Anonymous has become the most well-known hacker group in recent years, appearing whenever a major event occurs, as defenders of the law. However, a new mysterious hacker group has been on the opposite side of the coin lately, grabbing the spotlight by carrying out DDoS attacks on large organizations and demanding ransoms in bitcoins. This is the Armada Collective, who attacked 3 Greek banks .
What are DDoS attacks?
Such attacks are called "denial of service attacks" against a computer, or a service provided, which aim to render the computer or service incapable of accepting other connections and thus unable to serve other potential customers.
There are generally two forms of this attack. One is the attack in which the service is forced to crash and have to be restarted, and the other is the sending of an excessively large number of fake requests for service, resulting in the service being unable to serve those who actually want the service.
The main form of these attacks uses multiple attacks via other victims or attackers and is known as a distributed denial-of-service attack (DDoS attack).
Such attacks can be used, for example, to render your email unusable. For example, someone could set up a mechanism that would send you letters, filling your mailbox and thus preventing those you expect from receiving the mail.
The first alarm
Last October, the Swiss government issued an alert, warning major companies in the country about a new group of hackers sending threatening emails and then launching DDoS attacks to demonstrate their capabilities. During their attacks, the new hackers, who signed themselves as Armada Collective, had demanded between 10 and 30 bitcoins (3,582 – 10,746 euros), threatening to crash the companies’ systems if a ransom was not paid.
This is the email that the victim companies received:
Under attack
In early September, seven encrypted email providers, ProtonMail, Zoho, Hushmail, FastMail, Neomailbox, VFEmail and Runbox, reported being under attack for three days. Among them, ProtonMail, used by researchers at the European Organization for Nuclear Research (CERN), was forced to pay 20 bitcoins, but even after paying the ransom, the threats did not stop.
It was then that a second group of hackers found the fertile ground - prepared by the Armada Collective attack - to invade ProtonMail's systems and cause problems in its infrastructure. Armada Collective even separated itself from the second attack and returned part of the ransom to ProtonMail, while sending "apology" emails this time saying "Someone with great power, who wants to destroy ProtonMail, invaded after our initial attack.".
ProtonMail may have been the first victim, but it won't be the last. Hushmail and VFEmail, which also promised enhanced security for electronic communication, were subsequently severely attacked, while enterprise services company Runbox came close to being shut down.
Next target: banks
Four banks in Thailand were the next victims of the Armada Collective in late October, with the attackers threatening to destroy their servers.
The outcome of the blackmail was never known. However, the Armada Collective had warned: "Do not make this known to the authorities or the media, otherwise our attack will escalate.".
It was just the precursor to the attack on Greek banks. Last Thursday, the Bank of Greece's management was alarmed as the Armada Collective attempted to hack the banks' electronic systems and succeeded for several minutes.
Information from the Bank of Greece indicates that the attack occurred on Thursday at three banks and targeted the e-banking system. It caused problems for 30-45 minutes but was then addressed.
Continuous meetings followed between the governor of the Bank of Greece, the director of the Hellenic Anti-Corruption Agency and the head of the Cybercrime Investigation Unit, and as the Bank of Greece estimates, the attack has been dealt with.
However, all three services are closely monitoring the situation in case there is another attempt to hack the Greek banking system.
Source: tvxs.gr

