Home » today » World » Investigators discover identity of hacker who has attacked nearly 5,000 websites in 40 countries since 2013 – Internet

Investigators discover identity of hacker who has attacked nearly 5,000 websites in 40 countries since 2013 – Internet

A hacker named VandaTheGod has carried out an “invasion” campaign on 4,820 government websites, academic institutions and private companies in 40 countries since 2013. Now, Check Point investigators have managed to discover the identity of the hacker who became a cybercriminal, reporting all the information found the authorities.

According to the security company, the attacker was known for altering the visual aspect of his targets’ web pages, in a practice known as “defacing”. In a first phase, the hacker aimed to spread anti-government messages, denouncing social injustices and situations of corruption.

photo-swipe" data-trackerlink="Article|Content|Widget_embed-image"> <picture data-lazy = "true" style = "height: 0; padding-top: 85.0847500%;" class = "has-dimensions" data-original-w = "590" data-original-h = "502" data-original-src = "https://mb.web.sapo.io/4fdf4175778698744460eddaaae683ea80c38eea.png" title="VandaTheGod | Defacing Campaign – Researchers discover identity of hacker who attacked almost 5,000 websites from 40 countries since 2013 – SAPO Tek "data-caption ="

VandaTheGod | Defacing Campaign

credits: Check Point

“data-title =” VandaTheGod | Defacing Campaign – Researchers discover identity of hacker who attacked almost 5,000 websites from 40 countries since 2013 – SAPO Tek “> <! – Conditionally wrap elements in <video> tags which will then make them visible to IE9. ->

credits: Check Point

The hacker stood out for being very active on social networks and for using different user profiles and channels to give visibility to his campaign. One of VandaTheGod’s first attacks was on the Brazilian government’s website, in response to the burning in the Amazon rainforest.

The cybercriminal used to leave a link to his Twitter page on the “hacked” pages, which led the experts to believe that the profile on the social network was, in fact, managed by VandaTheGod. The fact that many of his publications are written in Brazilian Portuguese and that the hacker claims to belong to the Brazilian Cyber ​​Army ended up as clues for researchers.

photo-swipe" data-trackerlink="Article|Content|Widget_embed-image"> <picture data-lazy = "true" style = "height: 0; padding-top: 43.6551700%;" class = "has-dimensions" data-original-w = "1450" data-original-h = "633" data-original-src = "https://mb.web.sapo.io/91ff77e95fd7430d020967f6b44813b024ce3644.png" title="VandaTheGod | Defacing Campaign – Researchers discover identity of hacker who attacked almost 5,000 websites from 40 countries since 2013 – SAPO Tek "data-caption ="

VandaTheGod | Defacing Campaign

credits: Check Point

“data-title =” VandaTheGod | Defacing Campaign – Researchers discover identity of hacker who attacked almost 5,000 websites from 40 countries since 2013 – SAPO Tek “> <! – Conditionally wrap elements in <video> tags which will then make them visible to IE9. -> VandaTheGod | Defacing Campaign

credits: Check Point

After a phase of hacktivism, VandaTheGod began to change the pattern of his behavior and attacks against public figures, universities and entities in the health sector followed. In one case, the hacker claimed that he had access to the medical records of one million New Zealand patients, indicating that the “ransom” for each of the contacts was $ 2000.

photo-swipe" data-trackerlink="Article|Content|Widget_embed-image"> <picture data-lazy = "true" style = "height: 0; padding-top: 36.7941700%;" class = "has-dimensions" data-original-w = "549" data-original-h = "202" data-original-src = "https://mb.web.sapo.io/a10992e150875d1f22e064d89811909d934ef515.jpg" title="Tweets made VandaTheGod – Researchers discover identity of hacker who attacked almost 5,000 websites from 40 countries since 2013 – SAPO Tek "data-caption ="

Tweets made by VandaTheGod

credits: Check Point

“data-title =” Tweets made VandaTheGod – Researchers discover identity of hacker who attacked almost 5,000 websites in 40 countries since 2013 – SAPO Tek “> <! – Conditionally wrap elements in <video> tags which will then make them visible to IE9. -> Tweets made by VandaTheGod

credits: Check Point

The cybercriminal even set out to hack 5,000 websites, declaring that he would only stop doing so when he achieved his goal. Check Point researchers explain that in order to attack the 4,820 pages he was able to access, VandaTheGod scanned his vulnerabilities for an entry point. As you can see, some of the websites belonged to Portuguese domains. In all, 16 national websites were attacked.

photo-swipe" data-trackerlink="Article|Content|Widget_embed-image"> <picture data-lazy = "true" style = "height: 0; padding-top: 75.4386000%;" class = "has-dimensions" data-original-w = "741" data-original-h = "559" data-original-src = "https://mb.web.sapo.io/205265b8deecf73ebff5aa33d05d1b77501b15d4.jpg" title="List with some of the websites attacked by VandaTheGod – Investigators discover the identity of a hacker who has attacked almost 5,000 websites in 40 countries since 2013 – SAPO Tek "data-caption ="

List with some of the websites attacked by VandaTheGod

credits: Check Point

“data-title =” List with some of the websites attacked by VandaTheGod – Researchers discover identity of hacker who attacked almost 5,000 websites from 40 countries since 2013 – SAPO Tek “> <! – Conditionally wrap elements in <video> tags which will then make them visible to IE9. -> List with some of the websites attacked by VandaTheGod

credits: Check Point

The methods used to give visibility to the attack campaign ended up tracing its destiny, as it contained details about its trail. By analyzing the publications he made on social networks and comparing them with information through the online tool WHOIS, the specialists were able to discover that VandaTheGod was actually a Brazilian citizen of Uberlândia, in the state of Minas Gerais.

After alerting the authorities, Check Point noted that some of the photos that allowed the discovery were deleted, however some of its profiles remain active. For now, it is not yet clear whether the Brazilian authorities have taken any action in relation to the hacker.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.