Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo ccbrt.org

Group: Benzona

Discovered by ransomware.live: 2026-01-17

Estimated attack date: 2026-01-17

Country: TZ

Data exfiltrated: 1.8TB

Ransom: $500.000

Description:

[AI generated] Comprehensive Community Based Rehabilitation in Tanzania (CCBRT) is a healthcare organization that operates primarily in Tanzania. The organization aims to provide affordable, high-quality healthcare services to the local community, particularly those with disabilities. It focuses on areas like disability hospital services, rehabilitation, eye health, maternal and newborn healthcare. CCBRT is also known for its training and capacity building activities.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 1

Third Party Employee Credentials: 2


External Attack Surface: 2


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@namecheap.com
MX Records
  • aspmx2.googlemail.com.
  • aspmx.l.google.com.
  • alt1.aspmx.l.google.com.
  • alt2.aspmx.l.google.com.
  • aspmx3.googlemail.com.
TXT Records
  • v=spf1 ip4:41.220.128.10 include:habari.co.tz include:_spf.google.com ~all
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.