Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

guesty, LITELLM/TRIVY CAMPAIGN (TEAMPCP)

www.guesty.com

Group Vect
Discovered 2026-04-15
Est. attack date 2026-04-15
Country IL

Description:

Status: STATUS: NEGOTIATING | Sector: property management | internal projects, 4 million sent/received mails with attachments, userbase, Airbnb and booking.com data stolen from guesty DATA SIZE: 700GB | Deadline: 9d 8h

Infostealer activity detected by HudsonRock

Compromised Employees: 62

Compromised Users: 564

Third Party Employee Credentials: 93


External Attack Surface: 44


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abuse@godaddy.com
MX Records
  • alt2.aspmx.l.google.com.
  • aspmx.l.google.com.
  • alt3.aspmx.l.google.com.
  • alt4.aspmx.l.google.com.
  • alt1.aspmx.l.google.com.
TXT Records
  • cursor-domain-verification-35crq9=7gnjNgKRq46PaCvRPUCV7TjO7
  • google-site-verification=KJGYwyUYhb43t7RCMTdF7yVy6gys3hrnXoRqeyij6Uk
  • airalo-domain-verification=CARam0uDz80V0q7
  • miro-verification=b62af21c77238215ab627a8b4914501d13005728
  • atlassian-domain-verification=cuzcsbAWK9F7UKX+KOu7VQDe2N51/yRV2luaJGVvaU1xqiIngWR2oldErLCdnwv+
  • MS=ms79940939
  • notion-domain-verification=DvD6esbkNiknFweqGn3tAizJopZHQpR0GCFren6R66Y
  • google-site-verification=5Tv2SPkPzxtt3mlfEjANEW-p5N3g89iY6mLDkqYaWMw
  • mongodb-site-verification=j7cYagXVe24HtIcSUPKS1AcqWyFCrG36
  • loom-site-verification=e3925d0272ad4094bd85acc5797c103b
  • apple-domain-verification=Smcms3NUhYxyJDlN
  • MS=ms32467218
  • docker-verification=a4399279-a9f6-4c01-a84e-efb52730281b
  • google-site-verification=iHHM4Qt5sLzxH-BZSrDZB8H42nYY_47Ue3NgvBif93Q
  • v=spf1 include:2f4v9wle8.spf.checkpoint-spf.com include:docebosaas.com a:zgateway.zuora.com ~all
  • brevo-code:c76be20f9afc1fb660ee501c2e59b5bc
  • v=verifydomain MS=3266658
  • MS=ms32796061
  • loom-verification=6448709232
  • ps-cd-verification=8930f444-c365-450d-ac13-ccfc7e9e96b1
  • google-site-verification=HHtDnGSyvhI4XHIIo0DbxJoJKZEt2swDvUVQ6TbeYX8
  • globalsign-domain-verification=fjJGuQ9iIL4t6JHF79Rpl4aWkus2YqoRARudIKwp76
  • _globalsign-domain-verification=l8maMumukHEsf48zQDRNXnT0mI_RmaTEmx6FylNwu_
  • google-site-verification=q4uvG63gGYbngxx66-3BChvZlYJUmWq8kfKZCXoBov8
  • make-domain-verification=ab1001ef-d437-4003-949c-29afd2e860eb
  • airtable-verification=776fcce162c1ae59a56557bb3b9f6eb8
Cloud / SaaS Services Detected
Apple Atlassian Microsoft 365 Miro