Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

KADOKAWA Corporation

kadokawa.co.jp

Discovered 2024-06-27 12:22 UTC
Est. attack date 2024-06-27
Country JP
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

Our team gained access to the Kadokawa network almost a month ago. It took some time, because of the language, to figure out that Kadokawa subsidiaries' networks were connected to each other and to get through all the mess Kadokawa's IT department made there. We have discovered that Kadokawa networks architecture was not organised properly. It was different networks connected to the one big Kadokawas infrastructure being controlled through global control points, such as eSXI and V-sphere. Once we have gained access to the control center we have encrypted the whole network (Dwango, NicoNico, Kadokawa, other subsidiaries).

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • aspmx.l.google.com. Google Workspace
  • alt1.aspmx.l.google.com. Google Workspace
  • alt2.aspmx.l.google.com. Google Workspace
  • aspmx2.googlemail.com. Google Workspace
  • aspmx3.googlemail.com. Google Workspace
TXT Records
  • v=spf1 include:_spf.google.com include:spf01.email.s-idc.net include:spf-bma.mpme.jp ip4:163.49.12.12/30 ~all
  • workplace-domain-verification= 27b81cb2-6317-43ad-b8c0-af04876a0edc
  • apple-domain-verification=TOWEGyQu4PBgKhu9
  • facebook-domain-verification=zpka5ufiqapf1bpzblb96rrw7iw6yh
  • google-site-verification=_uYdCsmcrmKc-vG9VcoBXODwi7UU-28n_ELqMUl2LWs
  • google-site-verification=rzt2P5oDH25Rak-JzTKbbesdq0Yy-RAV_At3IedOw4I
  • nulab-verification-code=cu1cQmftFI8fSECWe6VEl1jPy8LtAUnKuNlWIxpSgmFnPbejHY5YH5Lor6S4u6Ec
Cloud / SaaS Services Detected
Apple

Leak Screenshot:

Leak Screenshot