Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks


Group Everest
Discovered 2026-04-20 02:32 UTC
Est. attack date 2026-04-20
Country US

Description:

[AI generated] Frost Bank is a Texas-based financial institution and a subsidiary of Cullen/Frost Bankers, Inc. Founded in 1868 and headquartered in San Antonio, it operates across major Texas cities offering personal and commercial banking, wealth management, insurance, and investment services. As one of the largest independent banks in Texas, it serves individuals, businesses, and institutions within the United States financial services industry.

Infostealer activity detected by HudsonRock

Compromised Employees: 1

Compromised Users: 620

Third Party Employee Credentials: 1


External Attack Surface: 76


Infostealer Distribution

DNS Records:

The following DNS records were found for the victim's domain.

WHOIS Emails
  • domain.operationsweb.com
MX Records
  • mail1.frostbank.com.
  • mail2.frostbank.com.
TXT Records
  • facebook-domain-verification=lf6i3763ga5u6i8qgshvlsq2irgx31
  • hpJZ2Lz0Jjw6jLyvt84bE2u+OFKNCuEFo3gEAaLNT35vdlPhKPMfZpe5hTL7igHMI2Mit2yAsII5wTQnqN/QJg==
  • bPlK9dhmcpGFjFFXoM/vkkPyeArVsctRGEvecFesEzGy1Rzdby/s5HuQn/n495Op
  • atlassian-domain-verification=bPlK9dhmcpGFjFFXoM/vkkPyeArVsctRGEvecFesEzGy1Rzdby/s5HuQn/n495Op
  • v=spf1 include:_spf.frostbank.com include:_bottomline._spf.frostbank.com include:_spf.salesforce.com include:spfhost.messageprovider.com include:_digitalsvcs._spf.frostbank.com -all
  • asv=13463e5b2012a6720d6eaf488fca95bc
  • 185cf514f6cc4e69af538da1a89ada22
  • google-site-verification=RV66LMyDOUQtakYKmW22odhdVezhZSqq4_UTiTv4tkg
  • MS=5BED3FDAFD4FABE05E837A002F529297E886C525
  • docusign=1409ca79-0672-47f8-a09f-84c69c50618d
  • docusign=da5f028e-af76-4816-a7de-fe7355da72de
  • 3hlbhg9mprbvhmsfpn03gspqnq48v60s
  • k1dtnxn1bly49916d9lmbkl3dzdnc02n
  • ZA=3LK8RmgLISCYvPm5bgKQ6w==
  • GnZTASn1/+FifysBW9vZcIeEGguH9o9hBZ4NdsiJOS3vYdEW96mHeKv3XPK/qKgo8Y4B37rr762tpWUol5tKUg==
Cloud / SaaS Services Detected
Atlassian Salesforce DocuSign

Leak Screenshot:

Leak Screenshot