HomeSecurityTwo teenage hackers of the "Greek Electronic Army" are revealed

Two teenage hackers of the "Greek Electronic Army" are revealed

Twomembers of the “Greek Electronic Army” group recently identified by the Electronic Crimes Enforcement Network speak to “Kathimerini”

Greek Electronic Army - Members of the Greek Electronic Army are revealed

He had warned his mother that this day would come. Then, on June 11, 2015, just before ten in the morning, a prosecutor and seven plainclothes police officers knocked on his door. “You know very well what you’ve done,” they told the 16-year-old who had just woken up. They asked him to open the only computer in the house, which was in his room. They searched specific folders, took photos of the desktop with a cell phone, removed the hard drive, and asked the teenager to get dressed and follow them.

A short time later, while waiting on the 13th floor of the Attica General Police Headquarters, the 16-year-old was observing every move of the members of the Cybercrime Unit. He was so focused that a police officer teased him by saying: “He’s hacking us with his eyes.” On the Internet, the student was known by the nickname “Oxyg3n.” According to the police, he participated in the hacker group “Greek Electronic Army,” whose members allegedly carried out cyberattacks on hundreds of websites of public institutions and private companies. “They were polite. But they told me that it is illegal to hack websites without authorization,” the student says today. “We had made a fuss with our actions.”

Greek Electronic Army - Members of the Greek Electronic Army are revealed

In the months that followed, some of his friends feared that they would be identified by the authorities. One of them recalls that every morning he waited anxiously for his turn to be identified. The next identifications of members of the group were finally made on January 18 and 19, 2016, in Thessaloniki, Patras, Karditsa, Didymoteicho and Attica. In one of these, according to the Police, a 36-year-old was found in possession of 1,642 folders with Greek and foreign websites that had been scanned to identify security vulnerabilities. The 36-year-old was also the only alleged member of the group who was arrested in the context of the raid.

The last member was found on January 27, at his school. During one of the breaks, the 17-year-old, known online by the nickname “Shadow Angel,” was informed that his father was waiting for him outside the principal’s office. They returned home together and in the living room sat a prosecutor with police officers from the Cybercrime Investigation Unit. “They hadn’t entered my room. They were waiting for me to come so they could open the computer in front of me,” says the student. The police have filed a case file with the Athens First Instance Prosecutor’s Office. So far, no charges have been filed.

 

The meeting

We met two of the group's members in Western Attica and in central Athens. They talked about their relationship with computers and their electronic attacks, which they sometimes treated as a game and sometimes as a challenge. "K" does not publish their real names, nor the exact areas of their residence. After all, the two hackers are still students, 2nd and 3rd year of high school, although the police presented them as older in their announcement.

Kostas wears glasses and has not yet grown a pubic hair on his face. Since his early years in high school, he has been searching the Internet for hacking tools and trying to study programming languages. “I am a studious person,” he says. “At school, I would crack the Wi-Fi password and hand it out on slips of paper to students so they could have free access.” Following instructions he found online, he created a program in the Visual Basic programming language that could extract passwords from his classmates’ Facebook accounts. Later, he switched from the Windows operating system to Linux, scanning websites with special software to discover vulnerabilities. “I never did any damage. I could have altered them, but I didn’t want to. Nor did I have any financial benefit,” he says. “I felt like I was winning a prize when I gained access. I did something that not everyone else could do.”.

Greek Electronic Army - Members of the Greek Electronic Army are revealed

The idea to create a group came about when he himself was hacked by an 18-year-old. “He gained access to all my accounts and closed them. He had caught me sleeping. It seemed like he had hit me using a computer in Pakistan, while he was in Athens,” recalls Kostas. The two teenagers met and gradually the group “Greek Electronic Army” was formed.

The number of its members was not constant and not all of them revealed their names. They often shared only their online nicknames such as “Massive Distraction”, “Surprised” and “HackoManGR”. Some communicated via IRC (Internet Relay Chat). But most preferred Skype. They spoke without using a camera and some altered their voices on the microphone (Kostas says that to this day he covers his computer camera, as he is afraid that a hacker might activate it without his knowledge).

Greek Electronic Army - Members of the Greek Electronic Army are revealed

To control the number of new members, they had registered their own domain name and were testing anyone who wanted to join. "We had created our own website with vulnerabilities and we wanted to see if they would discover them. We were measuring their capabilities. We cut people off because they knew absolutely nothing," says Antonis, the second member of the team who spoke to "K".

 

The government

One of their breaches occurred eight months ago, on a website belonging to the Ministry of the Interior. However, as it was later determined, it was not serious. The hackers had not gained access to sensitive data. After all, the specific page does not handle confidential information and is mainly used for posting texts. They could have falsified its content (an attack known as defacement), but they did not.

The websites of public organizations have always been the target of cyberattacks. For example, on February 8, 2001, the hacker with the nickname "external" had defaced the website of the Ministry of Agriculture by posting the message: "you can't (...) protect an NT4 (operating system) - and my grandmother can do it!". That was the fifth attack on a government website since the beginning of the year. Accordingly, in 2000, the Ministries of the Interior and Foreign Affairs, the General Secretariat of Public Administration, and the website of the Parliament had been selected as targets, among others.

It seems that the members of the “Greek Electronic Army” group randomly selected their targets, or did not always know which organization or service a particular website belonged to. They often simply focused on any addresses that ended in gov.gr in an effort, they say, to show “how vulnerable e-government is.” “Maybe it was a Saturday night, we weren’t doing anything special and we said, ‘Let’s go for some government stuff, guys?’” says Kostas.

One of the forms of attack they appear to have used is called SQL Injection. As Konstantinos Patsakis, a lecturer at the Department of Informatics at the University of Piraeus, explains to “K”, this is one of the most common online attacks in which hackers try to exploit incomplete programmer controls. Using various tricks, hackers attempt to gain access to a website’s database that requires a username and password. “Unfortunately, most people do not take the issue of network security seriously,” says Mr. Patsakis.

“Oxyg3n” chose the website secnews.gr to publicize the attacks, as do other representatives of the new generation of Greek hackers. The “Greek Electronic Army” proved their words by sending screenshots (photographs of the computer screen) and explaining what vulnerabilities they had discovered. This was, on the one hand, a way to showcase their capabilities and, on the other, to inform organizations and companies about the security gaps they may have. “We often receive corresponding evidence of attacks and vulnerabilities,” says Konstantinos Vavousis, head of the editorial team of secnews.gr. “In some cases, these messages come from teenagers.”.

 

And update

Some teenage hackers in the group were trying to communicate directly with public bodies and companies. Last June, before the Cybercrime Prosecution Service found Oxyg3n’s house, Antonis sent a message to an Athens museum. “I would like to inform you that I scanned your website and it has a Cross Site Scripting vulnerability. It is a very common type of vulnerability and allows a malicious user to insert code,” he wrote. The museum’s IT manager confirmed Antonis’ message to “K.” “He contacted us in good faith and we did not need to notify the Prosecution Service. We are currently building our new website, so we did not need to change anything,” she says.

Kostas claims that he did not bother to cover his electronic tracks. He posted the group's attacks on a Facebook page where he also maintains a profile under his own name.

"I wasn't hiding, I didn't think there was a reason. My goal was to prove if a website is not safe," he says.

In July 2014, on the occasion of the arrest of two other hackers who were accused of infecting computers and using them to produce the electronic currency bitcoin, 19 Greek computer science professors in a letter called on young people not to “be carried away by the sirens of the ‘easy solution.’” “Most likely, they will not lead them to a safe professional harbor, but rather to entanglements with the Law,” they wrote, adding, addressing their students, that “they have rightly chosen the difficult path of education for their professional recognition.”.

Legal security vulnerability checks are carried out by executives of specialized companies with the consent of a website's administrators. Mr. Patsakis says that today several penetration testers working in Greece are mainly engaged in auditing the infrastructure of companies in Arab states (Qatar, United Arab Emirates).

The two teenage hackers who spoke to "K" say they want to study Computer Science and then work professionally in network security. One is a student at a Vocational High School and the other will take part in the National Examinations in a few months. Mr. Vavousis emphasizes that there should be special care for children like them. "Someone needs to show them the right path, to cultivate and develop their knowledge and not to be exploited by cunning people.".

Next April in Athens, for the first time, as part of the Infocom Security conference (a cybersecurity event), a two-day hacking competition (Ethihak Contest) will be held in a controlled environment, with simulated cyberattacks. The number of participants has reached 100, of which 15 are minors. “Some of these children will come to the competition with their parents,” says Mr. Vavousis.

Source: kathimerini.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS