Group:
Clop
Discovered by ransomware.live: 2025-01-24
Estimated attack date:
2025-01-24
Country:
Description:
[AI generated] Mad Engine is a leading global apparel and accessories wholesaler. With a specialization in licensed merchandise, the company provides unique collections inspired by popular brands, films, and characters. In addition to B2B services, Mad Engine also supports direct-to-consumer sales. Their range extends from t-shirts and hoodies, to accessories like hats and socks. The company focuses on quality, creativity, and innovation in their designs.
Infostealer activity detected by HudsonRock
Compromised Employees: 0
Compromised Users: 2
Third Party Employee Credentials: 0
External Attack Surface:
2
DNS Records:
The following DNS records were found for the victim's domain.
- domain.operations@web.com
- madengine-com.mail.protection.outlook.com.
- apple-domain-verification=SAWi79wxIOGMNEk0
- openai-domain-verification=dv-TmrwdAkNimydb6lqWDW7y10R
- docusign=01d36d45-fba0-4063-ace1-f52d330dfad9
- asv=cc3e0917e8109974231dc052926ea77d
- atlassian-domain-verification=uqlj8iIAJG0hYXEK0BhQancF79ekaJyHbCvxL8hY0c1bouaOmqRLhaaMbN6JWDlv
- sophos-domain-verification=66b323819cc44648b02161c2f46d1c0c582e945d956bf7b02acf0475eee61e58
- google-site-verification=P8U0P_AbTzJ9OcaxQRPbu6g5-SuA9W80EEPRLzivbvA
- _nksubv3w78drs2enteinfqtmqjsf2s8
- v=spf1 ip4:54.177.171.143 ip4:184.169.238.165 ip4:207.114.137.222 ip4:52.8.151.153 ip4:13.56.239.156 ip4:12.162.76.210 ip4:63.208.108.82 ip4:52.52.214.238 include:spf.protection.outlook.com include:mail.zendesk.com include:spf.myconnectwise.net -all
- adobe-idp-site-verification=c068c6406aa53d552aee5bb876fc4c26c52f2dd9a7f220305fae7f86486fae83
Cloud / SaaS Services Detected
Adobe
Apple
Atlassian
Zendesk
DocuSign
Sophos
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.