Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Iberia Airlines

iberia.com

Group Everest
Discovered 2025-11-25
Est. attack date 2025-11-25
Country ES
City Madrid

Description:

[AI generated] Iberia Airlines, officially known as Iberia Líneas Aéreas de España S.A. Operadora, is the largest and national flag carrier airline of Spain. It was founded in June 1927 and operates an international network of services from its main base in Madrid. Iberia is a part of the International Airlines Group (IAG), along with other airlines like British Airways and Aer Lingus. Its fleet includes various Airbus models.

Infostealer activity detected by HudsonRock

Compromised Employees: 0

Compromised Users: 31012

Third Party Employee Credentials: 4


External Attack Surface: 100


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@acens.net
MX Records
  • poster1i.iberlayer.com.
  • poster4i.iberlayer.com.
  • poster2i.iberlayer.com.
  • poster3i.iberlayer.com.
TXT Records
  • _globalsign-domain-verification=nZvMMlnmAtTBVjUSUmpPkxmaXheA_jZW3tjO3eDXvm
  • 0lRl9Ln7uM7hWByU2/zPURYJU9uPW/Z/myaOgnJULlA=
  • proxy-ssl.webflow.com
  • onetrust-domain-verification=487caa94d6424189b16272918898f98e
  • google-site-verification=W4r9HKPY0YEL5ASfMZUYWPEeu9HWW7WYT-JDNQxAGKc
  • atlassian-domain-verification=zJ9AFo0np2wqrLS9O0kZQxRGOnCUtaP/8xvace9mgu9YZtVnlCM9lpZH8QXFFtsy
  • jbruGHMewGu5oZ+1oJB0lF2bshLlLtIrTzMiWP7V17U=
  • _globalsign-domain-verification=eOzKo5L35AVsz3o5Lhgi1uqiZkf6Y0VA-6W1numH-b
  • v=spf1 include:iberlayer.com include:iblhelper.net include:spf.protection.outlook.com include:inbentaspf.smtp.com ip4:18.209.218.79 ip4:18.210.161.213 ip4:54.152.130.14 ip4:54.175.250.82 " " ip4:195.53.213.13 include:spf.mandrillapp.com ip4:208.87.208.0/21 mx -all
  • tEw7HaYlfZMfqdfhPbPgDs5y/nXbVzKRWcIrrgt6KK8=
  • openai-domain-verification=dv-MwhDeNAWlyWh5ay7kEfjqmu6
  • d9BsCRJDxBZLw8xMw6f2HlbF/JrYx6Pg/lPJ+E3j0/g=
  • hVayFjlSeODSeVs1kK/vtlJycOLGOdYJMvLaIqSRNl4=
  • _akamai-host-challenge.test.api.iberia.com. TXT BpSicXZI9719ADw9tGkNpe4bll2-iJ0I2n-Z7JTuU-SwlojlASTMdg
  • affCoeXY6MEqYMjZ8ozzXox28dq3E3wHd3rY/0X0cbg=
  • m4GSvvz56tzgINopcXcByBAt3xzq2FlauTAHUfLROYHgKJn4ddLVqz2DQv//1CA0BgJjsJDM7ozaHTHqjQZLZQ==
  • v=DMARC1; p=reject; pct=100; rua=mailto:dmarc_rua@emaildefense.proofpoint.com; ruf=mailto:dmarc_ruf@emaildefense.proofpoint.com
  • MS=ms14609430
  • _globalsign-domain-verification=SHI6FyL2BSmVOFAezoH5w6vR0EneyN94Pf7toJGeIn
Cloud / SaaS Services Detected
Atlassian Microsoft 365 Mandrill OneTrust Proofpoint

Leak Screenshot:

Leak Screenshot