{"id":6967,"date":"2022-01-25T21:55:51","date_gmt":"2022-01-25T21:55:51","guid":{"rendered":"https:\/\/gridinsoft.com\/blogs\/?p=6967"},"modified":"2024-05-30T18:06:59","modified_gmt":"2024-05-30T18:06:59","slug":"belarusian-cyber-partisans-attacked-railway-servers","status":"publish","type":"post","link":"https:\/\/gridinsoft.com\/blogs\/belarusian-cyber-partisans-attacked-railway-servers\/","title":{"rendered":"Belarusian Cyber Partisans hack group attacked railway servers"},"content":{"rendered":"<h4>A hack group that calls itself Belarusian Cyber Partisans claims to have attacked and encrypted the servers of the Belarusian Railways. The hacktivists said that the reason for the hack was the fact that Russia used the Belarusian railway to transfer troops and equipment.<\/h4>\n<p>The group made a statement on Twitter and Telegram, claiming responsibility for the hack and demanding the release of political prisoners, as well as preventing further use of the transport infrastructure of the Belarusian Railway for the movement of Russian troops.<\/p>\n<p>The hackers reported that they &#8220;encrypted some of the servers, databases and workstations&#8221;, but did not touch the &#8220;automation and protection systems&#8221; for security reasons. <\/p>\n<div class=\"su-quote su-quote-style-default su-quote-has-cite\"><div class=\"su-quote-inner su-u-clearfix su-u-trim\">At the command of the terrorist Lukashenka, Belarusian Railway allows the occupying troops to enter our land. We encrypted some of BR&#8217;s servers, databases and workstations to disrupt its operations.Automation and security systems were NOT affected to avoid emergency situations. We have encryption keys, and we are ready to return Belarusian Railroad&#8217;s systems to normal mode. Our conditions: Release of the 50 political prisoners who are most in need of medical assistance. Preventing the presence of Russian troops on the territory of Belarus.<span class=\"su-quote-cite\"><a href=\"https:\/\/twitter.com\/cpartisans\/status\/1485618881557315588\" target=\"_blank\" rel=\"nofollow noopener\">Belarusian cyber partisans wrote on Twitter.<\/a><\/span><\/div><\/div>\n<p>In their <a href=\"https:\/\/t.me\/cpartisans\" rel=\"noopener nofollow\" target=\"_blank\">Telegram channel<\/a>, the hacktivists shared screenshots from hacked systems, showing that they have access to the internal systems of the Belarusian Railway, Veeam backup servers, a Windows domain controller, and a backup server that contains tens of terabytes of data. <\/p>\n<p><a href=\"\/blogs\/wp-content\/uploads\/2022\/01\/Belarusian-Railway-backup-server.jpg\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"\/blogs\/wp-content\/uploads\/2022\/01\/Belarusian-Railway-backup-server-1024x640.jpg\" alt=\"Belarusian Cyber Partisans\" width=\"640\" height=\"400\" class=\"alignnone size-large wp-image-6968\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2022\/01\/Belarusian-Railway-backup-server-1024x640.jpg 1024w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2022\/01\/Belarusian-Railway-backup-server-300x188.jpg 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2022\/01\/Belarusian-Railway-backup-server-768x480.jpg 768w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2022\/01\/Belarusian-Railway-backup-server.jpg 1280w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>One of the screenshots shows that the online ticket office of the Belarusian Railways responds with an error when executing the SQL query. <\/p>\n<p><a href=\"\/blogs\/wp-content\/uploads\/2022\/01\/Belarusian-Railway.jpg\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"\/blogs\/wp-content\/uploads\/2022\/01\/Belarusian-Railway-1002x1024.jpg\" alt=\"Belarusian Cyber Partisans\" width=\"640\" height=\"654\" class=\"alignnone size-large wp-image-6969\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2022\/01\/Belarusian-Railway-1002x1024.jpg 1002w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2022\/01\/Belarusian-Railway-293x300.jpg 293w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2022\/01\/Belarusian-Railway-768x785.jpg 768w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2022\/01\/Belarusian-Railway.jpg 1252w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>Yesterday, a <a href=\"https:\/\/www.rw.by\/corporate\/press_center\/news_of_passengers\/2022\/01\/vnimaniyu-passazhirov_24012022\/\" rel=\"noopener nofollow\" target=\"_blank\">message about temporary problems<\/a> appeared on the website of the Belarusian Railways. It is reported that &#8220;for technical reasons, services for issuing electronic travel documents are temporarily unavailable.&#8221; <\/p>\n<p>A single word is not said about the cyberattack in this message, as well as the exact nature of the failure and the timing of its elimination.<\/p>\n<p>How do you feel about such &#8220;promotions&#8221;? On the one hand, this is certainly a crime, but against the criminal Belarusian authorities. True, this can bring trouble to the most ordinary citizens of the country.<\/p>\n<p>You might also be interested to read that <a href=\"\/blogs\/vaccine-against-russian-hackers\/\">Cyrillic on the keyboard may become a \u201cvaccine\u201d against Russian hackers<\/a>, and that <a href=\"\/blogs\/russian-hackers-attacked-government-of-poland\/\">Russian-speaking hackers attacked the government infrastructure of Poland<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A hack group that calls itself Belarusian Cyber Partisans claims to have attacked and encrypted the servers of the Belarusian Railways. The hacktivists said that the reason for the hack was the fact that Russia used the Belarusian railway to transfer troops and equipment. The group made a statement on Twitter and Telegram, claiming responsibility [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":6970,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[15],"tags":[405,410],"class_list":{"0":"post-6967","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security-news","8":"tag-anonymous","9":"tag-hacking"},"featured_image_src":"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2022\/01\/belarus-cyberpartisans.jpeg","author_info":{"display_name":"Vladimir Krasnogolovy","author_link":"https:\/\/gridinsoft.com\/blogs\/author\/krasnogolovy\/"},"_links":{"self":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/6967","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/comments?post=6967"}],"version-history":[{"count":1,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/6967\/revisions"}],"predecessor-version":[{"id":6971,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/6967\/revisions\/6971"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media\/6970"}],"wp:attachment":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media?parent=6967"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/categories?post=6967"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/tags?post=6967"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}