Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo University of Gävle

Group: Nova

Discovered by ransomware.live: 2025-11-15

Estimated attack date: 2025-11-15

Country: SE

Description:

University of Gävle is a university college located in Gävle, Sweden. The university was established in 1977 and is currently organized into three academies and nine departments. The university offers around 45 masters- and bachelor's degrees and 800 courses in technology, social- and natural sciences and the humanities. ZoomInfo: https://www.zoominfo.com/c/ga%CC%88vle/1142576926 / Domain: https://www.hig.se/


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 46

Compromised Users: 67

Third Party Employee Credentials: 10


External Attack Surface: 102


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • hig-se.mail.protection.outlook.com.
TXT Records
  • apple-domain-verification=1gAtibXsW8y2wPCw
  • mentimeter-dee486c0-6303-4858-9543-95273ebf984f
  • adobe-idp-site-verification=41aebecb5d0ec9b76a56c7ae992b65ee640be4a911c9ef56389d02deec09d5f3
  • v=spf1 ip4:130.243.0.136 ip4:130.239.8.142 ip4:212.85.68.72 ip4:213.157.70.68 ip4:213.157.70.73 include:all._spf.plma.se include:spf.protection.outlook.com ~all
  • ZOOM_verify__rPqfZucQbiR_hNWe8_fqw
  • jamf-site-verification=dZXK8tg_uv06OyWPV-Gxcw
  • MS=ms14926464
  • google-site-verification=OmKYq6Lri6qYe0m3xT_riDpKzhA0I615ZfgVLYeBB-M
  • 9c35cb0b410945ed8398831e82475a5d
Cloud / SaaS Services Detected
Adobe Apple Microsoft 365 JamF Zoom

Leak Screenshot:

Leak Screenshot