Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Sibanye-Stillwater

Group: ransomhouse

Discovered by ransomware.live: 2024-07-22

Estimated attack date: 2024-07-11

Country: ZA

Description:

Sibanye-Stillwater is one of the world’s largest primary producers of platinum, palladium, and rhodium and is a top tier gold producer. It also produces and refines iridium and ruthenium, nickel, chrome, copper and cobalt. The Group has recently begun to diversify its asset portfolio into battery metals mining and processing and increase its presence in the circular economy by growing its recycling and tailings reprocessing exposure globally.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 286

Third Party Employee Credentials: 26


External Attack Surface: 28



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse instra.com
  • info domain-contact.org
MX Records
  • za-smtp-inbound-1.mimecast.co.za.
  • za-smtp-inbound-2.mimecast.co.za.
TXT Records
  • globalsign-domain-verification=AF74D219BD461EA43BB21B8F4E336C2A
  • FbHqSGxQZF0LW35rf1iNUrRuCGhzH+CKFiQIGcwU/9e+qrCXYYBylEOlBrdhese3cUXjvmnZEXovrs0tBmjPFQ==
  • geZDlvbGqdn9a+zCLt9f2dv4A4YDwnsNMayWwxtU0Du7RxY8LRyO//N7QNTkfbRG3QWLJAhlSi+GAVJGf3w0Mg==
  • 14d19c4431519eeb2a377587154b674e62bdf8892c1919b4114c65272336020d
  • MS=D6068C054AAB88019C0CE5366F004F1996B7FA8D
  • v=spf1 a ip4:41.0.228.146 ip4:216.220.10.18 ip4:67.131.13.125 ip4:102.36.193.30 ip4:52.0.219.252 include:za._netblocks.mimecast.com include:us._netblocks.mimecast.com include:eu._netblocks.mimecast.com include:spf.protection.outlook.com include:_spf.psm.k" "nowbe4.com -all
  • amazonses:vIjy9TpD7BzedPWeERcdjSEH/AaGASXAzFo7A1jlP8s=
  • 7d4e49f52d4df991b1aec41c0c5e34b17cec0a25649106b8d39ccdc783b3855
  • globalsign-domain-verification=5680E333ED0989B5D5B838B55FBBFCAF
  • 24DKHP720kqGwyLVbLVHLGpmvp31bkkHnh0ROchQ3pz9hfVnovDwXyzDq98meoZ8s12nGpYLT0DI95pMeTMVug
  • 0ed1fe018a989b7dca6c5a46a09b3a21043f590c73
  • apple-domain-verification=MDKm4lOf5fSGrWbY
  • globalsign-domain-verification=8769E26B8BA38233106464AFD03747BA
  • 24DKHP720kqGwyLVbLVHLGpmvp31bkkHnh0ROchQ3pz9hfVnovDwXyzDq98meoZ8s12nGpYLT0DI95pMeTMVug==
  • 0ed1fe018a1c96add2c5ab43739a63d844e5d5ad0d
Cloud / SaaS Services Detected
Apple Amazon SES/WorkMail Mimecast

Leak Screenshot:

Leak Screenshot