Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

doosan.com

doosan.com

Group Settra
Discovered 2026-06-28 19:53 UTC
Est. attack date 2026-06-08
Country KR

Description:

How Doosan / Geith / Bobcat Buries Defects and Protects Its Secrets PROLOGUE: 3.27 TERABYTES OF FILE...

Infostealer activity detected by HudsonRock

Compromised Employees: 113

Compromised Users: 604

Third Party Employee Credentials: 114


External Attack Surface: 159


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusewhois.co.kr
  • dsdomaindoosan.com
MX Records
  • xmd8.silverpop.eb2b.vtrnz.com.
  • xmd9.csg.eb2b.vtrnz.com.
  • mx2.hc644-4.ap.iphmx.com. Cisco/IronPort
  • mx1.hc644-4.ap.iphmx.com. Cisco/IronPort
  • reply.csg.eb2b.vtrnz.com.
TXT Records
  • globalsign-domain-verification=tXqWBa4tg8CamC4B0uz7Tpp5hcrOCpzpz5Rv6wjiPx
  • teamviewer-sso-verification=54cb281da171442ba0e042da79f75c05
  • apple-domain-verification=dZzfBHd2ZF0T5pus
  • anthropic-domain-verification-z23v2d=OLWZCMzPzqZcSs2pjLFdr5dXr
  • aWZo+NKm078dpQxJ62LdcAH6lh1maaIDdmNOjs9NU2XMJaGkp82PKRh8+q4C1tI2qmbqB2dhl5qDKb0DE6umuw==
  • amazonses:0OhF/z8eMStZw8Z28j7+Jmz+ZbwFCeLoY6C7zvGX/fo=
  • upjtuvcfa2tskpcniu86mavqir
  • oj2lau6g00ldbv84m13pqepbn
  • mindmanager-verification=fcdfdb17beb023d3d99fa0466139d7471fb0446b2bc237676f131e85f2edaf79
  • 6okqn2loasnaf3qhkdjsiolhb0
  • autodesk-domain-verification=uEuRBNlqHQ_cnEjsBOMc
  • 2m2H+yF1xFam5ghNbjlZAqAhOsPYMXBFkpslP5Pi18gEVv9/IWXbYcd6TzXu6GO48FM9C840TVfrV9YOA8BC4w==
  • onetrust-domain-verification=15323edd476e4656a5ee386290270564
  • turingsign=10B9CD46-0CEF-7AC3-B8F6-0A98DFC707D0
  • MS=ms55178697
  • _github-challenge-DoosanICA.doosan.com.=24ceeba5fa
  • MS=ms37971220
  • turingsign=6a169442531d474e93e243ac3dfe93b6
  • 0+mEFnwa6eIRRI2T6wu5wobV5FmBCyLkzw4q1VRw5VmtqHThSPv96n98K4dOTgN5FNqRx9sAmhcDiWA8WPWZSA==
  • TNTbyFeWM6Q9C0dVSW5wgHsDzjK+ELFsV20mEFZd0X4IIqZS8SCpfo2wHdMEhF8xXPyDIoiX7I2a6aePaDz4Kg==
  • docusign=8fc02c2d-a31b-4573-9bf0-622230846051
  • sending_domain1034153=9de1cac75f0aeeaaeaa4bbc22af229cb5ffca7b78aa7d7ee28da4616a151c75e
  • e4kk77p0ll20ja4nf3mto953al
  • MS=ms55503121
  • klaviyo-site-verification=StSYCm
  • klaviyo-site-verification=X8s6bz
  • sending_domain796563=44b21263b8febb2865f22870dfb8771749a5e4b5feef265ae77bf2078a4e4a6d
  • QZyHFxLcEc0XRKrpVgUjx7sY8LYxMnNSjxLBSniWNE1DFjUukBoj9tb/hgz5iRs7gq9eOj7/Zo3+0XGoIq0FZA==
  • 5nfpjce58a0516spcpjjl03hcg
  • atlassian-domain-verification=MyttQhK0QLkok4i1csV5CsPkwW7KA5H7/4swmSmnJPndAISx9PFsJehj4GTroym3
  • hcp-domain-verification=a7b112596937c0a40c635108f19490fb9cbf620ebd5b791e297fc8207659c834
  • toast-domain-verification=jCmTujZ7YkRyMtpx8oIo
  • openai-domain-verification=dv-hy8ccoT6VZ64RzRbptew6IbE
  • turingsign=E960DF7E-9772-8EDA-43DE-EC9982842795
  • google-site-verification=D8Siu6Gs2Djz7Vx_EgnzXAkKoiI68wIj9quuRXnLa5E
  • perplexity-ai-domain-verification-3nn7a5=6pW5VLb3QAzN0SW0aiUbgE4YX
  • cc4a1807-93ae-43ca-9f3e-306c14ac63a0
  • atlassian-domain-verification=kvvjbcRR0w8oCrnW1vwcu1y1pd2gWp5z4BI8sNVpz6BGbkVwfx0Ef2Bye5KPD2xR
  • atlassian-domain-verification=O87nwHhpHE1eRZwQZlRCBvx9oRA2eXOTTZrMqtQaXHekfGaaCnsKC55kCmf8qdyS
  • cknjg72r5mgj5phgjiif5mkg3i
  • sending_domain1106913=d31aad114289d9e9b63f54db6c9794442d698cf061765f6d4a46ece4f87037a5
  • 8WxhADMMAEcMXgkk8ruTcGInly8XKALmMIoF8zRYfZco+e4ZS5SPkeUMvIDow95lHCN/d3ds2AQbPz+JQx0BEw==
  • v=spf1 include:amazonses.com include:spf.protection.outlook.com include:cust-spf.exacttarget.com include:spf1.doosan.com include:ab.sendgrid.net " "include:spf2.doosan.com include:_spf-dc4.sapsf.com include:_spf.salesforce.com include:_spfblocka.toast.com -all
  • autodesk-domain-verification=FEQGS-i44MeeZWul60BF
  • c5dd4f20-b12c-4887-a276-39d2e9bb3b9f
  • 7na6vno6mm3sgi6napagf0kknn
  • sending_domain1093142=9580595d087d74f126a2ff964f5625f2c2ed22c4311b50ac4b45ddb1726e8fcc
  • atlassian-domain-verification=8WSnhS5r3BrI1ZyjGVFdcvwAOLhWAoY/EHu546D4UXemPvfzvcokWr+XHwMTGhiq
Cloud / SaaS Services Detected
Apple Atlassian Amazon SES/WorkMail Microsoft 365 Salesforce Anthropic OpenIA Teamviewer Autodesk SendGrid OneTrust DocuSign

Leak Screenshot:

Leak Screenshot