Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo Office of Public Sector Anti-Corruption Commission

Group: Direwolf

Discovered by ransomware.live: 2025-12-22

Estimated attack date: 2025-12-22

Country: TH

Data exfiltrated: 200GB

Description:

Government


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 4

Compromised Users: 33

Third Party Employee Credentials: 18


External Attack Surface: 21


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • staff@thnic.co.th
MX Records
  • mx2.uc-workd.com.
  • mx1.uc-workd.com.
TXT Records
  • v=spf1 include:_spf.uc-workd.com -all
  • MS=ms19215713
  • globalsign-domain-verification=KozlCYloziolgaIO22P2D9qHzrV4rlGOHWaACiycKG
  • \226\128\156cloudflare-verify" "IN" "TXT" "232658529-460231333\226\128\157
  • MS=E8F0E326225349510C15D32C05F07ED4BB2EE124
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot