Group:
Ransomhub
Discovered by ransomware.live: 2025-01-22
Estimated attack date:
2025-01-22
Country:
Description:
[AI generated] Ilem Group is a technology company specializing in providing IT solutions. The main areas covered by the company are IT system integration, software development, data management, cloud services & cybersecurity. Based in Switzerland and Morocco, they help businesses improve by implementing innovative technological strategies. The company also offers digital transformation and tech consultancy services focusing on quality and efficiency.
Infostealer activity detected by HudsonRock
Compromised Employees: 1
Compromised Users: 2
Third Party Employee Credentials: 1
External Attack Surface:
3
DNS Records:
The following DNS records were found for the victim's domain.
- ilemgroup-com.mail.protection.outlook.com.
- panop-verification=VhuA11LTIL1nkQ0FYgEAjJCfrQN0ij07
- qvm53lh60ke8ev42gtfanjgr3m
- v=spf1 include:spf.protection.outlook.com a:mail.gmge.migros.ch a:mail2.gmge.migros.ch +ip4:185.247.64.9 -all
- 5KosBz9DYuYYotXIaPOr5vDSDxwf1Bc2WQ205QUafxwR+vhblq3PNUdS5PM64Y/q/OaKXSG5IMdcU7Ei0V5SUQ==
- EBi1PWj7lxwMTFXMsKR7XLwO2NC5RO+vyMpdRq75qNT1mcNcJN8oKjsXccBt0iywLos61b4tprTwUXo6vZHuzg==
- GXR9VnSM8fBrSOLkXLH6pd4RvQR3AN/AtsfOIeXo5PmGkBAFAxYbRpZaivU76wnxwdGJWvEPuTulB/kE4scbzA==
- Xn4eGB8VpmX0AXFjXUSVIhLiKwzNBgadTkDNId7tRZUOQefRRhWQvfTd0p0YC8HWvENE3t89jPKbDs6pbC64lA==
- a00vabvba3un15asj4eq12lshl
- apple-domain-verification=HuifEOAuC7nFLr6r
- ciscocidomainverification=20983fddc395a9bf7b6553e4e71f547e70f416e80078af75c6ca359583dac1d
- google-site-verification=-mEQuyhrw6MKXBEDsZ-p_IzUTXLbDrWlptS5OZQYUZE
- google-site-verification=9yVA0KgLb799SutETtZYDfPA57eTpYyowqF3qjplKSE
- google-site-verification=qu3ooGuvlYKf1gf98r1TQYL_zeM2UKlfBgAu5FMCzQo
- hpl1rl75sjqopcss6q2lcbtmjk
- lr1a68qt4hj5fu8i169tjj8o2h
Cloud / SaaS Services Detected
Apple
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.