According to research by cybersecurity firm Group-IB, AnonGhost appears to have exploited an API vulnerability in the real-time rocket alert app RedAlert, which is widely used in Israel. The RedAlert app has over a million downloads from the Google Play.
See also: RedAlert ransomware: Targets Windows and Linux VMWare ESXi servers

“During thebreach , they were able to intercept requests, expose vulnerable servers and application programming interfaces (APIs), and use Python scripts to send spam to some users of the app,” researchers tell X. The attackers shared information about the alleged attack on their official Telegram. The image included in the original post suggests that AnonGhost sent fake messages to users of the app, stating that “a nuclear bomb is coming.”
At the same time, Elad Nava, the director of Pushy, the company behind the RedAlert app, said that the claims are false and the app is working normally.
"This is fake news. The RedAlert application continues to operate normally," Nava told Cybernews via email.
RedAlert application developed in collaboration with the government of Israel, with the central goal of citizen safety.
How does RedAlert work?
RedAlert by terrorist groups. The application monitors launch indications and notifies users before these programmed missiles reach their destination.
Researchers note that while hacktivist groups like AnonGhost are typically associated with small-scale DDoS or website harassment, they sometimes carry out more sophisticated attacks.
"It often happens that hacktivists exploit web and mobile APIs, which are often considered easier targets compared to the main product APIs," the researchers hypothesized.
See also: Israel: Hackers target energy, defense and telecommunications companies
The AnonGhost alias has been in use for some time. Several years ago, researchers at Binary Defense believed that the group had connections to the infamous Islamic State (ISIS).

Cyberwarriors have been actively involved in the fight following recent Hamas attacks on Israel. A group of attackers, called Ghosts of Palestine, recently attacked several Israeli sites, while the Ganosec Group said it aims to disable the Israeli Security Agency website.
Hours after the Hamas invasion, the Israeli government website gov.il was down. The Killnetclaimed full responsibility for the Telegram attack. Anonymous Sudan has sided with Hamas and Killnet on Telegram.
There are also active pro-Israel hackers. The official Hamas website was taken down – allegedly by a hacker group called India Cyber Force. Other groups supporting Israel include SilenOne, Garuna Ops , and Team UCC Ops.
The Group-IB company reported that various threat groups have entered the conflict between Israel and Hamas.
See also: Israeli hospital hit by ransomware attack
Israel is in turmoil after a deadly attack by Hamas militants around Gaza early Saturday morning, killing hundreds of civilians in Israeli cities and a music festival. With Israel now shelling Gaza, where Hamas is based, the toll from the attack reached 600 on Sunday night, with both sides claiming heavy casualties.
Source: cybernews
