Group:
Cactus
Discovered by ransomware.live: 2025-03-17
Estimated attack date:
2025-03-17
Country:
Description:
<p>Automotive Parts</p><p>KYB Americas Corporation was established in 1974 and is headquartered in Greenwood, IN, USA. KYB manufactures original equipment shocks and struts for carmakers in the Americas and around the globe.</p><p>Website: <a href="https://www.kyb.com/">https://www.kyb.com/</a></p><p>Revenue : $600.5M</p><p>Address: 850 N Graham Rd Ste C, Greenwood, Indiana, 46143, United States</p><p>Phone Number: (317) 881-7772</p><p><mark class="marker-yellow"><strong>Download link #1:</strong></mark> <a href="https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/KYB/PROOF/">https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/KYB/PROOF/</a></p><p><mark class="marker-yellow"><strong>Mirror:</strong></mark> <a href="https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/KYB/PROOF/">https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/KYB/PROOF/</a></p><p><mark class="marker-yellow"><strong>DATA DESCRIPTIONS:</strong></mark> Confidential engineering data, drawings, personal identifiable information, customers' and partners' information, financial information, confidential information on corporate business and marketing strategies, manufacturing data, correspondence, HR department data, employees' and executives' files, database exports and backups, etc.</p><p><img src="/uploads/1_4b26899fb1.png" alt="1.png"><img src="/uploads/5_78aeb63477.png" alt="5.png"><img src="/uploads/3_5789862998.png" alt="3.png"><img src="/uploads/4_3dedf92b86.png" alt="4.png"><img src="/uploads/2_5f0250781d.png" alt="2.png"><img src="/uploads/6_1c1e371224.png" alt="6.png"></p>
Infostealer activity detected by HudsonRock
Compromised Employees: 0
Compromised Users: 7
Third Party Employee Credentials: 0
External Attack Surface:
5
DNS Records:
The following DNS records were found for the victim's domain.
- domain.operations@web.com
- kyb-com.mail.protection.outlook.com.
- Codesolarwinds-service0desk-verification=fe7788a30a590dc323dd8b3c9d0803ff
- vmware-cloud-verification-8a9a4cd2-b4b0-4f54-9d65-a104c8654d31
- 2-AFy*g3ZPUbDw4cBCyRVNdA4vHcgqQx
- v=spf1 include:mailgun.org include:spf.protection.outlook.com ip4:52.15.75.221 ip4:66.42.201.46 ip4:104.152.196.114 ~all
- apple-domain-verification=SsRFCFIvaQe9oDxX
- 9c5b5101-343e-4236-a2c6-bd03e19c7b4a
- MS=69386C22893C77CD5CA7AF979DB036D73B802749
- MS=ms81862908
Cloud / SaaS Services Detected
Apple
Microsoft 365
Mailgun
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.