Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Enjoying ransomware.live? Help us keep tracking ransomware gangs and shipping new features. Support us

Shamir Medical Center

shamir.org

Group Qilin
Discovered 2025-10-02 14:49 UTC
Est. attack date 2025-10-02
Country IL
Sector
Agriculture and Food Production Education Energy & Utilities Financial Services Government & Defense Healthcare Hospitality Manufacturing Other Professional Services Retail & E-Commerce Technology Transportation

Description:

We have successfully infiltrated and gained full access to your systems at Shamir Hospital, the largest medical facility in Israel. Over the course of our operation, we have exfiltrated approximately 8 terabytes of sensitive and confidential ...

Infostealer activity detected by HudsonRock

Compromised Employees: 7

Compromised Users: 34

Third Party Employee Credentials: 0


External Attack Surface: 10


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuseenom.com
MX Records
  • mx.zoho.com. Zoho Mail
  • mx2.zoho.com. Zoho Mail
TXT Records
  • globalsign-domain-verification=4B6708F3E8EF8DE4302B1BFACAF95725
  • google-site-verification=d4El3chmP-Y5HsUUkx3493kpploZ8r7nalb5g_8g7vM
  • 00d3z000001brprea4
  • rovag_verification_token=16286FA9B1CC44C6931DD36F185396DC
  • zoho-verification=zb49060843.zmverify.zoho.com
  • v=spf1 mx a ip4:62.219.21.31 ip4:31.168.46.49 include:zoho.com -all
  • _globalsign-domain-verification=HXyecr9ZTCHKUrCMYrO5GEzvaTG-WBu61SNTT4b_ds
Cloud / SaaS Services Detected
Global Sign Zoho Campaigns Zoho Mail

Leak Screenshot:

Leak Screenshot