HomeRapidalertNSA cyber-weapons on high-profile Greek targets!

NSA cyber-weapons on high-profile Greek targets!

The installation of the surveillance software on high-profile Greek targets was carried out either by the NSA's specialized team or by hackers who used the tools from the latest ShadowBrokers leak.

nsa
Last week, the tools of the NSA's hacking operations against global targets of interest to the said secret service were leaked online by the now-infamous Shadow brokers. The leak was made available online in the form we see below, where anyone could freely download them:

NSA cyber-weapons on high-profile Greek targets!

The leaked NSA arsenal of cyber-weapons includes several exploits (for Microsoft Windows, Lotus Notes, MDaemon Webadmin, IIS, Solaris systems, and Microsoft Exchange) as well as additional tools written in Python.

NSA cyber-weapons on high-profile Greek targets!

These tools (Fuzzbunch, Eternalblue, Doublepulsar, Danderspritz) constitute specialized software with extremely impressive capabilities (ed. some call it the NSA's Metasploit) that has been used by NSA hacker-agents against the infrastructure of governments, companies and organizations.

NSA cyber-weapons on high-profile Greek targets!

 

THE RESEARCH

SecNews researchers conducted a thorough study this week regarding the NSA leaks from Shadowbrokers. As it has been known, the NSA Backdoor has been found installed in many countries so far (on thousands of computers & servers). A breakdown by country can be seen below:

NSA cyber-weapons on high-profile Greek targets!

However, the objective of SecNews' investigation, taking into account the importance of the leaked data, was to identify companies or networks exclusively in Greek territorythat have fallen victim to malicious activity or use of NSA cyberweapons..

In other words, we investigated, in combination with the leaked NSA arsenal, using their particular digital characteristics, which Greek IP addresses can be identified as having NSA cyber-weapons installed!

The procedure was carried out with the following steps and took 3 days.

  • As a first step, we scanned the Greek internet for publicly exposed SMB (Port 445) & Remote desktop (RDP Port 3389) services.
  • We detected 1086 IP addresses with the SMB service enabled on the internet
  • We detected 4263 IP addresses with Remote Desktop service enabled on the internet
  • Then, using appropriately parameterized scripts such as Mass-scan, detect_doublepulsar_rdp&smb (Python) and the files leaked by the NSA, we located where the cyber-weapon was installed.

The results-final findings are shown in the table below. We have hidden all the IP addresses that were identified with a red frame, to protect the targeted companies-organizations. This makes it impossible for a malicious user to use the relevant cyber-weapon for their own benefit.

NSA Greek Targets

CONCLUSIONS

According to the findings, the NSA remote access software was found installed:

  • Within the network (AIA-Cust3-Infr) of Eleftherios Venizelos Airport. We are not able to know whether it is an infrastructure network of the Airport or a third party company to which the airport provides the access backbone.
  • On a server at the SKAI television station that is accessible from the internet (ed. we hope not to change the results of Survivor ;))
  • On a Vodafone server or a company contracted with it.
  • On a server in the internal management network (Internal Network Management) of the company Interworks Cloud (interworks.biz, webserve.gr). It is worth mentioning that the Business marketplace of the telecommunications company Wind (windbusiness.com.gr) is also located in the same IP class.
  • To a customer with a DSL/VDSL connection of the company OTE/Cosmote (we do not know if he is a corporate customer or a home user). However, it does not appear to have any correlation with the critical infrastructure of OTE/Cosmote.
  • Within the server of the company SYKARIS (possibly Graphic Arts)
  • Within the server of the company MELKA (possibly a construction company)
  • At a terminal/server of the Civil Engineering department at the Aristotle University of Thessaloniki
  • On a server/terminal at the TEI of Epirus in the management VLAN.
  • At the University of Thessaly on a user terminal within the University (possibly a remote DSL connection).

NSA cyber-weapons on high-profile Greek targets!

From our research we found that Doublepulsar has been installed in the above. Doublepulsar allows the attacker to install any software they want, without being detectable in the form of a DLL.

It is clear that we cannot know whether the installation of the surveillance cyberweapons was done by the NSA or by third-party hackers who used the arsenal after the Shadowbrokers leak. What is certain is that the targets we mention should IMMEDIATELY check their systems (and especially if the affected systems “touch” internal networks.

NSA cyber-weapons on high-profile Greek targets!

The same process that we applied during our research on the Greek Public internet can be applied to internal servers to check if there are any cyber surveillance software installed. The targets mentioned above must carry out IMMEDIATE digital analysis checks to identify exactly what has happened to the above servers.[su_divider top=”no” divider_color=”#13471e” margin=”10″]1) Profile full of spelling errors.[/su_divider]

SecNews researchers are at the disposal of administrators or legal representatives of the mentioned companies, organizations & entities that appear to have been targeted to provide additional information regarding the details of the detection as well as the method of additional checks on the internal network if the competent administrators determine that they have been affected and to what extent.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS