Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Everest
Discovered 2026-01-05 04:01 UTC
Est. attack date 2026-01-05
Country DE

Description:

[AI generated] DESY, short for Deutsches Elektronen-Synchrotron, is a German research center funded by the Federal Republic of Germany, the states of Germany, and the German Research Foundation. Established in 1959 and based in Hamburg, it operates particle accelerators that are used to investigate the structure and function of matter. The center undertakes research in the fields of physics, photon science, nanotechnology, and much more.

Infostealer activity detected by HudsonRock

Compromised Employees: 18

Compromised Users: 57

Third Party Employee Credentials: 9


External Attack Surface: 95


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • b1721.mx.srv.dfn.de.
  • c1721.mx.srv.dfn.de.
  • a1721.mx.srv.dfn.de.
TXT Records
  • jamf-site-verification=IhsaJKXjMwxgqQ6BLavOYQ
  • cisco-ci-domain-verification=59878483e4881ac6dea5eb1d6b9f75b94fc05206ad35a47e224ffb31f1ec72aa
  • v=spf1 include:_spf1.desy.de include:_spf2.desy.de include:_spf.zimpel.de include:aspmx.pardot.com a:web07.hosting.astendo.de ?all
  • _globalsign-domain-verification=ro-lbcWwCRY5nLv0UFTFbaR8zhnI0Bs9TwrfdmPD5-
  • sending_domain871621=bac3104299add3e43e9ae4f3daff5d839f2f6c137f47dc33e28981e283be1d77
  • globalsign-domain-verification=ro-lbcWwCRY5nLv0UFTFbaR8zhnI0Bs9TwrfdmPD5
  • google-site-verification=Es9Pmp495cMgDRykWNAsCRWGutFSQJTRgI1pmDMzQ7E
  • "HARICA-buuGNklJfCVaO3igLZE"
  • MS=ms25975164
Cloud / SaaS Services Detected
Global Sign Microsoft 365 JamF Cisco

Leak Screenshot:

Leak Screenshot