.A., a Swiss-American multinational company specializing in computer peripherals and software. Logitech products include keyboards, mice, tablet accessories, webcams, home and PC speakers, headphones, and audio devices. Their items are notable for being innovative, quality made, user-friendly and diverse to cater to a range of customer needs.

Infostealer activity detected by HudsonRock

Compromised Employees: 18

Compromised Users: 33344

Third Party Employee Credentials: 21


External Attack Surface: 122


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaints@markmonitor.com
  • whoisrequest@markmonitor.com
MX Records
  • alt1.aspmx.l.google.com.
  • alt2.aspmx.l.google.com.
  • alt3.aspmx.l.google.com.
  • alt4.aspmx.l.google.com.
  • aspmx.l.google.com.
TXT Records
  • sprout-social-3af93c8b-606d-41aa-a406-d74ebbf4c3ff
  • apple-domain-verification=BuvO0D6Izr6qJcTM
  • google-site-verification=wtV3OTVkOcuXsBS2wGLY8ekHymEOksO7qzdC3gXTYtk
  • google-site-verification=C5XQw2J5KPbtStmuVWstr65RWM1OnK751en7znFVvak
  • remarkable-domain-verification=30f96462-62fe-44b7-aa0a-dd41af3b77f6
  • 202005060528120ciittu4sdds51am4jnq46267nmi2oyw7ex4x4w7vrew8fh85q
  • brevo-code:dda1db42545471cfb42a4d7b2ed6c30b
  • dropbox-domain-verification=hwq2jcdw8x2e
  • google-site-verification=eXTK4DovSV0z4ULDUjz2TpIq8gZoHQKAmT112cZ2EF4
  • oci-domain-verification=Yg3RbVPioRySsZuLC4koP8tpqyWjJ5zrtD1khwtEk18P
  • freepik-domain-verification=c76f2839abb8e911db2678c9ab93040c
  • stripe-verification=2276BA764BE86CDB1EDE8F56CBBE2BF28150FB9A98D81D9F07F910C0C21CD100
  • google-site-verification=srgm_qMCEej-2s9Vm0kEOOn23zmCBzVFZraEioHFH7o
  • 1552c83d-2998-4bf8-8fec-13635be21315
  • docusign=a0981d32-ab93-4aea-bd63-074847b35ea7
  • zoom-domain-verification = 40e7be74-ee0b-11ef-9cd2-0242ac120002
  • smartsheet-site-validation=00gHp-KILzZzgbig_6bdpe_TBfOfygnh
  • google-site-verification=hhpr2B48nkynz2xIR-aYsKVEopC1CXw4yejOFui4XzE
  • brevo-code:c7b027c990a74ce5f3f8cbd0aae35ba3
  • facebook-domain-verification=5o5zu88bmhoeu6at7zi31cpa6v2ohi
  • atlassian-domain-verification=WRDFg7vQ8oBuXO0arjtTP2c1eiMt1rl5xX9aqo9/OiqRWjkJxakFVkC3iA7nHpoN
  • atlassian-sending-domain-verification=6f94443d-7e50-4c0d-aa98-18883c1f313c
  • teamviewer-sso-verification=4733c993b0774f4e88e1f80fd0e428ce
  • MS=ms37624107
  • v=spf1 include:_spf.google.com include:everbridge.net include:mail.zendesk.com include:direct2u.spf.dt.com include:spfa.cpmails.com" " ip4:63.150.149.5 ip4:63.150.149.6 ip4:74.118.162.35 ip4:74.118.162.36 ip4:213.165.74.136 ip4:207.211.31.67" " ip4:13.110.146.172 ip4:205.139.110.47 ip4:204.77.217.54 ip4:107.23.26.71 ip4:107.23.32.213 ip4:82.195.249.26 ip4:54.251.169.91 ip4:204.77.217.50 ip6:2406:da18:8c8:4e00:c141:5599:cb4:8bd0 ip4:188.40.2.7 ip4:152.160.0.0/16" " ip4:37.98.235.2 ip4:199.15.215.48 ip4:54.236.103.127 ip4:208.66.205.16/28 -all
  • twilio-domain-verification=c324106a4d1b8ca11317499ed11d8181
  • MS=ms60342773
  • brevo-code:af8945295ad143532a77017f0e34ec18
  • onetrust-domain-verification=2556a4aae1804ed8aa24408789189ac2
  • atlassian-domain-verification=36rMD0Lad14LyDJ1h86m3vvz70IoE4NlGBQIVNpcq50nPhabI3wJ0RYiSx8Lh5gb
Cloud / SaaS Services Detected
Apple Atlassian Dropbox Microsoft 365 Stripe Box Teamviewer Zendesk Twilio OneTrust DocuSign

Leak Screenshot:

Leak Screenshot