The “Side-Door” Threat

Cyber security awareness against phishing scams malware and online fraud

Bypassing High- Security Defenses via Indirect Cyberattacks

As corporate cybersecurity perimeters become increasingly sophisticated, threat actors are shifting their focus away from direct technical exploitation. Instead, they are adopting indirect methodologies—leveraging social engineering, credential theft, and supply chain compromises to bypass high-security defenses. This report analyzes the evolution of hese “side-door” attacks across Europe, with a specific focus on the Greek threat landscape. By exploiting human vulnerabilities and trusted third-party relationships, attackers are successfully infiltrating organizations that would otherwise be highly resilient to direct assault.

1. The Evolution of Social Engineering in Europe

Social engineering has evolved from rudimentary mass-phishing campaigns into highly targeted, AI-driven operations. According to the European Union Agency for Cybersecurity (ENISA), by early 2025, AI-supported phishing campaigns represented more than 80% of observed social engineering activity worldwide [1].
The weaponization of Generative AI has fundamentally altered the threat landscape. Adversaries now utilize AI to craft highly convincing, grammatically perfect messages
in local languages. This development is particularly significant for countries like Greece, where the complexity of the language previously served as a natural barrier against automated, large-scale phishing campaigns.

fig1_social_eng_vectorspng

The primary objective of these campaigns is no longer immediate financial extortion, but rather credential harvesting. Threat actors seek to obtain valid user account details, allowing them to bypass perimeter defenses by simply “logging in” rather than breaking in. A notable example occurred in May 2025, when the threat group ShinyHunters launched a massive social engineering campaign that siphoned over a billion Salesforce customer records by tricking users into revealing their credentials [2].

2. The Greek Landscape: A Surge in Identity-Based Attacks

Research indicates that the evolution of cybercrime in Greece exhibits distinctive national characteristics, primarily centered around sophisticated fraud and identity theft [3]. The National Cybersecurity Strategy data reveals a concerning trend: identity theft attacks have steadily climbed the national threat rankings, moving from 13th place in 2020 to 7th place by 2025 [4].

Case Study: The 2025 Greek Cyber Fraud Network

In October 2025, Greek prosecutors dismantled what is described as the largest organized cyber fraud operation ever uncovered in the country. The network involved
over 1,200 suspects and generated illicit profits exceeding EUR 6 million [5]. The methodology of this network exemplifies the modern approach to credential theft:
Sophisticated Phishing: The group utilized highly targeted SMS phishing (smishing) and email campaigns, sending fake bank messages with fraudulent links to steal login credentials. Target Selection: Rather than solely targeting large corporations, the network focused on small business owners, media outlets, churches, and monasteries. In
one instance, a single victim lost EUR 78,690 after clicking a fraudulent link. Operational Hierarchy: The network operated with a corporate-like structure, including ringleaders, coordinators, data specialists, and makeshift call centers located in Roma settlements (Zephyri, Zevgolatio, Examilia) that changed locations frequently to evade detection.
Money Mules: The scheme relied heavily on intermediaries paid between EUR 200 and EUR 600 to provide their bank cards and online credentials, subsequently declaring them lost to obscure the financial trail. This case highlights how attackers build extensive libraries of compromised credentials, which can later be weaponized or sold to more advanced threat actors for lateral movement into higher-value targets.

3. Lateral Movement: From Low-Level Access to Critical Systems

The true danger of credential theft lies in its facilitation of lateral movement. Attackers frequently target low-level employees or peripheral systems to gain an initial foothold.
Once inside the network, they utilize these legitimate digital identities to move laterally, escalate privileges, and conduct long-term intelligence gathering.

fig4_attack_lifecyclepng

This stealthy approach enables malicious actors to blend in with normal administrative activity. By utilizing built-in tools (such as PowerShell or Remote Desktop Protocol) and busing cloud integrations (like OAuth applications), attackers can remain undetected for months. They map the network architecture, identify critical assets, and position hemselves for a devastating strike—all while bypassing the sophisticated intrusion detection systems guarding the perimeter.

4. Supply Chain Compromise: The Ultimate “Side-Door”

When a target organization’s internal security is too robust to breach directly, attackers pivot to the supply chain. By compromising a trusted third-party vendor, IT service
provider, or software developer, threat actors gain a legitimate conduit into the final victim’s network. In the fourth quarter of 2025, supply chain attacks shifted from isolated incidents to systemic failures, driven by the abused trust in developer tools and software installers [6].

fig2_supply_chain_impactpng

The cybersecurity paradigm has shifted. High-security organizations in Greece and across Europe can no longer rely solely on hardening their direct perimeters. The proliferation of AI-enhanced social engineering, the industrialization of credential theft, and the systemic vulnerability of the digital supply chain require a holistic defense strategy. Security odels must evolve to scrutinize the entire dependency tree, monitor for abnormal behavior within trusted channels, and assume that the perimeter has already been bypassed via a compromised identity or a trusted thirdparty
update.

References
[1] ENISA. (2025). ENISA Threat Landscape 2025.
[2] Europol. (2026). IOCTA 2026 – The evolving threat landscape.
[3] Chambers and Partners. (2026). Cybersecurity 2026 – Greece: Trends and
Developments.
[4] Ministry of Digital Governance, Hellenic Republic. (2020). National Cybersecurity
Strategy 2020-2025.
[5] Greek City Times. (2025). Massive Cybercrime Network Dismantled After Draining
Hundreds of Bank Accounts Across Greece.
[6] Sygnia. (2026). Supply Chain Attacks in Q4 2025: From Isolated Incidents to
Systemic Failures.
[7] Group-IB. (2026). Six Supply Chain Attack Groups to Watch Out for in 2026.
[8] Huntress. (2025). Rising Supply Chain Attacks on Cybersecurity Ecosystems.

Find more Cyber Security articles or contact us to learn how to better protect yourself, your business, and your digital environment from modern cyber threats.

About the Author

Αφήστε μια απάντηση

Η ηλ. διεύθυνση σας δεν δημοσιεύεται. Τα υποχρεωτικά πεδία σημειώνονται με *

You may also like these