-
A threat actor claimed to breach Georgian court systems and published technical screenshots showing SQL injection, SSRF, and ProxyLogon exploits.
-
The hacker reportedly took advantage of Metasploit, WMI commands, and DNS discovery to obtain access to internal portals and keep in check domain-hijacked networks.
-
Security experts recommend that public sector institutions upgrade their vulnerable servers and implement other security measures.

A cyber threat actor recently announced an attack against Georgian judicial infrastructure. The hacker posted details on a dark web forum. The post targets the digital systems supporting court operations across Georgia.
The intruder published numerous technical screenshots online. These external image files show distinct phases of a deep computer system breach. The shared files reveal how the hacker gained initial network access.
Independent security researchers have not verified the authenticity of these claims yet, and officials from the court system have not issued any public statements. Security analysts are reviewing the exposed technical evidence closely.
Technical Breakdown of the Claimed Attack Method
The hacker shared detailed operational screenshots to prove network entry. They published evidence showing initial foothold establishment inside internal systems. The intruder conducted active DNS discovery to map internal network addresses.
Additionally, the bad actor used SQL injection techniques to bypass web application barriers; notably, SQL injection allows intruders to manipulate database queries using malicious inputs. Consequently, the hacker reached protected judicial databases holding sensitive legal records.
The threat actor used advanced exploitation tools to expand access across the network. For example, the intruder utilized the Metasploit framework to launch automated system attacks. The hacker also executed Server-Side Request Forgery or SSRF exploitation attempts.
SSRF weaknesses give adversaries opportunities to compel private servers to conduct improper web requests. The villain also attacked Microsoft’s Exchange mail servers by employing ProxyLogon vulnerabilities, which give unauthorized actors total administrator access to server accounts.
After getting administrator access, the hacker was able to move laterally through the internal server networks of the company. The hacker made use of Windows Management Instrumentation or WMI queries to run system processes. WMI allows administrative control over local and remote Windows operating systems.
Also, the hacker accessed restricted internal portals meant exclusively for authorized court employees. They conducted extensive post-exploitation activities to maintain persistent access behind firewalls.
As a result, the threat actor created hidden access routes to monitor daily court activities. Network defenders face significant challenges when removing stealthy intruders from complex domain environments.
Why Judicial Infrastructure Attacks Create Severe Risks
Judicial server networks process confidential legal documents and sensitive personal records daily. For instance, court databases store private case files, witness testimonies, and judge deliberations. Compromising judicial networks exposes sealed legal evidence to unauthorized public view.
This means that bad actors can tamper with official digital records or delay court proceedings. They can also lock judicial databases to demand heavy financial extortion payments. Indeed, such disruptions to legal networks undermine public confidence in national justice systems.
Administrative control over court portals allows hackers to alter legal schedules. They can delete electronic filings or modify official court transcripts. They can also utilize elevated server access to monitor communication between lawyers and court officials.
Besides, exfiltrating confidential case files creates serious safety hazards for protected witnesses. Threat actors can sell stolen legal records to interested buyers on dark web forums. As a result, targeted court breaches threaten state security and individual citizen privacy.
The dark web infrastructure that enables such sales has been a focus of international law enforcement. The Dutch police recently shut down a criminal host used for dark web activities.
Additionally, successful infrastructure breaches encourage other cybercrime groups to launch similar attacks. Also, publishing complete attack paths provides blueprints for novice hackers worldwide. Other bad actors can copy exposed techniques to target vulnerable public sector servers.
In most cases, government organizations often depend on outdated software systems that have unresolved security vulnerabilities. But cybercriminals continually search through public IP addresses to locate vulnerable government websites. Therefore, public institutions must prioritize security upgrades to stop complex intrusions early.
Critical Defensive Steps for Government Server Networks
Government IT departments must audit exposed internet-facing software applications immediately. First, security administrators should inspect web servers for known ProxyLogon and SSRF vulnerabilities. Software engineers must apply official security patches to update email servers without delay.
Additionally, network managers should restrict public access to administrative WMI interfaces. Disabling unnecessary remote management services prevents hackers from executing unauthorized commands. Consequently, proper server hardening reduces attack surfaces and blocks lateral movement.
Second, organizations must enforce multi-factor authentication across all internal web portals. The authentication requires physical hardware tokens or temporary codes during login. Such extra login verification blocks unauthorized users even if passwords leak online.
In addition, security teams must monitor internal DNS discovery requests for unusual network scans. Detecting rapid domain queries helps analysts identify unauthorized reconnaissance activity quickly. In fact, early detection allows defenders to isolate infected machines before attackers expand control.
Also, system administrators should implement strict database input validation to prevent SQL injection. For example, developers must use parameterized database queries to neutralize malicious input strings. IT staff should also isolate sensitive judicial databases behind internal network firewalls.
Besides, organizations must maintain isolated offline backups to recover from sudden system lockouts. Security teams should analyze published attack screenshots to identify potential compromises inside their systems. Using a proactive threat hunting approach stops cybercriminals from maintaining persistent access inside legal networks.