Cybercriminals who tagged themselves as “Hackers of Saviors” have exploited and defaced more than 2000 Israeli websites that show the country’s commercial capital, Tel Aviv burning in flames with a fear-mongering caption.
The attack took place on May 21, 2020. It happened to go down on “Jerusalem Day” – an Israeli national holiday commemorating the reunification of Jerusalem and the establishment of Israeli control over the Old City in the aftermath of the June 1967 Six-Day War.
Most of the defaced websites were hosted by uPress, one of the popular Hosting providers. It is believed by forensics that the Hackers of Saviors have exploited a security vulnerability in WordPress to execute the malicious activity. Some of the targeted sites were uPress, Bang, Olufsen Israel – which is a high-end sound system retailer, Bet Gabriet – a cultural center, and several religious Jewish High Schools and post-high school programs.
Not only that, these cybercriminals defaced the targeted websites, but they have also tried to gain personal information by embedding a malicious script that requests users to access their webcam. It has also been revealed that there are two versions of this script that was delivered, the second one contains a code that captures a photo of the user and sends it directly on the hacker’s server.
Each defaced website has an embedded YouTube video with the eerie caption as of writing, and the video has been terminated from YouTube.
The most attacked website has been taken down, but some are still available online.
“It is better to be safe than sorry,” a famous idiom as we know. Installing an updated Anti-virus protection program is another layer of protection to take as having one will perform a scan for spyware and alerts users once they attempt to visit a malicious website. Users must also consider encrypting and backing up their data to protect themselves from cybercriminals.