Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Nova
Discovered 2025-12-19 13:59 UTC
Est. attack date 2025-12-19
Country PT

Description:

Portugal A teachers' trade union organization that defends the rights of education workers, organizes strikes, and provides information about issues related to careers and working conditions.

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 10

Third Party Employee Credentials: 1


External Attack Surface: 16


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • gestao.dominiosmeo.pt
  • spzcentrospzc.pt
  • josericardospzcentro.pt
  • spzcentrospzcentro.pt
MX Records
  • mxp.meoempresas.pt.
  • mxc.meoempresas.pt.
TXT Records
  • _globalsign-domain-verification=y5tXY-ZedNKm_3sAFGupL9JhlPRodr_GcCmZLAnVkX
  • v=spf1 a mx ip4:153.92.224.0/19 ip4:185.24.144.0/22 ip4:94.143.16.0/21 ip4:89.234.188.0/22 ip4:185.41.28.0/22 ip4:62.48.207.158 ip4:109.71.45.1 include:_spf.ptasp.com include:_spf.kmitd.com include:_spfrlo.altice-empresas.pt -all
  • MS=ms71918406
  • _globalsign-domain-verification=yf7vEv5KL167xFu1xIbXZhQgeRF3LzkDN9Gx5rVjQZ
Cloud / SaaS Services Detected
Global Sign Microsoft 365

Leak Screenshot:

Leak Screenshot