Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

www.ahmadiyya.ca

ahmadiyya.ca

Group: Ransomhub

Discovered by ransomware.live: 2025-03-21

Estimated attack date: 2025-03-21

Country: CA

Description:

[AI generated] "www.ahmadiyya.ca" is the official website for Ahmadiyya Muslim Jama'at Canada, a religious community of Muslims who accept Mirza Ghulam Ahmad as the Promised Messiah. The organization promotes a peaceful understanding of Islam and the spiritual rejuvenation through the advent of the Promised Messiah. They also engage in educational, humanitarian, and interfaith activities.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 15

Third Party Employee Credentials: 3


External Attack Surface: 4


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@godaddy.com
  • Please ask the Registrar of Record identified in this output for information on how to contact the Registrant, Admin, or Other contacts of the queried domain name
MX Records
  • alt4.aspmx.l.google.com.
  • alt1.aspmx.l.google.com.
  • alt2.aspmx.l.google.com.
  • aspmx.l.google.com.
  • alt3.aspmx.l.google.com.
TXT Records
  • v=spf1 a ip4:207.61.87.228 ip4:107.20.210.250 ip4:54.229.2.165 ip4:54.153.131.110 ip4:52.1.14.157 ip4:52.30.130.201 ip4:54.66.252.242 include:_spf.google.com include:amazonses.com -all
Cloud / SaaS Services Detected
Amazon SES/WorkMail

Leak Screenshot:

Leak Screenshot