Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo ROXU

Group: Spacebears

Discovered by ransomware.live: 2025-10-09

Estimated attack date: 2025-10-05

Country: ES

Description:

Grúas Roxu, established in 1978, is the parent company of the Roxu Group and currently made up by the following companies: ROXU, PLAAS, IGR, IDEA and DURRUTI cranes. Since it was established in 1978, Grúas Roxu has been growing to become the leading company in Asturias and one of the top lifting machinery rental companies in Spain. Grúas Roxu is a service company, its activity consisting in the rental of lifting machinery with an operator, focussing on advisory and rental services regarding self-propelled mobile cranes, mobile personnel lifting platforms, self-loading crane trucks, specialised transport, studies and planning of civil and public work assemblies, industrial assemblies, etc. Our objective is very clear: to keep growing in a constant and sustainable manner while continuing to be a national reference in our sectorThanks to Gesimde Asociados S.L, Ausil, Esnova. The leak was made possible by these companiesDatabasePersonal information of employees and clientsFinancial documents https://gruporoxu.com/en/


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 3

Third Party Employee Credentials: 0


External Attack Surface: 1



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse tecnocratica.net
  • abuse registrador.es
  • contact registrador.es
MX Records
  • _dc-mx.667bd70a51ca.gruporoxu.com.
TXT Records
  • v=spf1 include:_spf.google.com +include:spf.raiolanetworks.com +ip4:51.83.52.212 ~all
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.

Leak Screenshot:

Leak Screenshot