Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo University of Mannheim

Group: Qilin

Discovered by ransomware.live: 2026-02-18

Estimated attack date: 2026-02-18

Country: DE

Description:

N/A


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 50

Compromised Users: 975

Third Party Employee Credentials: 11


External Attack Surface: 111


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • proxmox-mg2.uni-mannheim.de.
  • proxmox-mg1.uni-mannheim.de.
  • proxmox-mg3.uni-mannheim.de.
TXT Records
  • apple-domain-verification=TCoQCRktvOKuEsGj
  • HARICA-nBDdn0MBll71F7zPVbe
  • google-site-verification=hjNaUkKKXqMgskqCvXiQZ6z3FgiqD_b_3WcMZ9Jnqqc
  • docusign=a54ceab8-efac-4862-956d-974be66efdb2
  • MS=5C940BB0AE08C25C9B2005790594703D3E6738F2
  • adobe-idp-site-verification=726793ff3dea185510f9ff9c8cc374adaf6ec9a8fe5bca96496d01f5eec78361
  • l05J1b8RCmWUIdiEdf8lsFXTgnK+JJyO7ChJhkDa5mRCU29BYHM0x42eEkdfBdlVPKH25Ec970n0MuTUu73e7w==
  • v=spf1 mx a:smtp.mail.uni-mannheim.de a:sapmail.bwhsrw.de include:spf.protection.outlook.com -all
Cloud / SaaS Services Detected
Adobe Apple DocuSign

Leak Screenshot:

Leak Screenshot