High-profile cyber attacks have been carried out in recent hours by Turkish hackers and cyberspies from the AKINCILAR group on Greek critical infrastructures and ministries!

According to reports found by SecNews editors on foreign information exchange forums, unknown hackers (possibly guided by government agencies of the neighboring country)proceeded to add/alter central and internal websites, while simultaneously posting messages. The Turkish hackers carried out their mass attacks as early as December 24, 2018, while the authorities seem not to have detected the malicious attacks until the moment these lines are written.
The websites of Greek ministries and services appear to still be under the control of Turkish hackers from AKINCILAR. The preparatory stages of the attacks against Greek targets by the Turkish hacker group AKINCILAR appear to have begun on 24/12/2018.
The chronicle of the attack by AKINCILAR
Turkish cyberspies initially carried out attacks on smaller targets to assess the vulnerability of systems, before making their presence known with obvious alterations to websites. The initial target was the website https://dimosio2020.gov.gr, which is essentially a public information website of the National Strategy of the Ministry of Administrative Reconstruction.
Subsequently and unknown how (possibly using codes obtained from the first target) the cyberspies successfully targeted the following:
- https://sports.ert.gr [ERT Sports News Website]
- https://int.ert.gr [ERT international news website]
- https://proskliceis.ert.gr [ERT content website]
- https://socialgrowth.ert.gr [Currently out of service]
At the same time, website corruption was observed on the websites of the Ministry of Interior, specifically:
- https://websdit.ypes.gr [THISEAS System Public Private Partnerships]
- https://efc.ypes.gr [European Programme Europe for Citizens 2014-2020]
- https://eyc2013.ypes.gr [European Year of Citizens 2013]
- https://gis.ypes.gr [Integrated Geographic Information System GIS/YPES]
Turkish government hackers appear to have identified weaknesses in the website servers, which gave them the ability, using specialized tools (which do not require special knowledge), to gain full access with administrator rights to the servers and add the altered content.

The following photo/message was placed on all of the websites that were altered:

This is a barrage of attacks on high-profile targets that directly or indirectly concern the Greek government.
Currently, anyone visiting some of the mentioned websites sees the above content. The image of the tank is accompanied by the phrase "One night we can come", written in Turkish, with threats of a new disaster.
"From here, we warn those who behave out of bounds and remind you that the history of the events of 7/09/1922 may repeat itself," they specifically write in the photo.
Who are the Turkish cyberspies AKINCILAR?

The AKINCILAR hacker group, according to information available to SecNews, is reportedly a small and agile group of cyber warriors (Akincilar Cyber Warrior), directly related to the President of Turkey, Recep Tayyip Erdogan. The group, who describe themselves as “Pro-hackers loyal to Erdogan”, are reportedly receiving orders to carry out cyberattacks against high-profile targets on the orders of individuals who are in the narrow core of the associates of the President of Turkey.
Most of the time, their attacks are guided by political developments concerning the neighboring country as well as events concerning its foreign policy and diplomacy. In addition to website defacement attacks, this group carries out denial of service (DDoS) attacks and mass data exfiltration attacks.

The AKINCILAR group is the specialized cyberattack team of the Turkish Hacking Group Cyber Warrior (TW). The group was founded in 1999, with its first serious cyberattack taking place in 2003, when they carried out a massive attack on 1500 American websites, altering their content in protest of the American invasion of Iraq and the arrest of a Turkish agent in Northern Iraq, who was interrogated by the American military.
The group has sub-groups regarding strategy, intelligence, research and development, and logistics. However, their specialized group for cyberattacks is Akincilar. The sub-group mainly targets government websites & networks while having the ability to develop its own cyber-weapons or improve others (from third-party manufacturers). In addition, they have also organized a Cyberwarfare Academy where they provide online-training to their new members!
From time to time, in the private information exchange forums they have, they have mentioned hacking methodologies , specifically a) how to hack into gmail accounts b) how to carry out attacks on satellite and aviation systems (!).

The same group of Turkish hackers, associated with the president of Turkey, had claimed last week that they had taken down the website of the Ministry of Foreign Affairs and gained access to the e-mails of diplomats, something that was not confirmed by the Greek side, while a statement was issued by the Ministry of Foreign Affairs.
However, from the relevant material that was posted publicly and after studying it, despite the denials of the Ministry's executives, we found that the Turkish hackers had indeed gained unauthorized access to the email accounts of diplomats and employees of the Ministry (specifically to the Zimbra server).
The assessment of the SecNews technical team is that there is likely to be an active Phishing attack against government critical infrastructures at this time with the aim of extracting passwords from officials or employees of Ministries & Organizations.
The goal of Turkey's cyberwarriors is to provoke a reaction from the Greek government, following media pressure and fear of nationalist outbursts, while at the same time sending a strong message about the cyberwarfare capabilities they have for both espionage and sabotage.
Immediate Actions by the Authorities – The attacks have not been noticed!

The information systems that were targeted, as we have found, are within the Syzefxis, which serves almost the entire Public sector, structured (at least theoretically) in accordance with all modern security requirements.
As we have mentioned many times in the past, Syzefxis as a provider DOES NOT essentially bear the responsibility of managing the servers of each entity but simply provides the means of access. Comprehensive care should be taken to ensure that at least the entities that manage sensitive personal data are protected, drawing on expertise from Syzefxis management executives who are appropriately trained and responsible for security issues.

The responsible administrators of the targeted websites must IMMEDIATELY take the necessary measures and repair at a technical level the weaknesses used by the hackers to gain unauthorized access. The servers that appear to have been subjected to the cyberattack must be placed off-line and thoroughly analyzed for digital evidence, in order to identify the exact way in which the intrusion was carried out and to expel the attackers in case they have penetrated other servers in the network under investigation.

It appears that the attackers exploited a weakness in the CMS management systems that the websites were created in. However, specifically for the Geographic Information website of the Ministry of Interior, it must be investigated whether data containing personal data of employees or citizens.
Additionally, our assessment is that the competent bodies and the Personal Data Protection Authority mainly regarding the GDPR legislation, since it has not been clarified whether the hackers gained access to the personal data of employees or citizens!!!

We call on the competent IT services of the competent Ministries and Organizations that were targeted by the AKINCILAR hacker group to take immediate measures and regain access to the servers, as well as to provide information via press release if personal data of employees or Greek citizens was leaked!
Stay tuned to SecNews, the reliable 24-hour information website on information security issues and cyber breaches.
