Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo ki.se

Group: Trisec

Discovered by ransomware.live: 2024-02-19

Estimated attack date: 2024-02-19

Country: SE


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 5

Compromised Users: 102

Third Party Employee Credentials: 15


External Attack Surface: 73



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • ki-se.mail.protection.outlook.com.
TXT Records
  • d365mktkey=OLENvjgB6lRUO9ZN2zHWsx2Mo741W0BCCo7i6fhiZesx
  • apple-domain-verification=ypyg2Jun8VDasTx6
  • SITHSvalidation_2025-09-22
  • MS=E939D92A52B20225345A44C2EAB76DBB8B4C957E
  • h28dtj3uyO66Imn7T5Jer9h5ZZjrDeB/IX6pfskcjlbs9khsGcBdCBRedBH4bqVQlATXNTsC2+bu0ciQSMghAQ==
  • ipLe2RXybLVX0k1pgECUYrqltVFAhXAHA8RvD15PPFTKwzvn9seMVG1W8Pw8zo1PR2qFLxcBfKToVz7aYQyJjw==
  • HARICA-BNzIpHuZb4fHrhDL5we
  • facebook-domain-verification=unvisrjjgpehgtb4kdhhh03k6vxcyp
  • v=spf1 include:_spf.ki.se include:spf.protection.outlook.com include:all._spf.plma.se include:_spf.nanolearning.com include:spf-eu.exlibrisgroup.com include:_spf.tem.scaleway.com ip4:82.196.180.210 ip4:205.201.136.26 ip4:130.239.8.142 " "ip4:130.239.8.162 ip4:78.47.65.45 ip4:193.75.92.158 ip4:54.72.160.116 ip4:54.76.9.230 ip4:54.77.64.171 ip4:212.247.0.192/26 ip4:130.235.56.199 ip4:130.235.56.200 ip4:130.235.56.201 ip4:130.235.56.202 ip4:94.140.53.162 -all
  • atlassian-domain-verification=VRUjln7jv2GQqNSjlsiOaXHKsHptSPkw4cAUJ6/DITYSttG5F5E/Rs6rOmMOJzPa
  • jamf-site-verification=yKe3ekVoO3CXw9r8SiDOfg
  • SITHSvalidation_2025-01-14
  • google-site-verification=IUyKr3qvycjFZKjstMTyFQMhq4FzjxtNWk6UtaRGlOw
Cloud / SaaS Services Detected
Apple Atlassian JamF

Leak Screenshot:

Leak Screenshot