Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo LIFEFITNESS.COM

Group: Clop

Discovered by ransomware.live: 2025-11-21

Estimated attack date: 2025-11-21

Country: US

Description:

[AI generated] Life Fitness is a well-known, global company specializing in commercial-grade fitness equipment for both personal and communal use. Their product range includes treadmills, stationary bikes, stair climbers, and strength-training equipment. Known for their innovative designs, durability, and user-friendly interface, they cater to both fitness enthusiasts and professional athletes alike. They also offer fitness technology, training, and services.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 77

Third Party Employee Credentials: 21


External Attack Surface: 48


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse cscglobal.com
MX Records
  • lifefitness-com.mail.protection.outlook.com.
TXT Records
  • 00d3000000077wkeaq
  • google-site-verification=zB_vOivwb-pLxfiQUWCQj19xzMY4eRLG9Lmk7hgF0E0
  • shopify-verification-code=5qTb7TFdfa5v6oBMktUhtv2ISqyP9g
  • docusign=aef70d80-5879-4cb6-9572-b6e11f3868b4
  • google-site-verification=MuUFVTzXQbgbR7jR9Qv3rjkRUp6dnPBDN6mmf70qNUg
  • solarwinds-service0desk-verification=0cbe610ebf44cba10b725e8f8d60e1fc
  • pardot_65192_*=9ad85690e7efa228e74927dbef25deee7e65cc7da0fe5b848a97b1b89dfddae3
  • google-site-verification=RnesjmaBJ0BIqZ5N5AjR44jd6FO2l6ZaJXXwyzHsUCk
  • firebase=settopboxes-e91b8
  • klaviyo-site-verification=YkaAdx
  • google-site-verification=zhLfBtMt4IZWxjSiqJFKprIyCOeD1EwUuASnBWu9lWk
  • MS=ms61315734
  • klaviyo-site-verification=R5TgCu
  • v=spf1 ip4:69.42.126.188/32 ip4:23.100.234.234 ip4:62.138.219.8/32 ip4:67.231.149.64/32 ip4:3.22.230.72 ip4:54.251.43.237/32 ip4:134.119.253.26/32 ip4:178.18.90.94/32 ip4:180.87.182.8/32 ip4:23.253.142.38/32 include:spf.protection.outlook.com include:_spf" ".salesforce.com include:mail.zendesk.com include:aspmx.pardot.com include:lsw.solcon.nl a:mail.paymentworksuite.com include:_spf.linqhost.nl include:spf.mailjet.com ~all
Cloud / SaaS Services Detected
Microsoft 365 Zendesk Mailjet DocuSign

Leak Screenshot:

Leak Screenshot