Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

NATO Leak - 1

nato.int

Discovered 2023-12-08 08:42 UTC
Est. attack date 2023-11-26
Duplicate Entry
This victim has been identified as a duplicate of another entry in our database. However, this may not always be the case: the same organization can be targeted multiple times by the same or different ransomware groups, which may result in separate legitimate entries. Search for related entries

Description:

intergovernmental, military alliance

Infostealer activity detected by HudsonRock

Compromised Employees: 56

Compromised Users: 842

Third Party Employee Credentials: 35


External Attack Surface: 136


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • nraddincia.nato.int
  • dmzsupportncia.nato.int
MX Records
  • mailstream-eu1.mxrecord.io.
  • mailstream-east.mxrecord.io.
  • mailstream-central.mxrecord.mx.
  • mailstream-west.mxrecord.io.
TXT Records
  • v=spf1 redirect=_spfnato.nato.int
  • _globalsign-domain-verification=Vn9nwDBdNQuJDGKckbKdOSB2b7N-qBgjlah10zidOr
  • google-site-verification=1nd__5b63e-sQsJy9eA4RSK8A0Pdjj7tHHUplooQ0Y8
Cloud / SaaS Services Detected
Global Sign

Leak Screenshot:

Leak Screenshot