Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Alphv
Discovered 2023-07-26 14:51 UTC
Est. attack date 2023-05-16

Description:

Orion Corporation is a South Korean confectionery company, headquartered in Munbae-dong, Yongsan District, Seoul. The company is one of the three largest food companies in South Korea

Infostealer activity detected by HudsonRock

Compromised Employees: 2

Compromised Users: 32

Third Party Employee Credentials: 13


External Attack Surface: 35


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusegabia.com
MX Records
  • spam.orionworld.com.
  • mail.orionworld.com.
TXT Records
  • MS=2A7845F5DA744B95E996FB5AC22F4AEA36826ABC
  • v=spf1 ip4:125.141.205.112 ip4:20.214.198.9 ip4:20.214.198.6 ip4:211.62.35.141 ip4:220.76.203.171 ip4:211.62.35.131 ip4:211.62.35.143 ip4:20.214.198.15 ip4:13.124.111.122 ip4:119.206.195.166 ip4:210.98.148.0/24 -all
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.

Leak Screenshot:

Leak Screenshot