Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Mecanex USA

ruag.com

Group Akira
Discovered 2025-11-03
Est. attack date 2025-11-03
Country US
City Clearfield

Description:

Mecanex USA is a U.S. subsidiary of RUAG Aviation. RUAG Aviation is a leading supplier, support provider and integrator of systems and components for civil and military aviation worldwide. We will upload 24gb of corporate documents soon. Detailed employe e information (Social security number, passports, driver licenses , phones, addresses and so on), confidential military information , lots of contracts and agreements (including military), informat ion on how to work with explosive and so on, NDA, etc.

Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 18

Third Party Employee Credentials: 14


External Attack Surface: 13


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@united-domains.de
  • whois@united-domains.de
  • contact@wdp.services
MX Records
  • ruag-com.mail.protection.outlook.com.
TXT Records
  • j6hrdcjxbfl01432xp8xldypx7gjfh76
  • PofIGv8hqjzvkLbVb0PhzxTliksI5nO3/3ZwlWBmNGWlDAnYSCRLoiPN6JkRStJ5VW5gYrpSrM6WD/upoDePyg==
  • box-domain-verification=f429d565f2ff4c21c9b8e6912bc82af8a093583309aedd3e1e97529a3523c9a9
  • F54A1629-26F5-45A0-B2BF-3D08E193C32D
  • nitro-verification-code=LTQzNDgwNTk3NjczMTEzNDY4MDg=
  • Z3nRN1kmGJRMLeuiZSOlZMuJGmET21ZOYbwJ6K1zKl+sfXErOmZ1X/gVA0AuD8dQ51BD5mPaBe48ohNPVudwwA==
  • _3y9lhqkmv8nezb3vg7qv2swa22t5d56
  • 2xf3bwvp1rsjx9rlqb2r8bt4bp3jpp8j
  • v=spf1 ip4:91.223.121.6 ip4:91.223.121.28 ip4:91.223.121.170 ip4:62.154.222.200 include:spf.protection.outlook.com include:_spf.jpberlin.de -all
  • MS=ms34305627
Cloud / SaaS Services Detected
Microsoft 365 Box