Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

gov.krd

gov.krd

Group: Lockbit5

Discovered by ransomware.live: 2026-03-30

Estimated attack date: 2026-03-18

Country: IQ

Description:

The Ministry of Higher Education and Scientific Research oversees higher education institutions in t...

Infostealer activity detected by HudsonRock

Compromised Employees: 15

Compromised Users: 1625

Third Party Employee Credentials: 71


External Attack Surface: 105


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • aspmx.l.google.com.
  • alt1.aspmx.l.google.com.
  • alt2.aspmx.l.google.com.
  • aspmx2.googlemail.com.
  • aspmx3.googlemail.com.
TXT Records
  • MS=80DF31A262DAB32470C0CF4124521B338E699372
  • globalsign-domain-verification=wbdypNBPRxDA7pbVKik0tD-_SeH22sESkMRd2bCTOm
  • google-site-verification=Mn06nqFdghXDTSv4BmRaTo76P_l3fCzCuMb0q12qccA
  • google-site-verification=Id2c7TtI77DQsPoE0_k3qfzOwtrJDN9XXY6NqqB_bm8
  • globalsign-domain-verification=5A134FDB5EA8F434CF2367325E6ABE85
  • globalsign-domain-verification=8a5a5e13bd8ca52f81a6522a0ce9804c
  • globalsign-domain-verification=D101C89D64D6586C221B71FC3221F438
  • cisco-ci-domain-verification=1aa4a951a6ff654a4f66c6a09815a55c8d45d14e484429f07035a7b0ad4d77b4
  • MS=3D39FA588C39DA64F80922586C428859B945992F
  • v=spf1 include:_spf.google.com ~all
  • _globalsign-domain-verification=2ZFiOMpMOqj4jXC1-ujMq0kCVfszeEwvBqVQJkgsDh
  • google-site-verification=RR4xq1Y2IxBQvaHZ0C5j7qDOMhk0NALbFBiGFbeob_I
  • google-site-verification=83yOf3jpexbZMeDuGpGxs37oeM_5NKFbafRI0e0zUBk
  • globalsign-domain-verification=8F71C2F776BD01573FE34D584B1BA372
  • slack-domain-verification=9fhQyEqPZGjiOvlN0Eyctha6hQzLiTvdZShlMVvP
  • globalsign-domain-verification=5932CB5FDC92BBD067875E1834325369
  • globalsign-domain-verification=faf9c9cf1f42e593ed82bd8a287b643a
Cloud / SaaS Services Detected
Slack Cisco

Leak Screenshot:

Leak Screenshot