Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Hacker Group Comes Out of Nowhere to Launch Attacks Against Government Networks

A hacker group going by the name “The Unknowns” is gaining attention for a string of attacks against government and private networks, which started back in March. However, there are questions as to whether or not their recent actions could lead to their downfall.

A hacker group going by the name “The Unknowns” is gaining attention for a string of attacks against government and private networks, which started back in March. However, there are questions as to whether or not their recent actions could lead to their downfall.

The Unknowns, as the group refers to themselves, entered the public’s eye a few weeks ago, and since then they have claimed credit for attacks against Oak Ridge National Labs, NASA, the European Space Agency, the French Ministry of Defense, the U.S. Air Force, Harvard, Bahrain’s Ministry of Defense, a French radio station, and the Jordanian Yellow Pages.

One of the most recent attacks included the defacement of Oak Ridge National Labs’ DAAC portal. According to ORNL, the Distributed Active Archive Center (DAAC) “…provides data and information relevant to biogeochemical dynamics, ecological data, and environmental processes, critical for understanding the dynamics relating to the biological, geological, and chemical components of Earth’s environment.”

The attack, according to the group’s public face (who is known as Zyklon B), was successful in part thanks to a PHP shell uploaded to the webserver, which was only possible after a staffer at ORNL fell victim to social engineering via email. We’ve reached out to ORNL for a statement. At the time this article went to press, no one was available for comment.

Last week, NASA acknowledged that The Unknowns had targeted a website hosted at the Glenn Research Center. That hack centered on the Interagency Advanced Power Group, and resulted in the loss of 307 records that were taken from a compromised database. However, the records lost and the other information housed on the server were not critical, NASA said.

“NASA security officials detected an intrusion into the site on April 20 and took it offline. The agency takes the issue of IT security very seriously and at no point was sensitive or controlled information compromised,” a spokesperson for the agency said in a statement.

Likewise, the European Space Agency confirmed that an SQL Injection vulnerability was the root cause for their Unknowns-based attack problems, but added that nothing of importance was compromised.

The U.S. Air Force however, has suffered the most at the hands of The Unknowns, after more than 200MB of Official Use Only documents were leaked by the group. The documents were taken from the USAF’s auxiliary Civil Air Patrol.

Advertisement. Scroll to continue reading.

In terms of justification, The Unknowns are keeping things simple according to public statements.

“Victims, we have released some of your documents and data, we probably harmed you a bit but that’s not really our goal because if it was then all of your websites would be completely defaced but we know that within a week or two, the vulnerabilties [sic] we found will be patched and that’s what we’re actually looking for,” a statement explains.

"The Unknowns" Hack Government SitesOn Twitter, the group mentioned that they will be emailing their victims and informing them how the attacks took place, and sharing additional information in order to help them. While it seems noble, it is unlikely that any of the victims will want the help, and most will be looking to involve law enforcement, especially the government agencies swept up in the attack.

Zyklon B, according to @iHazCandy of Consternation Security, has made too many mistakes. For example, the screenshots posted as proof during the ORNL attack led to the discovery of an IP address in France.

“I had this kid’s IP on day one,” he said [screen shot] during a brief chat Friday morning.

If the information is true, then The Unknowns might not remain that way for long. We’ll keep an eye on the situation surrounding them and update as needed.

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Artificial Intelligence

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.

Cybercrime

Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.