Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo revitalash.com

Group: cactus

Discovered by ransomware.live: 2025-02-18

Estimated attack date: 2025-01-15

Country: US

Description:

<p>Cosmetics.<br><br>“Athena Cosmetics, Inc. Is committed to the belief that it’s continuing business success is built upon the manufacture and sale of safe, reliable, quality products, combined with uncompromised integrity and the spirit of philanthropy. As a company, we embrace and pass these values on to our customers, employees and partners.”<br><br>Website: <a href="https://www.revitalash.com/">https://www.revitalash.com/</a><br><br>Revenue : $21.5M<br><br>Address: 23000 Avalon Blvd, Carson, California, 90745, United States<br><br>Phone Number: &nbsp;(805) 662-2020<br><br><mark class="marker-yellow"><strong>Download link #1:</strong></mark> &nbsp;<a href="https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/REVITALASH/PROOF/">https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/REVITALASH/PROOF/</a><br><br><mark class="marker-yellow"><strong>Mirror:</strong></mark> <a href="https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/REVITALASH/PROOF/">https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/REVITALASH/PROOF/</a><br><br><mark class="marker-yellow"><strong>DATA DESCRIPTIONS:</strong></mark> Personal Identifiable information (both customers and employees), database backups &nbsp;(150k+ customers private data), various confidential corporate and employees docs, financials, HR dept data, agreements, complaints, QA docs, corporate correspondence, etc.</p><p><img src="/uploads/Passport_0692e3a968.png" alt="Passport.png"><img src="/uploads/Michael_Brinkenhoff_Passport_6e8358e1d0.png" alt="Michael Brinkenhoff Passport.png"><img src="/uploads/Lani_Starr_2024_Arbitration_Agreement_0e8fcf6c9f.png" alt="Lani Starr 2024 Arbitration Agreement.png"><img src="/uploads/2023_P_and_L_budget_compare_b02b1545b8.png" alt="2023 P&amp;L budget compare.png"><img src="/uploads/Complaint_Form_374606_US_C0854646_Kristin_Vanderpool_4c40c6732a.png" alt="Complaint Form - 374606US - C0854646 - Kristin Vanderpool.png"></p>


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 12

Third Party Employee Credentials: 1


External Attack Surface: 5



DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations web.com
MX Records
  • revitalash-com.mail.protection.outlook.com.
TXT Records
  • google-site-verification=FNk5IDlFPm7nrGspCDbCoGMFuSXHnJOLDfX-Cf_WTQo
  • google-site-verification=Wr2aMeJaWOGjhkA_wpEzf1Ezklv27rPwAEmbQilbdIU
  • google-site-verification=GRq2tyUzrp9xjG6EBZ_BNrBF6Ts7wbqA2sM-24O-yBQ
  • klaviyo-site-verification=LALdK7
  • shopify-verification-code=5zWGjHzqw6JInn0996dHT1VJwZNgyt
  • v=spf1 include:spf.protection.outlook.com include:sendgrid.net -all
  • apple-domain-verification=0dzm51Xfw7pOeLUc
  • MS=ms62192209
  • shopify-verification-code=g0IUm0WPE16oxc2dbIvCDWQgmYht0v
  • facebook-domain-verification=s4pkj67c2rflnl85gain109rk806po
Cloud / SaaS Services Detected
Apple Microsoft 365 SendGrid

Leak Screenshot:

Leak Screenshot