Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Qilin
Discovered 2025-08-10
Est. attack date 2025-07-21
Country JP

Description:

JTEKT Corporation manufactures and sells steering systems, transmission components, bearings, machine tools, electronic control devices, home appliances, etc. It has its headquarters in Japan and offices in Europe, North America, Asia, Oceani ...

Infostealer activity detected by HudsonRock

Compromised Employees: 7

Compromised Users: 0

Third Party Employee Credentials: 3


External Attack Surface: 2


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • No emails found.
MX Records
  • jtekt-eu.mail.protection.outlook.com.
TXT Records
  • Certeurope=VAUgc4CrDjviEaMmqbm2ul6p490Zq4
  • _9z2qh9js7s45053777s5k9fery7vdp4
  • MS=ms51283934
  • v=spf1 MX include:spf.afas.online ip4:195.6.123.20 ip4:195.6.123.253 ip4:185.67.149.77 ip4:80.188.166.204 ip4:109.99.191.41 ip4:194.78.81.6 ip4:185.87.251.161 include:spf.protection.outlook.com include:spf.smartemailing.cz include:amazonses.com ~all
  • xpfn98crls3c248jmkdhlk5hqnwcyd7b
  • 4v8kbzw2gl65rpy70tm9c0wrtf3q88hc
  • cHyU7V4/HjA6TD6derqAGa08TY/mrs5fY798gVZvY5Vid5ZxLiQszr984z3rr2MsBFbS7NMQ+yhd3oKnzhnzHw==
  • 9dn3j9zh4y2gg77xfz3f9xycs2pnbm7p
  • MS=ms28376120
  • MHW7FHgfCoePW5G0zarKr5qSO+A=
  • J0T3E23752
  • MS=ms72765454
  • _a46hco4um3274jrvk664nbtrw6alf3q
  • sz01kgcbdc6ssn2c58rr2cknxwp3svh7
Cloud / SaaS Services Detected
Amazon SES/WorkMail Microsoft 365

Leak Screenshot:

Leak Screenshot