HomeSecurityTop domains in Greece hacked by state hackers

Top domains in Greece hacked by state hackers

State-sponsored hackers breached ICS-Forth, the organization that manages Greece!

domain

ICS -Forth (Institute of Computer Science of the Foundation for Research and Technology), publicly admitted the security incident via an email sent to domain owners.

The hackers behind the breach are the same group mentioned in a Cisco Talos in April, which they named Sea Turtle.

The group uses a relatively new approach to hacking attacks. Instead of targeting victims directly, they compromise or gain access to accounts at domain registrars and managed DNS where they make modifications to a company's DNS settings.

By modifying DNS records for internal servers, they redirect traffic intended for a company's legitimate applications or webmail services to clone servers where they perform man-in-the-middle attacks and intercept login credentials.

The attacks are short-lived, lasting from hours to days, and are extremely difficult to detect due to the fact that most companies do not monitor changes to DNS settings.

Top domains in Greece hacked by state hackers

Reports on the activities of this hacking group have been published by FireEye, Crowdstrike and Cisco Talos. FireEye attributed the attacks to the Iranian government, while Crowdstrike and Cisco Talos have refrained from making any statement about the attacks. The US DHS and UK NCSC have also issued security alerts about the group's new strategies.

The Sea Turtle group typically compromises accounts at domain registrars and manages DNS providers – accounts owned by their targets, who use them to manage DNS entries for various servers and services.

However, now, Sea Turtle has dared to hack an entire service provider to achieve its goal – namely, to modify the target server's DNS server settings

Top domains in Greece hacked by state hackers

In its first report, the Cisco Talos team said that the Sea Turtle group had compromised NetNod, a Sweden-based internet exchange node that, among other things, provided DNS services for ccTLD organizations such as ICS-Forth.

Unfortunately, this time around, for the ICS-Forth attack, the Talos team has no details on what the hackers did on the network after gaining access to its systems. It is also not yet confirmed which domain names the hackers changed DNS settings for, but they certainly maintained access for another five days after ICS-Forth announced the incident.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS