Menu
Browse
Date:

Feb 2014

Location:

Paraguay

Summary

An Iranian hacker compromised the Network Information Center of Paraguay by exploiting a remote code execution vulnerability, gaining unauthorized access to backend systems and altering DNS records to redirect Google Paraguay's domain to a defacement page. The attacker leaked user credentials and internal data after authorities denied the breach, despite prior warnings from a cybersecurity expert about the unaddressed vulnerability. The intrusion exploited misconfigured directory permissions, enabling unrestricted access to sensitive files without requiring full server control.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 3 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

On February 25, 2014, an Iranian hacker operating under the alias Mormoroth compromised the Network Information Center of Paraguay (NIC.py), the registry managing Paraguay's .py country-code top-level domain. The attacker exploited a remote code execution (RCE) vulnerability in NIC.py's systems, subsequently leveraging improper directory permissions to gain root access to servers. Mormoroth documented his access through published screenshots of NIC.py's backend systems and leaked user credentials and database information obtained during the breach. While no Google systems were compromised, the hacker manipulated DNS records for google.com.py to redirect visitors to a defacement page under his control, creating the appearance of a Google Paraguay website compromise. The DNS alteration represented a targeted disruption rather than persistent access to Google infrastructure.

Cyber Incident Image

Mormoroth initially claimed he did not intend to publish stolen NIC.py data but reversed this decision after Paraguayan authorities publicly denied the occurrence of any breach. In a post on ha.cker.ir, he detailed his exploitation methods, noting administrators had configured directory permissions insecurely, enabling unrestricted file access. A cybersecurity expert cited by Paraguayan media outlet ABC Color revealed he had reported the same vulnerability to Paraguay’s National Computing Center five years prior but received no response, leaving the security flaw unaddressed until the breach. The incident exposed NIC.py's operational data and credential information while temporarily disrupting Google Paraguay's domain resolution. No containment actions or post-incident responses from Paraguayan authorities were documented in the available reporting.

Sources
Sources available to members
1 source