Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Discovered 2025-10-03 15:41 UTC
Est. attack date 2025-07-04
Country MX

Description:

[AI generated] Aeroméxico is Mexico's flag carrier and a major international airline. Established in 1934, it operates scheduled services to more than 90 destinations in Mexico; North, South, and Central America; the Caribbean; Europe; and Asia. Its main hub is in Mexico City, with secondary hubs in Guadalajara and Monterrey. Aeroméxico is known for its high-quality services, including in-flight entertainment and meals.

Infostealer activity detected by HudsonRock

Compromised Employees: 14

Compromised Users: 15743

Third Party Employee Credentials: 177


External Attack Surface: 107


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • abusecomplaintsmarkmonitor.com
  • admindnstinations.com
  • whoisrequestmarkmonitor.com
MX Records
  • mxa-00117101.gslb.pphosted.com. Proofpoint
  • mxb-00117101.gslb.pphosted.com. Proofpoint
TXT Records
  • google-site-verification=ulmdj7tHwgpDnMZ27-UwcEc2csaVb4yHakW-ldqBxdQ
  • v=spf1 include:mailgateone.aeromexico.com include:spf.protection.outlook.com include:_spf.aeromexico.com include:spf-00117101.pphosted.com include:sparkpostmail.com include:rp.oracleemaildelivery.com include:spf.sabre.com -all
  • google-site-verification=jqOLypVj24Orohl8_f9hD4ypwRwkeZ8KY8XAposh1aU
  • _ez2cj358nefsr6j6dmc7j050r1gkaz9
  • MS=ms67139787
  • _globalsign-domain-verification=6wfBI6Os4g25rvNo1kaxA92bvP5e4RHP9iyvGHlrSH
  • google-site-verification=6O2g2M8LHq44dMlFv0eunxcMxXRPUbNM66piIYO8vr0
  • openai-domain-verification=dv-pTvjcXzv1Nvy5pENE22AaY4a
  • facebook-domain-verification=cze1ni30oh2d5121j278tqym2ahcc7
  • DirectFedAuthUrl=https://sso.skyteam.com/app/lams_entraidauthentication_1/exki1nw5b7Ankn4wZ417/sso/saml
  • rxb6fsktlq2zcvzxzf4v9tdf64sqw1qh
  • google-site-verification=KtIcMo2l1cf7DnU2hGu5pLrbzqNGEPMD43IyvDk1rB4
  • miro-verification=c6a92953e9be3edc9b3b4f386fb662816e878a23
  • zspl00wy51bglsk4kk9gqx5464dbl9pp
  • apple-domain-verification=qPA83WwkUUovmGU5
  • globalsign-domain-verification=efe2f8a4c1dd0398a6d20ea6fdbaf8ed
  • dtm-domain-verification=ebr1VFa6VZQo6eC1MD2316ICGoFU012T6WhbS5QO_cY
  • _globalsign-domain-verification=gxDZTHFxmg56fm5vMzUelQcu7UZSnIYHxvoZHAUJYR
  • MS=C1053E47608FC4A26CB780C21700A86734E5A230
  • _globalsign-domain-verification=JISMYicSjYQMSVse8RQebKVLppLFX3ZBkrIedcrcmC
  • google-site-verification=8S0jzpBH6RIgb9WBZfPuuYihWTJifBYuYxcrk-fv5vg
  • _globalsign-domain-verification=zkyB5C1cq-PiUv2uR0BxA5ebSSkMp0sO5ji-5EdgOf
Cloud / SaaS Services Detected
Apple Global Sign Microsoft 365 OpenIA Miro Proofpoint

Leak Screenshot:

Leak Screenshot