Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Logo Instituto Nacional de Oftalmologia, Peru

Group: Nightspire

Discovered by ransomware.live: 2025-11-09

Estimated attack date: 2025-11-09

Country: PE

Data exfiltrated: 30 GB

Description:

Instituto Nacional de Oftalmologia, Peru


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 5

Compromised Users: 28

Third Party Employee Credentials: 5


External Attack Surface: 8


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • unoccleon gmail.com
MX Records
  • email.ino.gob.pe.
TXT Records
  • google-site-verification=IF3lP-OJi-BsRUJ0XMfA_z10yWovOVEiOOOVP7SBo8Y
  • v=spf1 mx ip4:143.137.144.6 ~all
Cloud / SaaS Services Detected
No well-known cloud or SaaS service detected.