Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Qilin
Discovered 2026-02-17 12:24 UTC
Est. attack date 2026-02-17
Country US

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 50

Third Party Employee Credentials: 31


External Attack Surface: 15


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuseenom.com
MX Records
  • mxa-00a16401.gslb.pphosted.com. Proofpoint
  • mxb-00a16401.gslb.pphosted.com. Proofpoint
TXT Records
  • v=spf1 include:_spf.castlegroup_com._d.easydmarc.pro ~all
  • 75A50AC48E
  • MS=ms63720790
  • amazonses:9IQKwy0rY9qbTpzcGEC8z0QxMp6p5FDemK1PU5KECRQ=
  • amazonses:H+Q8vau7J3GiKqd5EJFYQHnVq0EgbzHHH7NCr++W57M=
  • dropbox-domain-verification=u5qtv9ar404n
  • google-site-verification=SsGXpyT0XCuMYUzJAIt9ZafcWqKFgSuSHocXCgtV6so
  • google-site-verification=b3hYehtUCy-3h_9av8jwA6jSs-yvCZtNI8esb0MDZ3w
  • pardot1074592=aabdea0bfd886c3731eabd06e3b5eb640a34f6e0ce32897a692d854b6936b205
  • sending_domain1074592=f815a4505adf6065248f6d6d20d8a5724d365ff9df0fde4a71fd58f491f4b5a4
  • thcy642vpqbyj6059rcqqnmwflf3370h
Cloud / SaaS Services Detected
Amazon SES/WorkMail Dropbox Microsoft 365 Salesforce Box Proofpoint

Leak Screenshot:

Leak Screenshot