Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo XOX Mobile

Group: Qilin

Discovered by ransomware.live: 2025-11-21

Estimated attack date: 2025-11-21

Country: MY

Description:

N/A


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 3

Compromised Users: 3395

Third Party Employee Credentials: 4


External Attack Surface: 101


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • cs ipserverone.com
MX Records
  • xox-com-my.mail.protection.outlook.com.
TXT Records
  • v=spf1 mx ip4:219.92.30.57 include:spf.protection.outlook.com include:spf_c.oraclecloud.com -all
  • facebook-domain-verification=q7ujep4u6531m3k79332ao7y4kb6og
  • cisco-ci-domain-verification=451f934c7982d08da7bb31263bd121eca8faf77f89463e0a500f9791a59ba947
  • google-site-verification=lgHBGGwi9mCjyQCYZ67OrPwzSbsYlnsZMDbVKlVHZq8
  • MS=ms61169134
Cloud / SaaS Services Detected
Microsoft 365 Oracle Cloud Cisco

Leak Screenshot:

Leak Screenshot