Group:
Dragonforce
Discovered by ransomware.live: 2025-11-22
Estimated attack date:
2025-11-22
Country:
Description:
C&M Software is a leading technology company specializing in solutions for the financial market. Their offerings include automated processes, secure payment integrations, and payment solutions tailored for both immediate and installment transactions. The intended clients range from financial institutions to retail and corporate sectors, aiming to enhance efficiency and risk management within their financial operations. With a commitment to innovation, C&M Software is recognized for providing robust and flexible technology services that streamline payment processes and improve business intelligence.
Infostealer activity detected by HudsonRock
Compromised Employees: 0
Compromised Users: 2
Third Party Employee Credentials: 5
External Attack Surface:
3
DNS Records:
The following DNS records were found for the victim's domain.
- cmsw-com.mail.protection.outlook.com.
- v=spf1 a mx ip4:187.33.114.101 include:amazonses.com include:spf.protection.outlook.com include:47195188.spf07.hubspotemail.net -all
- google-site-verification=RBnvhlPXX-bFdrQmMbUV4UQJIC6sdJzgGS1R-lOBc3o
- google-site-verification=EVYz8olGLilgTB-vM_d-qd0AEvTHUbEK82zioIz3U6Q
- _4jpfaf5d09f9kgrmkj04tq6xke3ikn7
- d4sign-domain-verification=424fbece-3ac5-4f3d-9e7c-4898f5ba51a4
- MS=ms76282405
- MS=B74B32CE8CDF5E7F383A642AB97929930C04A9F6
- atlassian-domain-verification=vhnLGt2oapTgnn0L9NNAq/WgGlmjq5qd5EGbIk/gIUl9OPIAiyq4BktrBZ26xfZZ
- google-site-verification=xDMmsHCjC1cGH_byqu75EobruHAPUKE_dAPhYy9mU6A
- 1fm2b1602dzlnj9xk814yb58m1v0xqy0
Cloud / SaaS Services Detected
Atlassian
Amazon SES/WorkMail
HubSpot
Microsoft 365
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.