Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo zHealthEHR — Practice Management Software for Chiropractic & Wellness Clinics

Group: Kazu

Discovered by ransomware.live: 2026-01-26

Estimated attack date: 2026-01-26

Country: US

Data exfiltrated: 15 GB

Ransom: $500 000

Description:

zHealthEHR is a cloud-based electronic health record (EHR) and practice management platform built primarily for chiropractors and other wellness providers. It combines clinical documentation, appointment scheduling, patient intake, billing, payments, and automated reminders into a single system, helping small to mid-size practices streamline daily operations. The platform focuses on ease of use, customizable SOAP notes, and patient engagement tools, allowing providers to reduce administrative workload and run their clinics more efficiently through a subscription-based software model.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 33

Third Party Employee Credentials: 0


External Attack Surface: 16


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@godaddy.com
MX Records
  • aspmx2.googlemail.com.
  • aspmx3.googlemail.com.
  • alt2.aspmx.l.google.com.
  • aspmx.l.google.com.
  • alt1.aspmx.l.google.com.
TXT Records
  • google-site-verification=3qaN9uRZj61Y6Uvc1_pa5uVh2y9s1HqlOCDnZrZK2hk
  • _amazonses:4zwK0ps4pqRjqQBthkrc3pZliKE/FVkJlCj7RUq2PyI=
  • facebook-domain-verification=mynnq6nl0hj8bsuhkn6uu89s3r6nwo
  • google-site-verification=DDb9w6BDooejyP8GG0k3ONH7XKktdhQmLOJ6D1Wq6uU
  • MS=ms13222264
  • atlassian-domain-verification=LQKyYnjxPKqacz3RnghBPKiVTix7Avs2ttaYKRb/IRzDaasumddS6pMqiEgAcFc2
  • v=spf1 include:amazonses.com include:spf.zoho.com include:transmail.net include:zcsend.net include:_spf.google.com include:spf.happyfox.com ~all
  • google-site-verification=oEjj7c9Lubkzt7hYOCpmXqn5tMZWc2kIdwauDmpf9AQ
Cloud / SaaS Services Detected
Atlassian Amazon SES/WorkMail Microsoft 365 Zoho Campaigns