Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo NPIAV

Group: qilin

Discovered by ransomware.live: 2025-09-03

Estimated attack date: 2025-09-03

Description:

NPi Audio Visual Solutions, USA - the company organizes and hosts business events and parties. What happens behind closed doors at private conventions? Now we can peek behind the curtain and find out what the rich and famous really discuss an ...


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 1

Third Party Employee Credentials: 2


External Attack Surface: 1


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • d301411a.ess.barracudanetworks.com.
  • d301411b.ess.barracudanetworks.com.
  • npiav-com.mail.protection.outlook.com.
TXT Records
  • iiqukhl2n5jefks9vij9vccgvh
  • apple-domain-verification=qa19E9a22EFkl8rY
  • v=spf1 include:spf.protection.outlook.com -all
Cloud / SaaS Services Detected
Apple

Leak Screenshot:

Leak Screenshot