Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo lso.com

Group: Embargo

Discovered by ransomware.live: 2025-12-06

Estimated attack date: 2025-12-06

Country: LS

Description:

Lone Star Overnight (LSO) is headquartered in Austin, Texas, and, over the last 30 years, has become a leading regional parcel delivery company. LSO has a netwo... - LSO does not understand encryption so we demonstrated for them how encryption works. We have ~500 GB data total includin...


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 16

Third Party Employee Credentials: 1


External Attack Surface: 13


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse godaddy.com
MX Records
  • lso-com.mail.protection.outlook.com.
TXT Records
  • mailerlite-domain-verification=6443419e71471ed93c2dd43a2bb2f4fb49bb51e2
  • v=spf1 ip4:50.20.30.10/32 ip4:64.57.249.52 include:spf.protection.outlook.com include:dnsexit.com include:mailgun.org include:mktomail.com include:servers.mcsv.net include:_spf.createsend.com include:6024592.spf05.hubspotemail.net include:amazonses.com in" "clude:_spf.mlsend.com -all
  • brevo-code:6f031b532c3b8178dc00ee326f0c1b69
  • v67k9mrp4qd09421pjaatrpmln
Cloud / SaaS Services Detected
Amazon SES/WorkMail HubSpot Mailchimp Marketo Mailgun

Leak Screenshot:

Leak Screenshot