Group:
Ransomhub
Discovered by ransomware.live: 2024-12-03
Estimated attack date:
2024-11-19
Country:
Description:
[AI generated] FibroGen, Inc. is a biopharmaceutical company dedicated to the discovery, development, and commercialization of novel therapies to treat serious unmet medical needs. The company focuses on areas such as fibrosis and oncology, with its lead product candidates targeting conditions like chronic kidney disease and anemia. FibroGen harnesses innovative technologies to develop first-in-class therapeutics.
Infostealer activity detected by HudsonRock
Compromised Employees: 1
Compromised Users: 2
Third Party Employee Credentials: 3
External Attack Surface:
1
DNS Records:
The following DNS records were found for the victim's domain.
- domain.operations@web.com
- fibrogen-com.mail.protection.outlook.com.
- apple-domain-verification=sIeWx3HATchGRd31
- atlassian-domain-verification=RB9cAFTW3pwaaIFa6wOL1d06nZjsW7B71Ff74UcGolCHKATzjcchA2eA9h9/IjlC
- docusign=aa350096-b462-41ab-bc8a-b52bf7c3e90d
- docusign=e9219f41-e4cf-4bdf-a87a-6d35a84edf56
- google-site-verification=63sgAjlp00116eHO286Y5icV3S9Ktij2_6KKux1JEqg
- rippling-domain-verification=c70a08d7be189b2b
- v=spf1 include:spf.ess.barracudanetworks.com include:spf.protection.outlook.com ip4:34.83.147.102 ip4:198.37.147.129 ip4:12.230.193.5 ip4:12.230.193.7 ip4:128.136.28.235 ~all
- zoho-verification=zb26368958.zmverify.zoho.com
- MS=65C4E84AD373F9EF607C86B1A1B905B415E09386
Cloud / SaaS Services Detected
Apple
Atlassian
Zoho Campaigns
Rippling
DocuSign
Leak Screenshot:
Legal Disclaimer:
Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession,
hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data.
This platform indexes only publicly visible information posted by ransomware operators and
open web sources without accessing or obtaining the underlying stolen content.
The service is provided to support public awareness, legitimate research, and cyber-resilience.
No stolen personal or confidential data is collected or distributed via this site.