Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo RFSUNY.ORG

Group: Clop

Discovered by ransomware.live: 2025-11-21

Estimated attack date: 2025-11-21

Country: US

Description:

[AI generated] "RFSUNY.ORG" refers to The Research Foundation for The State University of New York, a private, nonprofit educational organization that administers sponsored programs for SUNY. Founded in 1951, they offer flexibility and adaptability to the funding, research, and business needs of SUNY faculty and students by assisting in areas such as talent management, grant application, project administration, innovation and partnerships.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 15

Third Party Employee Credentials: 1


External Attack Surface: 16


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • rfsuny-org.mail.protection.outlook.com.
TXT Records
  • v=spf1 mx a ip4:141.254.11.0/24 ip4:74.217.49.0/25 ip4:74.202.83.0/24 ip4:69.25.227.128/25 Ip4:40.76.221.254 ip4:52.0.84.155" " ip4:70.42.26.104/29 ip4:70.42.29.32/27 ip4:150.136.17.102 include:rp.oracleemaildelivery.com include:spf_a.oracle.com include:spf_c.oracle.com include:spf.protection.outlook.com include:servers.mcsv.net include:huronclick.com ~all
  • MS=ms49024339
  • 08D6nwD8p3qG/8GUhORniUbNV+ckia9SlVpQ+xeimq3+mJ95b9Xrbzod3Du0bCfUDFblh1J6DmUJ+VdnWjMvVw==
  • docusign=41d5b2f1-9dcd-4c5f-8460-3b43a8e2115b
  • 7e6bc1f5-61e7-4c0c-839b-0ca72c04a7ae
Cloud / SaaS Services Detected
Mailchimp Microsoft 365 DocuSign

Leak Screenshot:

Leak Screenshot