HomeSecurityTurkdef Ops interview: The Turkish hackers who attacked Greece!

Turkdef Ops interview: The Turkish hackers who attacked Greece! [Updated]

A global exclusive on SecNews is the interview with the Turkish hacking group Turkdef Ops, which consists of aspiring hackers with knowledge that allows them to execute successful and powerful hacking attacks.

Turkdef Ops has counted several hacking attacks since its founding, with some of them being named the Sea Turtle campaign by foreign security experts and the global media.

Turkish hackers answer the questions of the SecNews editorial team, revealing interesting information about the group and its activities, which has a worldwide reputation and many security experts are trying to analyze their campaigns.

Among other things, the Turkish hackers refer to the critical state infrastructure and services of Greece that they have breached, the way they organize their operations, what their goals are, and what their opinion is of Greek hackers and the level of security of Greek infrastructure.

Turkdef Ops interview: The Turkish hackers who attacked Greece! [Updated]
Turkdef Ops interview: The Turkish hackers who attacked Greece

One of the Greek targets was the Greek Internet Name Registry .gr, which suffered an attack on its information systems in April 2019.

According to information that cannot be disputed (and cannot be shared), Turkdef Ops has also gained unauthorized access to other gTLDs (Top level Registries) of European countries and their counterparts in the Middle East. This allows them, under the conditions listed above, to redirect any domain they want from the targeted countries to websites of their own choosing!!!

This was also done against Greek targets in April 2019, when the Ministry of Foreign Affairs, the Maximos Palace, the Ministry of Citizen Protection and the National Intelligence Service were targeted. The data intercepted at that time (via DNS redirection) was minimal (since the attack lasted less than 24 hours) and mainly concerned passwords for webmail services and electronic mail.

Additionally, in the interview given by Turkdef Ops, they openly expressed their opinion about Anonymous Greece.

Hackers with high expertise provide answers that will impress but also alarm the Greek public!

Turkdef Ops interview: The Turkish hackers who attacked Greece! [Updated]
Turkish hackers against Greek infrastructure

–The interview follows–

How would you like to be called? Do you have any nicknames?

We do not use our real names publicly. In this interview, we are: LinuxLov3r, ZeroTolerance, Bozkurt34 and fl0ry. However, you can refer to us by our team name, Turkdef Ops.

Many people don't know your story. When did Turkdef Ops start? There is no public information about the founding of your group.

In fact, we started hacking to escape a monotonous lifestyle, to have fun and have fun.

 This led to our acquaintance. Since we were acting together, we decided to form our own team, Turkdef. Each member of Turkdefops has his own area of ​​expertise, and together we are the best team in defacement.

Bozkurt34 is an expert in phishing , LinuxLov3r has experience in DNS attacks, ZeroTolerance is an expert in database attacks , and finally, fl0ry is an expert in web application vulnerabilities.

Apart from Turkdef Ops, we have very ordinary lives. School, family, girls, sports, friends, etc.

Turkdef Ops interview: The Turkish hackers who attacked Greece! [Updated]
Turkdef Ops interview: The Turkish hackers who attacked Greece

How easy/difficult is it to communicate securely with each other?

We communicate via WhatsApp. Most of the time we choose audio messages.

Has Turkdef Ops ever been hacked?

Yes, some members of the group have been targeted by (amateur) hackers in the past. Others have also been infected with malware. In both cases, however, these were not successful attacks.

Does your group act on your own initiative or are you funded by a government or private entity?

No, we act for ourselves. We do not seek money or sponsors for what we do. In fact, what we gain each time through attacks (as experience) is greater than money.

What is the main goal of your action?

We are not kids trying to get attention. What we are trying to achieve is for the world to see how the world's largest companies and organizations are failing at security.

Have you targeted any other critical infrastructure in Greece, besides ICS FORTH and Toyota Greece?

Yes, in the past we have hijacked some Greek ministries by attacking the Greek DNS. The authorities did not hide the truth but admitted through a statement that they have been the victim of a hacking attack. Obviously, they still have not taken the necessary security measures. Our attack was discussed a lot in the media.

Can you share with us some details (non-confidential) about how a successful large-scale attack like the one you achieved on ICS FORTH is possible? Were there sql injection vulnerabilities, zeroday exploits or some other ways (loopholes) to achieve such an attack?

There is always a vulnerability in every system, which most of the time you overlook. But the fact that we overlook it does not mean that it does not exist. We base every detail, we consider every possible possibility before we attack. Regarding ICS Forth, we exploited several vulnerabilities. We used several bugs.

Our initial target was Volkswagen.gr. Since we did not find any vulnerability in Volkswagen Greece, we decided to go a step further and gain access to the domain from the Greek DNS panel.

In about two weeks, we gained access and the ability to modify the DNS and domain records in the Internet Name Registry .gr and .ελ. We'll tell you a secret, we didn't use it, but there are still Command Injection and LFI vulnerabilities in ICS Forth. Don't believe us? The image below confirms it.

Turkdef Ops interview: The Turkish hackers who attacked Greece! [Updated]

How would you describe the level of information systems security in Greece? Is Greece an easy target?

The level of Greece is average and is an easy target for a talented hacker. We would rate it 5/10

Turkdef Ops interview Turkish hackers Greece
Turkish hackers: “Internet security does not exist”

 Have you ever encountered any Greek hacking groups during your attacks?

Anonymous Greece. We probably wouldn't call them hackers. They're pathetic. They have no web hacking skills, only TCP/UDP DDoS.

 Even when they provoke us, they have childish gestures. So, we hacked Toyota Greece and within an hour we had information from 50,000 Greek citizens in our hands. We hope they understood what is considered real hacking by professionals. Good job, right?

Ultimately, Greece is your main target? Are there other targets on the Turkdef Ops list?

We choose targets that we find interesting. It is not our style to specifically target a country. The reason we organized a cyber-attack against Greece is to teach a lesson to the children we mentioned above.

Can you share with us some of your future attacks (by attacks we mean categories or sectors such as telecommunications companies, oil companies, shipping companies, government agencies, etc.)

Among our future goals, there is a famous technology website, a country domain management system, and a world-famous person. These goals may change. Keep following us 😉

Have you ever been targeted by the authorities? If so, what hacking attacks triggered this?

We once attacked the website of a Turkish political party that had a lot of voters. We were still teenagers at the time. Through a SQL Injection vulnerability, we gained access to the phone numbers of several MPs. We added them to group chats on WhatsApp and made fun of them.

Due to the cyber attack, the political party website was not accessible to the public for 4-5 days. Later, the Turkish police arrested us and interrogated us one by one and searched our computers. Since we were minors, they simply told us not to do it again and finally let us go.

Apart from that, our attacks have not bothered the authorities. By the way, a friend named Hasan was stealing credit cards with zerodays that he found on the Deep Web. He bought computers and phones with the stolen credit cards. At the time, they were worth 20 thousand Turkish liras.

Turkdef Ops interview Turkish hackers Greece
Turkish hackers and authorities

In the possibility of a future cyberwar, will Turkdef participate? Do you think you will be a difficult opponent for those who will face you?

Hacking is a chaotic world. We can't claim to know everything. But we believe in ourselves, we specialize in every area of ​​hacking. We strive to be the best.

In your experience, what is the most dangerous hacking method these days?

According to us, ransomware attacks are becoming more and more dangerous these days. We know some of the groups that use this method. We are able to identify which group is behind an attack just by looking at the ransom paper they gave to the companies. It is becoming especially difficult for large companies. They have to pay the hackers or their business will stop operating. A very high price.

Turkdef Ops interview Turkish hackers Greece
Dangerous ransomware attacks

What are the three most important steps users should take to avoid a hacking attack?

We are not a search engine like Google. We are not going to give you advice like everyone else does, “use strong passwords, don’t give your passwords to anyone, blah blah blah”.

The average internet user thinks they are 100% safe with a few antivirus programs and going to a security company. Security doesn't work, believe us. No one can be safe in three steps.

In the underground forums we participate in, you can find millions of zombie computers with viruses. You may find that access to NASA and Interpol. The US military database is up for sale. Most importantly, viruses are being sold that can exploit browsers. Have you ever heard of them? As soon as you click on a link that looks normal, your computer is compromised. Your antivirus program cannot block it. That's all we want to tell you.

Turkdef Ops interview Turkish hackers Greece
Turkdef Ops interview: The Turkish hackers who attacked Greece

Would you like to send a message to SecNews users or say something that hasn't been said in our interview?

We want to send greetings to our brothers: intrusive, pasa, exiqor, seeul8er, Injector_pCa, alfa, Ulukurt, AgonGYS, l0ryz.

SecNews is an impartial and objective news website specialized in cyberattacks and information security and will always give voice to groups or personalities that are of interest to our users. The opinions expressed in the interview reflect EXCLUSIVELY the views of Turkdef Ops.

We warmly thank LinuxLov3r, ZeroTolerance, Bozkurt34 and fl0ry for the answers they gave us and their willingness to respond to the Greek public for their much-discussed attacks on critical state infrastructure and services in Greece.

Learn more about Turkdef Ops on the website and Twitter account.

[UPDATE] Regarding the Screenshots attached to the article and taken from the hackers' profile [which currently remains inactive immediately after publication], individual Turkish users/readers who contacted the editorial team report that they are fake screenshots and that the hackers altered the screenshots they posted. SecNews broadcasts the interview as-is without cuts so that it can be evaluated by readers. The authorities must confirm what the hackers say and whether they are fake screenshots or real since the screenshots in question had been uploaded to the public profile on Instagram and were available to the public. In addition, we mention that at the time of the update to this article, the profiles of Turkdef Ops are inactive.

Turkdef Ops interview Turkish hackers Greece
Website: Turkdef Ops

Turkdef Ops and SeaTurtle campaign

Many of the attacks by Turkdef Ops claim to have been carried out as part of the Sea Turtle campaign, a global hacking campaign that has alarmed security experts and major media outlets worldwide.

The Sea Turtle campaign has been detected since January 2018, with primary targets being public and private government entities. Its hallmark is DNS hijacking attacks.

According to data so far, attacks have been detected on approximately 40 organizations in 13 countries.

Turkdef Ops interview Turkish hackers Greece
Sea Turtle campaign and Turkish hackers

Attackers are highly organized and use sophisticated methods that give them access to sensitive networks and systems. DNS hijacking attacks redirect users to malicious websites by modifying DNS name records or server settings.

The campaign appears to target two categories of victims. The first category includes national security organizations, foreign ministries, and energy-related organizations. The second category of victims includes DNS administrators, telecommunications companies, and internet service providers.

It is worth noting that the attackers' first target is third-party companies (providers), which offer services to their main targets (third party or outsource).

Learn more about the SeaTurtle campaign here.

Powerful attack by hackers on the Greek .gr Domain Name Registry!

In April 2019, the Registry of Domain Names with the [.gr] and [.ελ] endings suffered an attack on its information systems. This attack is part of a broader effort, at an international level, to negatively affect the operation of Internet Registries. The investigation of the incident did not reveal any evidence of a leak of personal data.

Turkdef Ops interview Turkish hackers Greece
Internet Name Registry .gr and .ελ

As part of the effort of the Registry of domain names with the ending [.gr] and [.ελ] to ensure the integrity of its data, as well as to protect the beneficiaries of the internet names, it proceeded to immediately change the authorization codes of the domain names [.gr] and [.ελ].

Learn more about the attack here.

Other attacks on critical infrastructure in Greece:

Did Turkish hackers attack a server of the Greek Parliament? [UPDATED]

Turkish hackers: Attack on websites of the Foundation for Research & Technology (FORTH)

Hacker wipes out a professor's bank account in Crete

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS