Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo lesker.com

Group: Chaos

Discovered by ransomware.live: 2025-12-02

Estimated attack date: 2025-12-02

Country: US

Data exfiltrated: 615 GB

Description:

Since it's foundation in 1954, Kurt J. Lesker Company has manufactured and sold vacuum equipment and parts to the electronic and communications related industries


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 102

Third Party Employee Credentials: 0


External Attack Surface: 15


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
  • webmaster lesker.com
MX Records
  • d53873b.ess.barracudanetworks.com.
  • d53873a.ess.barracudanetworks.com.
TXT Records
  • 59et5a542l819g0bch4arsei14
  • v=spf1 ip4:216.24.89.80/28 ip4:71.182.144.92 ip4:23.21.109.197 ip4:23.21.109.212 ip4:147.160.167.0/26 include:spf.ess.barracudanetworks.com include:spf.protection.outlook.com include:spf.us.exclaimer.net ~all
  • rJg32cnnCGtcfDJlABs3zadggoDRSIVJrUU6Qt7b53eyC+hpPpy0nIG/5uhQUINmSONsr72cBLIYF1Z9BC1bvQ==
  • g6t08fcla0g8u12ch4mqsurp2v
  • 1s015i451nhn31lsv310jjgnvk
  • MS=4CB142BDC856C6912C5FF8C53AE0EC761AE4B570
  • MS=ms76112946
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot