Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Limocar by Transdev.ca

Group: Coinbasecartel

Discovered by ransomware.live: 2025-10-26

Estimated attack date: 2025-10-26

Country: CA

Description:

Limocar, operated by Transdev Canada, is an intercity bus service offering reliable and efficient transportation between Sherbrooke, Bromont, and M...


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 1

Third Party Employee Credentials: 0


External Attack Surface: 1


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • reg.ca-admin gandi.net
  • Please ask the Registrar of Record identified in this output for information on how to contact the Registrant, Admin, or Other contacts of the queried domain name
  • abuse support.gandi.net
  • licences transdev.ca
MX Records
  • limocar-ca.mail.protection.outlook.com.
TXT Records
  • d365mktkey=IgVr4lZKBvsMxz3CCiAKIe5xiWKmDlF6jUp7QVqEO2Ix
  • qlqoiq5ucg0eurnqk39f70ikl8
  • njurfk64soj8o0bssbme6md576
  • btjr9gujc2kdbssfi7ab9iam1u
  • lu4e9hc0p2etdmeev9nnv9fbs
  • v=spf1 +a +mx +a:limocar.webserversystems.com include:relay.mailchannels.net include:sendgrid.net include:spf.standish.ca -all
  • MS=ms80734816
  • google-site-verification=lErEKuvj_Q2Q7Wrok1EIjfCl9V2loyVisKwGFV7AcYo
  • d365mktkey=0NHPTHZ52TxUQK551ASJmx6r7xVgxVqql07fhxru42ox
Cloud / SaaS Services Detected
Microsoft 365 SendGrid

Leak Screenshot:

Leak Screenshot