HomeRapidalertAlbanian hackers attack JP-Avax!

Albanian hackers attack JP-Avax!

Albanian hackers appear to have gained access to the internal network (Intranet) of the company JP-Avax!

An attack by Albanian hackers with a website alteration and a message posted against the construction company JP-AVAX took place in recent days!

JP-Avax

J&P-AVAX Group S.A. is one of the most well-known construction groups in Greece. The Group includes, more specifically, companies with 7th, 6th, 4th and 3rd class construction licenses for public works, as well as companies with complementary activities, such as Real Estate, Prefabrication, Vehicle Technical Inspection Centers, Parking Construction-Management and Operation, Facilities Management, E-Commerce, Project and Contract Management, Wood Impregnation, Exploitation of Renewable Energy Sources, Development of Wind and Photovoltaic Parks, etc.

The hacking group AHT-Crew, calling itself Albania Hacker's Terrorist , gained unauthorized access to the construction company's website, https://intranet.jp-avax.gr , where it posted a corrupted message. As is evident from the website's hostname, it is POSSIBLY an internal server for use within the company's internal network (Intranet).

You can see the relevant message posted below:

jpavax

The message from the Albanian hackers (whose aliases are Dr.Injection, MR.VIRUS, Individ^H4ck and Generaal AI) is of a purely nationalistic nature. The hackers appear to have exploited an operating system vulnerability (the server they accessed is an old version of IIS/6.0), which likely led to access to the server and posting a message.

Our assessment is that this particular group does not have high training or expertise and the attack was carried out due to deficiencies or forgotten upgrades to the company's operating system!

This is not the first time the company has been targeted by Albanian hackers. In 2012, a subsidiary of JP AVAX was targeted.

From the altered JP-Avax, it cannot be ascertained with certainty what data the Albanian hackers may have stolen, as well as whether the server was dual-homed, that is, it had simultaneous access to an internal data network and the Internet.

hackers

But it is certainly something that the responsible administrators must IMMEDIATELY investigate in order to verify the type of data that was targeted, the origin, and the type of attack.

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS