Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Group Alphv
Discovered 2023-07-26 16:26 UTC
Est. attack date 2022-12-01
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

Grupo NGN has refused to protect their customers' data and access to their networks. This link (TOR) contains Grupo NGN's random files: http://[REDACTED].onion/GRUPGN/ Auction ends Dec. 8 for all sensetive data of Grupo NGN and their customers, including - Access to multiple networks of Grupo NGN clients (with their networks secured, password changes will not help defend against an attack) - NDA documents and records of Grupo NGN customers' conversations - Personal data about employees and customers of Grupo NGN - Financial information of Grupo NGN and their clients that can be used for criminal purposes To participate in an auction to purchase Grupo NGN and their customer data, you can email: [REDACTED]@proton.me GRUPONGN.COM HACKED. MORE THAN 200GB OF SENSITIVE DATA STOLEN.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 3

Third Party Employee Credentials: 0


External Attack Surface: 3


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuseionos.com
MX Records
  • grupongn-com.mail.protection.outlook.com. Microsoft 365
  • grupongn.in.tmes.trendmicro.com.
TXT Records
  • MS=ms79953845
  • hes=b60467ef1949b47f3eded4095ec9bf91
  • site24x7-signals-domain-verification=dcb2bbe383244f773a1b196133ecc4a5
  • google-site-verification=nqARhc2cpGDO5iZGfYkFIu6WYEHhVOlUluaP8McgxBA
  • facebook-domain-verification=3ysldmhoh8ixildbqjm4fnzoi4q9c5
  • v=spf1 include:transmail.net include:spf.protection.outlook.com include:mail.zohoanalytics.com include:zcsend.net include:zeptomail.net include:spf.tmes.trendmicro.com include:spf-us.emailsignatures365.com include:ngncontactcenter.onmicrosoft.com include:" "50246737.spf08.hubspotemail.net include:mailgun.org ip4:162.252.248.0/22 ~all
Cloud / SaaS Services Detected
HubSpot Mailgun Microsoft 365

Leak Screenshot:

Leak Screenshot