Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Red Hat, Inc.

redhat.com

Discovered 2025-10-05 19:21 UTC
Est. attack date 2025-09-13
Country US

Description:

[AI generated] Red Hat, Inc. is a leading American multinational software company that provides open-source software products to businesses. It became a subsidiary of IBM in 2019. The company is best known for Red Hat Enterprise Linux, a top-level operating system. Other notable offering includes its architecture service, cloud computing (virtualization), and storage solutions.

Infostealer activity detected by HudsonRock

Compromised Employees: 70

Compromised Users: 65564

Third Party Employee Credentials: 80


External Attack Surface: 160


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • redhat.com-Adminanonymised.email
  • redhat.com-Registrantanonymised.email
  • abusecomlaude.com
  • redhat.com-Techanonymised.email
MX Records
  • us-smtp-inbound-1.mimecast.com. Mimecast
  • us-smtp-inbound-2.mimecast.com. Mimecast
TXT Records
  • google-site-verification=fkn6chapCdYNWIcpsgH0K6mkR0yo7ldeIRC7EH23yoo
  • MS=ms44845140
  • _w3mdwen0nsght830g06ehmrsdmvuilf
  • apple-domain-verification=xaB3GAa9xxzrpoS4
  • miro-verification=0bc02d4257d450b9f9034363a58f88b4b904dc22
  • docusign=c6aa79da-fde1-4b7e-8874-28eeb223ca63
  • cursor-domain-verification-xts7mh=BCrLupJRjleUhfxmNA4CUlgaE
  • Dynatrace-site-verification=6d28213f-f653-42df-8f09-a7ae69f50e6a__dk5hkah3juetfgj11au5isjmig
  • adobe-idp-site-verification=10154eb7d4abe67e9e45621e46476febbec28a97a4610d7c043c42c667aa18d4
  • wework-site-verification=EABEURRXyO1yBZcn
  • jetbrains-domain-verification=c52sdl8fpvtdvcunhy64u3149
  • google-site-verification=TaSjV4JOe2XfmL_vHFKJHkPk8sjgoLkuuTTWezDO0Pw
  • docusign=cfd355fc-11f9-4eaf-8ecf-64433ef46173
  • status-page-domain-verification=dfx5rbys1ts5
  • v=spf1 redirect=73t7ezjz._spf._d.mim.ec
  • MS=ms88428189
  • status-page-domain-verification=hyls0f05cd87
  • pendo-domain-verification=01424ad4-8f69-4456-90ff-5f544ada6cec
  • segment-site-verification=Kk3pC9UBfhioQzibTvTIhT4TFVwP4niP
  • slack-domain-verification=dPrnI9sLvqvAbQUwzvFsPXSPEU1PLODdgGxLhEUr
  • docker-verification=b3c48bbc-05f6-40b8-8391-b5ad3366c6ec
  • anthropic-domain-verification-75gwks=eCqmQbyCwqL2ocuciTDIydVPj
  • atlassian-domain-verification=fHiTv781WbOHgzl6U1McyXa9JUSSO5B0ECvgSZzJ9+b4q8wv0Tf4iI75xdcyoC00
  • Dynatrace-site-verification=1782cd51-ac66-4966-acdc-061c80f794f5__t1aa4l3qdsf475891sv2711t80
  • google-site-verification=rl_wq5rq_W7A7OSyK08d8Ta_Hf6AKP5tqtdlo4iGTvs
  • amazonses:ablaZDaC37yeQUcZAZjbfqRELxucC+8pBdvhFEpTSlY=
Cloud / SaaS Services Detected
Adobe Apple Atlassian Amazon SES/WorkMail Docker Microsoft 365 Slack Anthropic Miro Segment Mimecast DocuSign

Leak Screenshot:

Leak Screenshot