Quick Summary
AllegedExecutive Summary
The ransomware group qilin claimed Cosmocolor SA de CV, a manufacturing company based in Mexico, on August 30, 2026. The threat actor asserted unauthorized access to the company’s systems and data, listing Cosmocolor’s domain (cosmocolor[.]com[.]mx) on their leak site. The telemetry gathered by SOCRadar CTI indicates that infostealer malware captured 14 employee credentials and 9 corporate third-party credentials. These credentials included access to physical security platform Verkada, with the data spanning approximately two months prior to the leak site listing. Over the preceding 60 days before this claim, qilin had listed 248 victims on its leak site. The group’s primary targets geographically are the United States and Germany, with a significant focus on the Manufacturing and Professional Services sectors. Cosmocolor SA de CV aligns with the group’s typical targeting profile within the Manufacturing industry. Qilin is known for its high-volume operations and shows no indication of slowing down its activities.
Technical Analysis
SOCRadar CTI’s analysis of stealer-log data revealed a “severe_exposure_in_sample” verdict for Cosmocolor SA de CV. The collected telemetry included 14 employee credentials across platforms such as M365, ADFS, and Atlassian, in addition to 9 corporate third-party credentials. Notably, these third-party credentials provided access to physical security systems like Verkada. The timestamps associated with this credential exposure range from June 22, 2026, to August 25, 2026, indicating a two-month window of compromised access prior to the qilin group’s public claim. The exposed credentials encompass access to critical business and security infrastructure. The inclusion of Verkada credentials suggests a potential pathway into physical security monitoring systems, which could be leveraged for reconnaissance or other malicious activities. The timeframe of the exposed data, ending shortly before the leak site listing, strongly suggests a correlation between the infostealer activity and the ransomware group’s claim. Given the findings, continued monitoring of dark web sources and stealer-log feeds for Cosmocolor SA de CV is recommended. Proactive credential hygiene checks, including password rotation and multi-factor authentication review for all accounts, are crucial. Furthermore, organizations should consider monitoring activity related to Microsoft 365, VPNs, and remote-access portals for any suspicious access patterns.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.