Cybersecurity analysis: Results of research by independent security researchers on the cyberattack in Cyprus Following the recent revelation by SecNews regarding the cyberattacks that were carried out on critical state and private systems in Cyprus by the Turkish hacker RootAyyildiz Turkish Defacer, the independent group of cybersecurity analysts, PROMETHEUS GROUP, published a relevant whitepaper with a thorough study of the incident based on OSINT methodology (Open-source intelligence).
Learn more about hacking attacks:
1. RootAyyildiz Turkish Defacer: Turkish hacker attacks Cyprus!
2. Cyberattack on Larnaca Airport hermesairports.com by RootAyyildiz!
SecNews presents you with a part of the PROMETHEUS GROUP research, which you can find in its entirety here. SecNews is rebroadcasting this research with the aim of safeguarding society as a whole and investigating the recent incidents of breach that took place in Cyprus. PROMETHEUS GROUP, according to their statement, consists of Cypriot independent cybersecurity researchers.
The following are exclusively the findings and statements of the researchers. SecNews broadcasts part of the study, as shown below, without making judgments or altering the content of the research. The study of independent researchers can constitute a technical methodology for investigating corresponding incidents.

Quote from translation of study https://github.com/prometheusgroup/YPAM-CyberAttack/blob/main/Cyprus%20Ministry%20of%20Defense%20Cyber%20Attack.pdf
———————————–Start of Study Quotation——————————–
In the last two weeks, there has been a report of a cyberattack against the website of the Ministry of Defense by a well-known Turkish hacking group. The original news article was published by SecNews.gr (https://www.secnews.gr/331587/rootayyildiz-turkish-defacer-hacker-cyprus/) on March 24, 2021 and included a detailed analysis of the attack, along with photographic evidence of the stolen data.
On March 29, 2021, the website Philenews.com, among others, published an article (https://www.philenews.com/koinonia/eidiseis/article/1157770/prospatheia-epithesis-apo-chakerstin-istoselida-toy-ypam) stating that the attack against the Ministry was successfully blocked and that the Ministry took all necessary measures to prevent similar future actions.
Some will argue that Cypriot politicians are accustomed to “quietly” covering up major incidents caused by incompetence, indifference, negligence, profit, self-promotion and/or self-preservation (Explosion at the “Evangelos Florakis” naval base, Haircut on bank deposits in 2013, COOP and Laiki bankruptcies, etc.) Therefore, we decided to present the possible impact of the aforementioned cyber attack.
According to the SecNews article, the attacker managed to compromise one of the Department of Defense websites. But which one? What information can we uncover about the attack through Open Source Intelligence (i.e. information that is available in the public domain)? A simple query on the DNSdumpster.com website can give us useful information about the Department’s public websites.

According to the image above we can try and visit the mod.gov.cy website to check if we can find indicators of compromise (IoCs) or information that could lead to the conclusion that the website has been compromised.

The image above shows that the website was created using the MODX Content Management System (CMS). This is an indicator that this is a compromised website because in some of the images posted by the hacker, the extracted database tables and website file names start with modx_ (e.g. modx_dashboard.csv). If this is the compromised website, what other government websites use the MODX CMS and have also been compromised or could be compromised in the near future?
A quick Google search shows that publications.gov.cy and www.pio.gov.cy could potentially be victims of the same attack, as they may be affected by the same vulnerability.
However, to get an idea of the number of websites that are likely sharing the same server as the MOD website and have likely already been compromised during the attack, we simply clicked on the “Find hosts sharing this IP address” option on the DNSsumpster.com website as shown in the image below.

A sample of the list of 78 websites listed on DNSsumpster.com can be found below. Please keep in mind that the compromised data has not been released by the hacker, so it is possible that the data was not stolen.
The full list of websites on this server is included below for the information of those whose data may have been compromised and to initiate an investigation.

What about the website www.mod.gov.cy?
The DNSdumpster.com image shows that it is running on a Lotus Domino webserver, but a visit to the website shows that it is down/unavailable. It should be mentioned that the WayBackMachine website (archive.org) takes snapshots of publicly accessible websites on the internet at specific time intervals. The WayBackMachine automatically redirects us to a snapshot of mod.gov.cy which means that both domains (mod.gov.cy and www.mod.gov.cy) point to the same IP address and therefore webserver until very recently (i.e. it was the same website).
Thus, the last remaining site on DNSdumpster.com's list, newarmy.mod.gov.cy, was not accessible at the time of writing this analysis. However, the WayBackMachine shows that the last snapshot of the site was taken on January 19, 2021 and had the following content.

At first glance, it seems like a very important website. However, considering the fact that the personal details of applicants who tried to register for the National Guard (SYOP) may have been stolen, the Data Protection Commissioner should investigate the incident further. Furthermore, if the personal details of professional soldiers have indeed been compromised, it is a matter of national security, since they could be in the hands of a foreign state.
Let's try to calculate the probability of this website being compromised. Opening the snapshot of newarmy.mod.gov.cy taken on August 20, 2019, we see the following redirect message.


[More in the study here]
But have they been compromised? The images released by the hacker include a list of MS SQL Server database instance names. This can be easily deduced from the default MS SQL database names “master”, “msdb” and “model” which are clearly visible in the image below.

[More in the study here]
The list of private and public companies and government entities that shared the same server with newarmy.mod.gov.cy is:
There is a very high probability of the aforementioned websites being compromised, given that they belong to the same server.
Most worrying of all is that two of the potentially compromised databases belong to the Office of the Commissioner for Electronic Communications & Postal Regulations under the control and administration of the National Computer Security Response Team (CY-CSIRT) and the Digital Security Authority (DSA). According to the national legislation of the DSA, it is the competent authority for the security of digital networks and information systems in Cyprus and the coordinator for the implementation of the national security strategy. In simple terms, it is responsible for protecting the country's critical infrastructure (e.g. Electricity Authority, Water Bodies, Sewerage Authorities, Banks, etc.) and collects information regarding security, vulnerabilities and defense mechanisms, while it has the power to impose fines (fines and imprisonment of up to 3 years) on companies and individuals under the Authority's control.
The following questions arise regarding the incident:
1. Have the Ministry of Defense and the Deputy Ministry of Research, Innovation and Digital Policy taken the necessary measures to inform the competent authorities about the incident (e.g. the Commissioner for Personal Data Protection)? If not, why not?
2. Why was the incident undermined in the public statement issued by the Ministry of Defense to the media?
3. What is the actual extent of the personal information leak, considering all customers from the list above?
4. This was not the first time a cybersecurity incident affecting government systems had occurred or been publicized. Why didn't the government take the necessary steps to securely deploy the website (e.g., penetration testing, avoiding a shared hosting environment for sensitive information, etc.)?
5. Who are the people responsible for government cybersecurity procedures?
6. What information regarding Cyprus' critical infrastructure was leaked from the OCECPR website? Why was it not detected by them and what measures have they taken to prevent such data from being breached?
We believe that it is common practice in Cyprus to cover up cyberattacks. This has a detrimental effect on companies, as they cannot see the real risk of attacks, therefore they are skeptical about the necessity of taking preventive measures to protect themselves, until of course it is too late (as we have seen from our experiences time and time again).
At the time of writing this whitepaper, SecNews.gr (secnews.gr/339663/hacked-larnaca-airporthermesairports-rootayyil/), published an article about an attack on the Hermes Airports website.
[More in the study here]
Therefore, we would like to make the following recommendations to the government regarding systems, policies and procedures:
1. With regard to any and all government information systems, security must be taken seriously by all stakeholders, and not left as an afterthought.
2. The government should conduct security reviews and penetration tests to identify and fix critical security vulnerabilities. It should also continuously monitor its systems for ongoing hacking attacks and have a plan in place for any such possibility.
3. Designate a contact person so that anyone who discovers a security weakness/vulnerability related to a government system can responsibly report it.
4. Implement a bug bountyso that Cypriot hackers (security experts) can legally test and report vulnerabilities in government systems for which they receive a financial reward.
5. Openly acknowledge and report security incidents affecting government systems. We recommend appointing representatives to communicate such incidents to the public.
[More in the study here]
All the above recommendations also apply to all private sector companies that need to take the necessary steps for their applications. What has been mentioned above is based solely on information that we have been able to collect from public sources and proper investigation by the relevant authorities should be carried out to confirm it (based on our combined techniques and experience).
More news: Mobile malware-One of the biggest threats to organizations in 2020
We apologize in advance to the affected companies if we have caused damage to their reputation, but our intention was to responsibly inform the public and individuals whose personal information may have been compromised, as it was obvious that no one else would do so.
Prometheus Group cybersecurity experts/analysts
“We are a group of Cypriot cybersecurity professionals who prefer to remain anonymous (at least for now). This is the first time we are researching and publishing our work. We created this group to raise public awareness about the state of cybersecurity in Cyprus.
"Because of our work, we have become aware of several attacks on critical organizations and government. Unfortunately, these incidents remain unreported or undermined. We have observed a shift to a more security-oriented mindset for organizations in the private sector, but the public sector is completely lacking."
Whitepaper by PROMETHEUS GROUP
———————————- [End of Study Quote] ——————————–
[SECNEWS UPDATE 13.04.2021]
It should be noted that the involved entities were informed of the existence of the relevant research on Github. We were not given an official response for publication and at their request their names have been removed.
