Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Logo SPZC

Group: Nova

Discovered by ransomware.live: 2025-12-19

Estimated attack date: 2025-12-19

Country: PT

Description:

Portugal A teachers' trade union organization that defends the rights of education workers, organizes strikes, and provides information about issues related to careers and working conditions.


🕵️ Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 10

Third Party Employee Credentials: 1


External Attack Surface: 16


Infostealer Distribution


DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • spzcentro@spzcentro.pt
  • josericardo@spzcentro.pt
  • spzcentro@spzc.pt
  • gestao.dominios@meo.pt
MX Records
  • mxp.ptempresas.pt.
  • mxc.ptempresas.pt.
TXT Records
  • MS=ms71918406
  • _globalsign-domain-verification=yf7vEv5KL167xFu1xIbXZhQgeRF3LzkDN9Gx5rVjQZ
  • _globalsign-domain-verification=y5tXY-ZedNKm_3sAFGupL9JhlPRodr_GcCmZLAnVkX
  • v=spf1 a mx ip4:153.92.224.0/19 ip4:185.24.144.0/22 ip4:94.143.16.0/21 ip4:89.234.188.0/22 ip4:185.41.28.0/22 ip4:62.48.207.158 ip4:109.71.45.1 include:_spf.ptasp.com include:_spf.kmitd.com include:_spfrlo.altice-empresas.pt -all
Cloud / SaaS Services Detected
Microsoft 365

Leak Screenshot:

Leak Screenshot