Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Handala
Discovered 2025-02-02 08:50 UTC
Est. attack date 2025-02-02
Country NL

Description:

Today, in a strategic move, we, the Handala Group, have successfully breached and taken full control of the systems at Tosaf, one of Zionist’s largest industrial giants, with over 5,000 employees and 60 offices worldwide. Early this morning, we initiated a full lockdown of all entry points to the facility, preventing workers from entering. Following…

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 3

Third Party Employee Credentials: 18


External Attack Surface: 3


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegodaddy.com
MX Records
  • inbound-smtp.us-east-1.amazonaws.com. Amazon SES
TXT Records
  • v=spf1 include:70pqbgqtk0.powerspf.com ~all
  • 00Dj0000001oiVV=1TBPg0000000D6v;00DO200000Hr8or=1TBO20000000V3p;00Ddx000001plqj=1TBdx0000000BLF;00Dbf000003pZzh=1TBbf0000000HTt
  • 228ion3hac49du15qa5ho88bq3
  • MS=ms78389633
  • R10IO1SDYugvpNrSk+n/PIawqaYGvVYLgsENc7fW//UJ2hFcQy4l8MM7Gt3Eut1+cM7Jznpzf+Qc7UmjwyOLJA==
  • l8cvj37kql9ji1k36n5bekjv6b
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot