HomeRapidalertAnonGhost are planning attacks on oil companies.

AnonGhost is planning attacks on oil companies.

AnonGhost

The well-known hacktivists Anonymous, and specifically AnonGhost, who carried out the attacks against oil companies in 2013, are back in exactly the same way today, 6/20/2014, exactly one year later.

Specifically, the hacktivists AnonGhost , who have close ties to Anonymous, announced that they will target companies in Saudi Arabia and Kuwait, due to the partnerships they have developed with Israeli companies.

The electronic video message from the hacktivists AnonGhost, as we have become accustomed to in the past, can be seen below:

https://www.youtube.com/watch?v=Yc2Ztb0Z3xA

The list of targets includes the target countries and some of the largest oil exporting companies.

The US, Canada, UK, Israel, China, Italy, France, Russia, Germany and Qatar are the countries that will be targeted according to AnonGhost in the coming hours. Some of the companies that may be targeted are Kuwait Oil Company, Petroleum Development Oman, Qatar Petroleum, Saudi Aramco, ADNOC, ENOC and Bahrain Petroleum Company.

The list of targeted companies is shown in the screenshot below:

op.petrol.target.list

 

It seems that the AnonGhost have already conducted a preliminary online search of their targets, and have published a full list on Pastebin [here] and [here]. In addition to the list, there is also a document with personal information and credit cards of about 500 people, which we will not publish for security reasons.

[box_warning]Sources report that, similar to the previous OpPetrol, there will be cyberattacks in multiple ways, such as distributed denial of service (DDoS) attacks, phishing and sending malicious software, attempts to steal employee data and information, searching for vulnerable software, attacks on websites using SQL Injection and possible alterations to central websites.[/box_warning]

The motives for the attacks are, according to Anonymous, clearly political. The action is being carried out because the main currency of the international oil export market is the US dollar, which means, as they say, that transactions are not processed in the local currency of the producing country. The group claims that this leads to the exploitation of the energy resources of the Middle East and Asia by Westerners. In fact, Saudi Arabia has betrayed Muslims, they say, with its partnerships with the US and Israel.

oil.plant

Targeted companies (although it is possible that the damage has already been done before the announcement of the targets) should:

  • They constantly check the company's Intrusion Detection/Prevention systems for malicious activity and monitor network traffic
  • Ensure that the operating systems of servers that have access to the Internet are up to date and all security patches are installed
  • User terminals must have fully updated software (and updated third party applications such as Java/Adobe/Flash) and the latest antivirus updates
  • Ensure that web servers and websites are fully updated with all relevant patches and have protection against DoS/DDoS attacks. Also discuss the issue of DDoS with the Uplink provider so that the company is aware of the measures they have in place in the event of such an attack
  • Install web application firewalls on online web applications
  • Inform the IT Department and security managers so that they are prepared in the event of a breach
  • Employees should be informed about the possibility of a cyberattack. They should not follow links that are suggested to them or open strange attachments even if they appear to come from known senders. Full information is required regarding social engineering and phishing techniques.
  • Third-party integrators should be aware and their availability should be ensured.
  • Ensure that only necessary services are accessible from the Internet side and protected with all modern technologies.

For continuous updates, you can follow the hacktivist collective's Twitter  and stay tuned to SecNews for any new releases.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS