Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo rainbowtel.net

Group: Incransom

Discovered by ransomware.live: 2025-12-10

Estimated attack date: 2025-12-10

Country: US

Description:

Rainbow Communications offers reliable high-speed internet and phone services primarily in Northeast Kansas. They cater to both residential and business clients, providing essential connectivity solutions. We downloaded 200GB of selected information (accounting, HR, customer data, as well as confidential information).


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 2

Third Party Employee Credentials: 16


External Attack Surface: 3


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@godaddy.com
MX Records
  • rainbowtel-net.mx.av-mx.com.
TXT Records
  • v=spf1 include:e2ma.net include:_spf.mailersend.net include:_spf.qualtrics.com include:sendgrid.net ip4:137.118.16.0/22 ip4:76.77.208.28 ip4:208.80.200.0/21 ip4:66.179.68.37 include:spf1.neonova.net ~all
  • google-site-verification=1K47g_aNPElwpo8OhE5DUbi8jWCc2xUvKeuVB2pIWgw
Cloud / SaaS Services Detected
SendGrid

Leak Screenshot:

Leak Screenshot