Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

CIE Automotive

cieautomotive.com

Group Cactus
Discovered 2023-12-07 12:58 UTC
Est. attack date 2023-11-07
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

CIE Automotive is an industrial group specialised in supplying components and subassemblies for the automotive market. CIE Automotive focuses its activity on seven technologies — Aluminium, Forging, Stamping and Tube Welding, Machining, Plastic, Casting and Roof Systems.

Infostealer activity detected by HudsonRock

Compromised Employees: 4

Compromised Users: 50

Third Party Employee Credentials: 31


External Attack Surface: 19


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • legalserviceseurodns.com
  • jezkerracieautomotive.com
MX Records
  • cieautomotive-com.mail.protection.outlook.com. Microsoft 365
TXT Records
  • MS=ms23482022
  • v=spf1 include:_spf.mlsend.com mx ip4:212.8.121.89 ip4:212.8.121.90 ip4:212.142.196.68 ip4:212.142.196.69 ip4:46.255.210.145 ip4:54.240.31.72 ip4:54.240.31.73 ip4:54.240.31.74 include:spf.mailjet.com include:spf.protection.outlook.com ~all
Cloud / SaaS Services Detected
Microsoft 365 Mailjet