HomeInvestigations Albanian-Skopje TetovaHackersGroup targets Greek Police! Attack in progress?

[EXCLUSIVE] Albanian-Skopje TetovaHackersGroup targets Greek Police! Attack in progress?

tetova-HACKERSSecNews EXCLUSIVELY a very important issue with unpredictable dimensions regarding the security of critical infrastructures, which will create a sensation.

According to indications identified by the SecNews network research team, Albanian hackers have targeted, among others, the Greek Police and its services! The Albanian hackers, who belong to a large organized cybercrime group called TetovaHackers, have set themselves the goal of carrying out cyber attacks against Greece, initially targeting the Greek Police or related services.

TetovaHackers have made this intention public on their Facebook page , as we can see in the message below:

astynomia.gr.tetova.hackers

 

See their message translated:

“Announcement: The Tetova hackers group called TetovaHackersGroup a few days ago carried out an attack on the Greek Police website, www.astynomia.gr.

According to Greek media, the hacker group stated that they could control the website from Tetovo. Greek media contacted the hacker group via email at tetovahackersgroup@gmail.com with the question “TetovaHackersGroup why did you attack the Greek Police website?”

The leading member of the TetovaHackersGroup and press officer, the hacker with the pseudonym DJ-X@NI, stated about the attack:

We attacked the website of the infamous Greek Police because Greek hackers attacked our website in Tetovo. We do not allow hacking of our website by various groups of Skopjeans or Serbs, Russians or Greeks. We defend our Albanian land. Thank you.”

tattoo.logo

Who are TetovaHackers?

SecNews, in collaboration with experts and security researchers, investigated who is behind the organized cybercrime group TetovaHackersGroup. The group also uses minors who are approached via the Internet under the pretext of protecting Albania. Minors participate in the offensive actions and in this way the perpetrators of the attacks conceal their identity, hiding behind users with a low cognitive level.

From the information known so far, the leading members of TetovaHackers are based in a small town of 50,000 inhabitants, Tetovo, northwest of Skopje.

The city has a predominantly Albanian population, and is essentially the "unofficial capital" of a disputed region between Albanians and Skopjeans, stretching from Tetovo to Debar. The area is also a "hotbed" of many nationalist Albanian parties, and has one of the highest crime rates in the wider region, second only to the city of Skopje.

tattoohackers

The TetovaHackersGroup, as they state on their website, have as their main mission to attack infrastructures in Serbia or Greece and to protect their country. They also state that they are not a community, not a group but a “family” (see here https://www.facebook.com/TetovaHackersGroupDeface)

The administrator of the TetovaHackersGroup website is the following profile https://www.facebook.com/TetovaHackersGroup

admin.user.tetova.hackers

Their founding member has a communication group where he announces his attacks here: https://www.facebook.com/groups/337739133005557/

SecNews publishes, after investigation, EXCLUSIVELY, the profiles of the involved members of the group, who are directly related to TetovaHackers but also to the attack against Greek targets.

– TheDacooder AL

Profile: https://www.facebook.com/Th3Dac00d3R

tetova.hacker.2

– Ditt,zz Ditt,zz

Profile: https://www.facebook.com/r00t.wildd

tetova.hacker.7

– Mirjon Janushaj (LoqkaMany)

Profile: https://www.facebook.com/WeedHaXoR

tetova.hacker.3

– DEVILC00DE

Profile: https://www.facebook.com/DEVILC00DE

tetova.hacker.4– Mc Alex (Alex Souljah)

Profile: https://www.facebook.com/Injector.Thc

tetova.hacker.5

– Silent Hacker's Group (Shg-Cr3w) – Collaborative group

Profile: https://www.facebook.com/sHg.Crew.Albania

tetova.hacker.6

– Jetmir Elmazi Domaqini

Profile: https://www.facebook.com/CELLOPEKI

 

tetova.hacker.1

The above appear to be acting in an organized manner under the guidance of an unknown user with the pseudonym DJ-X@NI as well as TheDacooder AL – PUSHER and FailHackers, with the aim of damaging the Greek Police and possibly other Greek critical infrastructures.

It has not been clarified what methodology the Albanian hackers use and what attacks they carry out. You are investigating whether this is a group funded by far-right Albanian parties or by the Albanian parastate with the aim of destabilizing attacks in the wider region. On the website of the Greek Police, they do not appear to have made any alterations nor does their attack appear to have been successful, but it seems that they only carried out a denial of service (DDoS) attack for a short period of time, a few days ago.

It remains unanswered, however, whether the attack is ongoing or whether they have the capabilities or have used more sophisticated methods (such as Spear phishing attacks, sending malware / advanced persistent threats) with the aim of extracting documents or accessing internal systems.

Studying their previous attacks, it appears that they had gained access to a Peruvian hospital as well as Greek websites.

The competent national security authorities and law enforcement agencies will be able to investigate, through a variety of methods, after the publication of the information identified by the SecNews research team, what exactly has been targeted by the Albanian hackers and whether the attack is still ongoing or was successfully repelled by national security systems.

We appreciate that:

  • It should be investigated IMMEDIATELY in the services targeted by the Albanians whether malicious e-mails have been sent to addresses that are shared on the Internet
  • In addition, it should be checked whether any falsified e-mails or links leading to malicious software or websites of dubious origin have been received by Greek Police officers
  • It should be checked in the central Internet access systems (Syzefxis proxy servers or others) if there are unauthorized connection attempts from the internal network to Albanian destinations, especially during non-working hours.
  • Appropriate filters should be created to restrict access to suspicious IP addresses
  • All system logs for the previous days that indicate the attack took place (3-4 days ago) should be analyzed
  • The specific persons who appear to be involved in the case, as well as third parties who have not been identified and are referred to only by pseudonyms, should be investigated.

After the issue was made public, unknown individuals claiming to be Greek Hackers contacted SecNews and stated that "the attack by the Albanians will not go unanswered and this particular group has already been targeted and their personal information will soon be exposed on the internet."

SecNews posted the above information with the aim of protecting society as a whole, but also to inform those responsible for national systems that have allegedly been targeted or threatened with attacks by malicious attackers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS