Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Northern Air Systems(2)

northernairsystems.com

Group Akira
Discovered 2025-12-11 15:08 UTC
Est. attack date 2025-12-11
Country US
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

Northern Air Systems has been a leading manufacturer of high-qual ity HVAC systems for commercial and industrial applications for n early three decades. As you could have noticed, we've made it 2nd time to penetrate to their systems and locked almost 90 vms. At this time we've taken five times more data (150gb) and we will upload the files soon. Detailed employee information (i-9 forms, passports, DLs, medical information, pictures and so on), client data (DLs, addresses, e mails), detailed financials, lots of projects information, contra cts and agreements, numerous NDAs, etc.

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • northernairsystems-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • v=spf1 include:spf.protection.outlook.com -all
  • apple-domain-verification=fq_v3lD1UrDf66yI-rd4fk5Fp9-1xnhbrR-Yzv60aB8
  • apple-domain-verification=iioalVUI4dlokLbS
Cloud / SaaS Services Detected
Apple