Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo namico.go.ke

Group: Tengu

Discovered by ransomware.live: 2026-01-26

Estimated attack date: 2026-01-26

Country: KE

Description:

The National Mining Corporation (NAMICO) is a Kenyan state corporation that serves as the government's investment arm in the mining and minerals sector. Established under the Kenya Mining Act 2016, its primary objective is the exploration, development, management, and investment of the country's mineral resources on behalf of the state.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 4

Third Party Employee Credentials: 0


External Attack Surface: 2


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • websupport@icta.go.ke
MX Records
  • mx1.govmail.ke.
  • mx2.govmail.ke.
  • mx3.govmail.ke.
  • mx4.govmail.ke.
TXT Records
  • v=spf1 mx a:spf.govmail.ke ~all
  • 134167C96E08210C71A6E7CB1DA285BE
  • DE699A21448C597B54326087B9AAA940
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.

Leak Screenshot:

Leak Screenshot