{"id":64,"date":"2026-05-13T19:34:03","date_gmt":"2026-05-13T16:34:03","guid":{"rendered":"http:\/\/34224059145.blog.com.gr\/?p=64"},"modified":"2026-05-27T18:57:18","modified_gmt":"2026-05-27T15:57:18","slug":"the-side-door-threat-levelzero-report","status":"publish","type":"post","link":"https:\/\/levelzero.gr\/en\/the-side-door-threat-levelzero-report\/","title":{"rendered":"The \u201cSide-Door\u201d Threat"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Bypassing High- Security Defenses via Indirect Cyberattacks<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As corporate cybersecurity perimeters become increasingly sophisticated, threat actors are shifting their focus away from direct technical exploitation. Instead, they are adopting indirect methodologies\u2014leveraging social engineering, credential theft, and supply chain compromises to bypass high-security defenses. This report analyzes the evolution of  hese \u201cside-door\u201d attacks across Europe, with a specific focus on the Greek threat landscape. By exploiting human vulnerabilities and trusted third-party relationships, attackers are successfully infiltrating organizations that would otherwise be highly resilient to direct assault.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1. The Evolution of Social Engineering in Europe<br><br><\/strong>Social engineering has evolved from rudimentary mass-phishing campaigns into highly targeted, AI-driven operations. According to the European Union Agency for Cybersecurity (ENISA), by early 2025, AI-supported phishing campaigns represented more than 80% of observed social engineering activity worldwide [1].<br>The weaponization of Generative AI has fundamentally altered the threat landscape. Adversaries now utilize AI to craft highly convincing, grammatically perfect messages<br>in local languages. This development is particularly significant for countries like Greece, where the complexity of the language previously served as a natural barrier against automated, large-scale phishing campaigns.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" width=\"1686\" height=\"1513\" src=\"http:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/2484be4f-cd02-4e8f-ad2d-4e4ea0dce9c0.png\" alt=\"fig1_social_eng_vectorspng\" class=\"wp-image-65\" srcset=\"https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/2484be4f-cd02-4e8f-ad2d-4e4ea0dce9c0.png 1686w, https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/2484be4f-cd02-4e8f-ad2d-4e4ea0dce9c0-300x269.png 300w, https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/2484be4f-cd02-4e8f-ad2d-4e4ea0dce9c0-1024x919.png 1024w, https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/2484be4f-cd02-4e8f-ad2d-4e4ea0dce9c0-768x689.png 768w, https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/2484be4f-cd02-4e8f-ad2d-4e4ea0dce9c0-1536x1378.png 1536w\" sizes=\"(max-width: 1686px) 100vw, 1686px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The primary objective of these campaigns is no longer immediate financial extortion, but rather credential harvesting. Threat actors seek to obtain valid user account details, allowing them to bypass perimeter defenses by simply \u201clogging in\u201d rather than breaking in. A notable example occurred in May 2025, when the threat group ShinyHunters launched a massive social engineering campaign that siphoned over a billion Salesforce customer records by tricking users into revealing their credentials [2].<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2. The Greek Landscape: A Surge in Identity-Based Attacks<br><br><\/strong>Research indicates that the evolution of cybercrime in Greece exhibits distinctive national characteristics, primarily centered around sophisticated fraud and identity theft [3]. The National Cybersecurity Strategy data reveals a concerning trend: identity theft attacks have steadily climbed the national threat rankings, moving from 13th place in 2020 to 7th place by 2025 [4].<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Case Study: The 2025 Greek Cyber Fraud Network<br><br><\/strong>In October 2025, Greek prosecutors dismantled what is described as the largest organized cyber fraud operation ever uncovered in the country. The network involved<br>over 1,200 suspects and generated illicit profits exceeding EUR 6 million [5]. The methodology of this network exemplifies the modern approach to credential theft:<br>Sophisticated Phishing: The group utilized highly targeted SMS phishing (smishing) and email campaigns, sending fake bank messages with fraudulent links to steal login credentials. Target Selection: Rather than solely targeting large corporations, the network focused on small business owners, media outlets, churches, and monasteries. In<br>one instance, a single victim lost EUR 78,690 after clicking a fraudulent link. Operational Hierarchy: The network operated with a corporate-like structure, including ringleaders, coordinators, data specialists, and makeshift call centers located in Roma settlements (Zephyri, Zevgolatio, Examilia) that changed locations frequently to evade detection.<br>Money Mules: The scheme relied heavily on intermediaries paid between EUR 200 and EUR 600 to provide their bank cards and online credentials, subsequently declaring them lost to obscure the financial trail. This case highlights how attackers build extensive libraries of compromised credentials, which can later be weaponized or sold to more advanced threat actors for lateral movement into higher-value targets.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3. Lateral Movement: From Low-Level Access to Critical Systems<br><\/strong><br>The true danger of credential theft lies in its facilitation of lateral movement. Attackers frequently target low-level employees or peripheral systems to gain an initial foothold.<br>Once inside the network, they utilize these legitimate digital identities to move laterally, escalate privileges, and conduct long-term intelligence gathering.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" width=\"2560\" height=\"1232\" src=\"http:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/99eacef6-d963-4d58-a9b8-ac5fd79fbd70-scaled.png\" alt=\"fig4_attack_lifecyclepng\" class=\"wp-image-66\" srcset=\"https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/99eacef6-d963-4d58-a9b8-ac5fd79fbd70-scaled.png 2560w, https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/99eacef6-d963-4d58-a9b8-ac5fd79fbd70-300x144.png 300w, https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/99eacef6-d963-4d58-a9b8-ac5fd79fbd70-1024x493.png 1024w, https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/99eacef6-d963-4d58-a9b8-ac5fd79fbd70-768x370.png 768w, https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/99eacef6-d963-4d58-a9b8-ac5fd79fbd70-1536x739.png 1536w, https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/99eacef6-d963-4d58-a9b8-ac5fd79fbd70-2048x986.png 2048w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This stealthy approach enables malicious actors to blend in with normal administrative activity. By utilizing built-in tools (such as PowerShell or Remote Desktop Protocol) and  busing cloud integrations (like OAuth applications), attackers can remain undetected for months. They map the network architecture, identify critical assets, and position hemselves for a devastating strike\u2014all while bypassing the sophisticated intrusion detection systems guarding the perimeter.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>4. Supply Chain Compromise: The Ultimate \u201cSide-Door\u201d<br><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When a target organization\u2019s internal security is too robust to breach directly, attackers pivot to the supply chain. By compromising a trusted third-party vendor, IT service<br>provider, or software developer, threat actors gain a legitimate conduit into the final victim\u2019s network. In the fourth quarter of 2025, supply chain attacks shifted from isolated incidents to systemic failures, driven by the abused trust in developer tools and software installers [6].<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" width=\"2508\" height=\"1567\" src=\"http:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/fe5f2a7c-bc84-44e5-bdf0-85de267e25c4.png\" alt=\"fig2_supply_chain_impactpng\" class=\"wp-image-67\" srcset=\"https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/fe5f2a7c-bc84-44e5-bdf0-85de267e25c4.png 2508w, https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/fe5f2a7c-bc84-44e5-bdf0-85de267e25c4-300x187.png 300w, https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/fe5f2a7c-bc84-44e5-bdf0-85de267e25c4-1024x640.png 1024w, https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/fe5f2a7c-bc84-44e5-bdf0-85de267e25c4-768x480.png 768w, https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/fe5f2a7c-bc84-44e5-bdf0-85de267e25c4-1536x960.png 1536w, https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/fe5f2a7c-bc84-44e5-bdf0-85de267e25c4-2048x1280.png 2048w\" sizes=\"(max-width: 2508px) 100vw, 2508px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The cybersecurity paradigm has shifted. High-security organizations in Greece and across Europe can no longer rely solely on hardening their direct perimeters. The proliferation of AI-enhanced social engineering, the industrialization of credential theft, and the systemic vulnerability of the digital supply chain require a holistic defense strategy. Security odels must evolve to scrutinize the entire dependency tree, monitor for abnormal behavior within trusted channels, and assume that the perimeter has already been bypassed via a compromised identity or a trusted thirdparty<br>update.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>References<\/strong><br>[1] ENISA. (2025). ENISA Threat Landscape 2025.<br>[2] Europol. (2026). IOCTA 2026 &#8211; The evolving threat landscape.<br>[3] Chambers and Partners. (2026). Cybersecurity 2026 &#8211; Greece: Trends and<br>Developments.<br>[4] Ministry of Digital Governance, Hellenic Republic. (2020). National Cybersecurity<br>Strategy 2020-2025.<br>[5] Greek City Times. (2025). Massive Cybercrime Network Dismantled After Draining<br>Hundreds of Bank Accounts Across Greece.<br>[6] Sygnia. (2026). Supply Chain Attacks in Q4 2025: From Isolated Incidents to<br>Systemic Failures.<br>[7] Group-IB. (2026). Six Supply Chain Attack Groups to Watch Out for in 2026.<br>[8] Huntress. (2025). Rising Supply Chain Attacks on Cybersecurity Ecosystems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Find more<a href=\"https:\/\/levelzero.gr\/articles\/\" data-type=\"page\" data-id=\"22\"> Cyber Security articles<\/a> or <a href=\"https:\/\/levelzero.gr\/contact-levelzero\/\" data-type=\"page\" data-id=\"26\">contact us<\/a> to learn how to better protect yourself, your business, and your digital environment from modern cyber threats.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Bypassing High- Security Defenses via Indirect Cyberattacks As corporate cybersecurity perimeters become increasingly sophisticated, threat actors are shifting their focus away from direct technical exploitation. Instead, they are adopting indirect methodologies\u2014leveraging social engineering, credential theft, and supply chain compromises to bypass high-security defenses. This report analyzes the evolution of hese \u201cside-door\u201d attacks across Europe, with a specific focus on the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":264,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[39,35,16,15,33,38,24,40,34,37,36],"class_list":["post-64","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-security-news","tag-credential-theft","tag-cybersecurity","tag-greece","tag-levelzero","tag-side-door","tag-sms-phishing","tag-social-engineering","tag-supply-chain","tag-threat","tag-trusted-third-party-relationships","tag-vulnerabilities"],"rttpg_featured_image_url":{"full":["https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/02-ebd32a1b-931a-4fab-b0e9-10b12e238561.webp",1000,1333,false],"landscape":["https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/02-ebd32a1b-931a-4fab-b0e9-10b12e238561.webp",1000,1333,false],"portraits":["https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/02-ebd32a1b-931a-4fab-b0e9-10b12e238561.webp",1000,1333,false],"thumbnail":["https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/02-ebd32a1b-931a-4fab-b0e9-10b12e238561-150x150.webp",150,150,true],"medium":["https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/02-ebd32a1b-931a-4fab-b0e9-10b12e238561-225x300.webp",225,300,true],"large":["https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/02-ebd32a1b-931a-4fab-b0e9-10b12e238561-768x1024.webp",720,960,true],"1536x1536":["https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/02-ebd32a1b-931a-4fab-b0e9-10b12e238561.webp",1000,1333,false],"2048x2048":["https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/02-ebd32a1b-931a-4fab-b0e9-10b12e238561.webp",1000,1333,false],"trp-custom-language-flag":["https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/02-ebd32a1b-931a-4fab-b0e9-10b12e238561.webp",9,12,false],"bosa-cyber-security-1920-550":["https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/02-ebd32a1b-931a-4fab-b0e9-10b12e238561-1000x550.webp",1000,550,true],"bosa-cyber-security-1370-550":["https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/02-ebd32a1b-931a-4fab-b0e9-10b12e238561-1000x550.webp",1000,550,true],"bosa-cyber-security-590-310":["https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/02-ebd32a1b-931a-4fab-b0e9-10b12e238561-590x310.webp",590,310,true],"bosa-cyber-security-420-380":["https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/02-ebd32a1b-931a-4fab-b0e9-10b12e238561-420x380.webp",420,380,true],"bosa-cyber-security-420-300":["https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/02-ebd32a1b-931a-4fab-b0e9-10b12e238561-420x300.webp",420,300,true],"bosa-cyber-security-420-200":["https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/02-ebd32a1b-931a-4fab-b0e9-10b12e238561-420x200.webp",420,200,true],"bosa-cyber-security-290-150":["https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/02-ebd32a1b-931a-4fab-b0e9-10b12e238561-290x150.webp",290,150,true],"bosa-cyber-security-80-60":["https:\/\/levelzero.gr\/wp-content\/uploads\/2026\/05\/02-ebd32a1b-931a-4fab-b0e9-10b12e238561-80x60.webp",80,60,true]},"rttpg_author":{"display_name":"admin","author_link":"https:\/\/levelzero.gr\/en\/author\/thanasiss23_n6va3fo7\/"},"rttpg_comment":0,"rttpg_category":"<a href=\"https:\/\/levelzero.gr\/en\/category\/cyber-security-news\/\" rel=\"category tag\">Cyber security NEWS<\/a>","rttpg_excerpt":"Bypassing High- Security Defenses via Indirect Cyberattacks As corporate cybersecurity perimeters become increasingly sophisticated, threat actors are shifting their focus away from direct technical exploitation. Instead, they are adopting indirect methodologies\u2014leveraging social engineering, credential theft, and supply chain compromises to bypass high-security defenses. This report analyzes the evolution of hese \u201cside-door\u201d attacks across Europe, with&hellip;","_links":{"self":[{"href":"https:\/\/levelzero.gr\/en\/wp-json\/wp\/v2\/posts\/64","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/levelzero.gr\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/levelzero.gr\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/levelzero.gr\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/levelzero.gr\/en\/wp-json\/wp\/v2\/comments?post=64"}],"version-history":[{"count":3,"href":"https:\/\/levelzero.gr\/en\/wp-json\/wp\/v2\/posts\/64\/revisions"}],"predecessor-version":[{"id":486,"href":"https:\/\/levelzero.gr\/en\/wp-json\/wp\/v2\/posts\/64\/revisions\/486"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/levelzero.gr\/en\/wp-json\/wp\/v2\/media\/264"}],"wp:attachment":[{"href":"https:\/\/levelzero.gr\/en\/wp-json\/wp\/v2\/media?parent=64"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/levelzero.gr\/en\/wp-json\/wp\/v2\/categories?post=64"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/levelzero.gr\/en\/wp-json\/wp\/v2\/tags?post=64"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}