Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo naffco.com

Group: Incransom

Discovered by ransomware.live: 2025-11-20

Estimated attack date: 2025-11-19

Country: AE

Description:

NAFFCO is an international manufacturer and supplier of firefighting, security, and safety products. They also offer training services and emergency responder certification. The company is headquartered in Dubai, in the United Arab Emirates. With a global network spanning over 100 countries, NAFFCO has been recognized as the unparalleled leader in fire safety. The official website of NAFFCO says:" Our success is driven by our "passion to protect"" We do not know for certain how well they protect their clients, but they could not protect themselves. We have 1TB of data at our disposal (fiscal data, internal mail, HR data, budgets, strategic development plans and much more)


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 193

Compromised Users: 105

Third Party Employee Credentials: 52


External Attack Surface: 35


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
  • ju5rq3jg28s networksolutionsprivateregistration.com
MX Records
  • eu-smtp-inbound-2.mimecast.com.
  • eu-smtp-inbound-1.mimecast.com.
TXT Records
  • qaqekbh7fa739ht0aqkb77fs7v
  • tuht6uqo506f2agdulp8ndmsjm
  • v=spf1 include:zeptomail.net.in include:eu._netblocks.mimecast.com ip4:151.253.145.165 ip4:172.104.53.46 include:spf.protection.outlook.com include:spf.exclaimer.net include:mail.zendesk.com -all
  • 3kvtb4m700c8qsbxl81m5t717q7j65bs
  • 3oj2gcs979qjdbn549ff92jeh4
  • 494d8dc99f9d4e578cdfb2a99d05a1fa
  • 5d1kt923vaaj53cspeaebgtgds
  • 5mi8biotrrl4gb36uf367nump8
  • 6ieqdr15v4etsr4bud2s4qh8i6
  • 7fbch93q8rvdrg7q7pa22ei8cu
  • 7gvj73lvo60qnqb1dh8ngu8kit
  • 8fmk23fr5neustst4lq3gt18r9
  • OXa7SNhXH7EpVwwbaQYcwRFwXHX6s/gtxhXkylWTrSvw7Ee8GEiOem01cS2RBMeF+Sv1Cy761WeBljIbk0j7Bg==
  • VvHJ+0h7xdK3wk//abvg1s0Lqpj4AcM+4EwtuQE+lerj/CWJ/9VmWxmhuMpTIOYBcjs/gIy0hh5JxzKsYxedew==
  • bj3bak06gdb69vv9fke38312vn
  • c3g2vapbu3b3lr2irluiidcjrn
  • cq1n452ssysjvyxbf4ghk7xk2cnylkkc
  • e9jkvu5m9u008j4buj1jbc9hle
  • google-site-verification=xsgCsCyZQ8fWoJ3AD0-5mLnUZV08Td3VCWM6Vlm8vDo
  • pbui8adcb7nfblo70mefgofdlf
Cloud / SaaS Services Detected
Zendesk Mimecast

Leak Screenshot:

Leak Screenshot