Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo keliweb

Group: Vect

Discovered by ransomware.live: 2026-02-28

Estimated attack date: 2026-02-28

Country: IT

Description:

Status: STATUS: NEGOTIATING | Sector: IT | DATA SIZE: 200GB | Deadline: 28d 7h


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 121

Compromised Users: 856

Third Party Employee Credentials: 1


External Attack Surface: 45


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • mx.spamfilter.io.
TXT Records
  • google-site-verification=k75CdSP9mIKZ9TFvFinKAehvR2o9KOSwgVHf0kB016I
  • google-site-verification=U7DaVh9jhHrw2PlUuoqJfZwQhBmq9i7v3tUJT0hqWws
  • google-site-verification=bFKn4djz4iag2Ko5zhmiTl86hy4judTIDwwJe3LFKsc
  • v=spf1 ip4:185.17.106.230 ip4:185.17.106.200 ip4:65.108.68.208 ip4:159.69.247.199 ip4:212.123.41.224/28 ip4:185.26.229.213 ip4:46.21.184.197 ip4:194.69.192.5 ip4:185.17.107.253 include:_spf.topdns.com include:musvc.com include:_spf.emfwd.name-services.c" "om include:spf.protection.outlook.com include:spf.spamfilter.io include:send.register.it -all
  • 1password-site-verification=KL5TIK5NBNHF5G2OXKM6GRVV7Q
  • MS=ms60433252
  • facebook-domain-verification=pyslnt78kzyzpyw3qkz84sv5idtdtx
  • MS=ms42767776
Cloud / SaaS Services Detected
Microsoft 365