Powerful Greek Army
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Powerful Greek Army, also known as Powerful Greek Hackers, is a threat actor based in Greece that has been publicly linked to several website intrusions. The group uses the aliases Cryptolulz and Kapustkiy in different operations and has acknowledged an affiliation with the Fallensec hacking group after early activities. Open source reporting describes the actor’s motivations as politically driven, aiming to expose security negligence and encourage administrators to remediate vulnerabilities.
The actor’s targeting has focused on governmental and diplomatic entities, with observed victims including embassies and high commissions located in Russia and India. The primary objective cited in the attributed incidents is to highlight inadequate security practices and to pressure responsible parties into patching flaws, rather than pursuing financial gain or espionage. Their operational method consistently involves exploiting web application vulnerabilities, specifically blind SQL injection and standard SQL injection techniques, to gain unauthorized access to databases and extract credential information. No malware families or specialized tooling are mentioned in the available sources.
Notable operations include the December 2014 breach of the Armenian embassy’s website in Russia, where the actor identified as Cryptolulz exfiltrated non‑sensitive user data after exploiting a blind SQL injection flaw. In November 2016, the actor operating as Kapustkiy compromised the High Commission of Fiji’s site in India via SQL injection, leaking login credentials for nearly two hundred accounts to prompt remediation. Shortly thereafter, the same actor used SQL injection to breach the High Commission of Ghana’s website and another diplomatic mission in India, again exposing credential data to force security improvements. These incidents illustrate a pattern of targeting diplomatic web presences through injection vulnerabilities to achieve politically motivated disclosure goals.
Incidents
Attributed incidents are available to members.
3 incidents