Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Shtainmetz Aminoach

Group: Thegentlemen

Discovered by ransomware.live: 2026-01-20

Estimated attack date: 2026-01-20

Country: IL

Description:

www.cpa.co.il https://www.zoominfo.com/c/shtainmetz-aminoach--co/447493108 Shtainmetz Aminoach is a leading accounting firm in Israel with 38 years of experience, located in Tel Aviv, and recognized among the top firms in the country. The firm specializes in a wide range of accounting services, including tax planning, international taxation, and financial consulting, catering to large and sophisticated corporations. With a team of experts, including former tax authority officials, they provide tailored solutions for various sectors such as high-tech, real estate, and e-commerce. Additionally, they are part of the global UHY network, enhancing their international service capabilities.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 7

Third Party Employee Credentials: 1


External Attack Surface: 1


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domains@y-tech.net
  • eli@cpa1.co.il
MX Records
  • cpa-co-il.mail.protection.outlook.com.
TXT Records
  • 530m28ubrp02d9ogr1oj2d04te
  • v=spf1 mx ip4:82.166.81.109 ip4:81.218.83.97 ip4:77.137.9.186 ip4:212.150.192.249 include:spf.protection.outlook.com include:xb.u-btech.com include:outbox.co.il include:emailv.com include:outbound.smtp.wisestamp.net ~all
  • 2+e67xctnGn/XZBhk2jpiKpA2xevmr465rQ5CkfC0Cu/9Wc4O6KnUUVwbrjnofOLzi8x7/rU9URoGhWsZtcD1w==
  • ms=ms86912220
  • r80tk83tioei9hs1fkfsgaf6i9
  • 5guov9hdl26dh3osb2iihkbon9
  • google-site-verification=mm4ltEaaMtYALz-M7np4BQmOsi5W1Z40MzmvD5bJdCI
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot