Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Qilin
Discovered 2025-09-03
Est. attack date 2025-09-03

Description:

NPi Audio Visual Solutions, USA - the company organizes and hosts business events and parties. What happens behind closed doors at private conventions? Now we can peek behind the curtain and find out what the rich and famous really discuss an ...

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 1

Third Party Employee Credentials: 2


External Attack Surface: 1


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operations@web.com
MX Records
  • d301411b.ess.barracudanetworks.com.
  • d301411a.ess.barracudanetworks.com.
  • npiav-com.mail.protection.outlook.com.
TXT Records
  • v=spf1 ip4:71.67.236.242 include:spf.protection.outlook.com include:spf.ess.barracudanetworks.com -all
  • iiqukhl2n5jefks9vij9vccgvh
  • apple-domain-verification=qa19E9a22EFkl8rY
Cloud / SaaS Services Detected
Apple

Leak Screenshot:

Leak Screenshot