Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo diethelmtravel

Group: Devman

Discovered by ransomware.live: 2025-12-07

Estimated attack date: 2025-12-07

Country: TH

Description:

[AI generated] Diethelm Travel Group is a leading travel company based in Asia, with over half a century of experience. It offers a comprehensive range of services including tailor-made trips, group tours, and MICE services. With 13 offices across Asia, Diethelm has a deep understanding of tourism in the region, providing expertly curated experiences for its clients. The company is recognized for its commitment to responsible tourism and exceptional customer service.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 9

Compromised Users: 8

Third Party Employee Credentials: 15


External Attack Surface: 10


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domainabuse cscglobal.com
MX Records
  • diethelmtravel-com.mail.protection.outlook.com.
  • trumpet.asianet.co.th.
  • mail.hk.diethelmtravel.com.
  • diethelmtravel.in.tmes-sg.trendmicro.com.
  • in.hes.trendmicro.com.
TXT Records
  • v=spf1 ip4:110.49.36.157 include:spf.tmes.trendmicro.com include:spf.hes.trendmicro.com in -all
  • XdipRMKP2jM1wb9EchSnHzFs7luixEpLIDY1OeBO0WWDvaVDrMqaddynohyI0CeR4CgWYdr13vyL0ublSHvAKA==
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.

Leak Screenshot:

Leak Screenshot