{"id":1799,"date":"2022-04-20T13:11:50","date_gmt":"2022-04-20T18:11:50","guid":{"rendered":"https:\/\/ardent-security.com\/?p=1799"},"modified":"2022-04-20T13:26:29","modified_gmt":"2022-04-20T18:26:29","slug":"ukraine-russian-towards-a-first-world-cyberwar","status":"publish","type":"post","link":"https:\/\/ardent-security.com\/en\/ukraine-russian-towards-a-first-world-cyberwar\/","title":{"rendered":"Ukraine Russian: towards a first world cyberwar"},"content":{"rendered":"<h2>Cyberattacks in Ukraine: Could It Lead to a First World Cyberwar?<\/h2>\n<p><em>When the US needed a place to test its Cold War atomic weapons, it used an isolated atoll named \u201cBikini\u201d in the Marshall Islands of the Pacific. The 25 mile long ring-shaped coral atoll witnessed more than 20 tests from 1946 into the 1960s. Today several foreign actors could be using the war in Ukraine as a test site for their cyber warfare techniques, tactics and procedures (TTPs). Cyberattacks can quickly cross borders, so it\u2019s critical that governments and corporations have the proper defenses in place for these evolving threats. \u00a0<\/em><\/p>\n<p>Ukraine\u2019s infrastructure is similar to Western Europe, Canada and the US and though its cyber defenses are more limited than that of the <a href=\"https:\/\/cybernews.com\/resources\/5-eyes-9-eyes-14-eyes-countries\/\">Five Eyes (FVEY) intelligence alliance<\/a> (Australia, Canada, New Zealand, UK and US). This makes it an attractive target for countries such as Iran, N. Korea and China to test their own cyber capabilities.<\/p>\n<p>What form have the cyberattacks in Ukraine taken so far? The first attacks seemed pro-Russian. They took down government websites with the <a href=\"https:\/\/en.interfax.com.ua\/news\/general\/791472.html?mid=1#cid=241671\">message<\/a> \u201cBe afraid and expect the worse.\u201d This useful advice was then followed by <a href=\"https:\/\/www.csoonline.com\/article\/3647072\/a-timeline-of-russian-linked-cyberattacks-on-ukraine.html\">false claims<\/a> that \u201cAll your personal data has been sent to a public network. All data on your computer is destroyed and cannot be recovered.\u201d though the country\u2019s State Bureau of Investigations &#8211; similar to US FBI &#8211; <a href=\"https:\/\/en.interfax.com.ua\/news\/general\/791483.html?mid=1#cid=242718\">denied<\/a> that any data was actually stolen. At one point Ukraine\u2019s deputy secretary of their National Security and Defense Council <a href=\"https:\/\/www.reuters.com\/world\/europe\/exclusive-ukraine-suspects-group-linked-belarus-intelligence-over-cyberattack-2022-01-15\/\">attributed<\/a> the attacks to a hacker group linked to the Belarusian intelligence service.<\/p>\n<p>In mid-January Microsoft <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/01\/15\/destructive-malware-targeting-ukrainian-organizations\/\">reported<\/a> wiper malware disguised as ransomware (<em>tracked as DEV-0586<\/em>) on several Ukrainian governmental agencies and organizations systems. Activation of the wiper malware would have killed the systems. Had it been placed in anticipation of the Russian invasion, like land mines waiting to be remotely activated?<\/p>\n<p>The US Dept. of Homeland Security (DHS) shortly thereafter issued an <a href=\"https:\/\/www.cnn.com\/2022\/01\/24\/politics\/russia-cyberattack-warning-homeland-security\/index.html\">intelligence bulletin<\/a> to critical US infrastructure operators and state and local governments warning of a possible Russian counter cyberattack if Moscow believed the US or NATO response to a potential invasion of Ukraine \u201cthreatened [Russia\u2019s] long-term national security.\u201d<\/p>\n<p>February brought a <a href=\"https:\/\/www.wsj.com\/livecoverage\/russia-ukraine-latest-news\/card\/some-ukrainian-government-banking-websites-disrupted-again-HnTGLkoVmpezDz8UBdPY\">distributed denial of service<\/a> (DDOS) attack on the Ukrainian defense ministry, military sites and two banks. There was evidence of Russian penetration of their military, energy and other critical networks to collect information needed to support the imminent invasion.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1797 aligncenter\" src=\"https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Tank.jpg\" alt=\"\" width=\"745\" height=\"496\" \/><\/p>\n<p>In late February, researchers from ESET and Symantec reported new malware called <a href=\"https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/ukraine-wiper-malware-russia\"><em>HermeticWiper<\/em><\/a> spreading across Ukraine, Lithuania and Latvia. The <a href=\"https:\/\/cyber.gc.ca\/en\/alerts\/disruptive-activity-against-ukrainian-organizations\">Canadian Centre for Cyber Security issued its Alert<\/a> regarding this malware on February 23<sup>rd<\/sup> referencing the following articles:<\/p>\n<ul>\n<li>HermeticWiper &#8211; <a href=\"https:\/\/www.sentinelone.com\/labs\/hermetic-wiper-ukraine-under-attack\/\">New Destructive Malware Used In Cyber Attacks on Ukraine<\/a><\/li>\n<li>HermeticWiper &#8211; <a href=\"https:\/\/www.welivesecurity.com\/2022\/02\/24\/hermeticwiper-new-data-wiping-malware-hits-ukraine\/\">New data\u2011wiping malware hits Ukraine<\/a><\/li>\n<li><a href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/hermetic-wiper-resurgence-targeted-attacks-ukraine\">Hermetic Wiper &amp; resurgence of targeted attacks on Ukraine<\/a><\/li>\n<li><a href=\"https:\/\/symantec-enterprise-blogs.security.com\/blogs\/threat-intelligence\/ukraine-wiper-malware-russia\">Ukraine &#8211; Disk-wiping Attacks Precede Russian Invasion<\/a><\/li>\n<\/ul>\n<p>One of the more visible attacks was against Viasat, the world\u2019s largest commercial satellite company. In late February, <a href=\"https:\/\/news.sky.com\/story\/satellite-giant-viasat-probes-suspected-broadband-cyberattack-amid-russia-fears-12554004?awc=11005_1649520039_c85e267f389658dfecc5b8409b6e7eac&amp;dcmp=afc-531979-na-na-longtail&amp;dclid=COPXlICth_cCFUGhAAAdwTYAVA\">Sky News<\/a> reported the multifaceted cyberattack against its KA-SAT network interrupted service to several thousand broadband customers in Ukraine and tens of thousands across Europe. Ukraine\u2019s response included <a href=\"https:\/\/techcrunch.com\/2022\/02\/27\/ukraine-takes-the-resistance-to-cyberspace-assembling-an-it-army-to-hack-sites-from-russia-and-its-allies-calls-on-tech-leaders-to-get-involved\/?mid=1#cid=692831\">a program<\/a> that signed up 184,000 civilian developers and hackers for its <em>IT Army of Ukraine<\/em>. This new group significantly increased the Ukrainian anti-cyberattack resources.<\/p>\n<p>Evidence that the Ukrainians and their allies were not purely defensive in the ongoing cyberwarfare was seen in early March when Russia\u2019s National Computer Incident Response &amp; Coordination Center <a href=\"https:\/\/safe-surf.ru\/specialists\/news\/676114\/\">published<\/a> a massive list of IP addresses and domain names it claimed were involved in ongoing nationwide DDOS attacks on Russian systems.<\/p>\n<p>When Russia finally invaded Eastern Ukraine, a group of purportedly vigilante hackers <a href=\"https:\/\/www.vice.com\/en\/article\/z3n8ea\/hackers-breach-russian-space-research-institute-website\">compromised<\/a> a website associated with Russia\u2019s Space Research Institute to post vulgar anti-Russian messages.<\/p>\n<p>Another hacktivist collective known as <em>Anonymous<\/em> <a href=\"https:\/\/www.ukrinform.net\/rubric-ato\/3421382-anonymous-hacker-group-takes-down-russias-fsb-website.html\">claimed credit<\/a> for taking down Russia\u2019s Federal Security Service (FSB) and 2,500 websites in Russia and Belarus in support of Ukraine. They also <a href=\"https:\/\/english.nv.ua\/nation\/anonymous-group-hacks-into-russian-tv-calls-on-russians-to-stop-war-in-ukraine-50222909.html\">hacked into<\/a> Russian broadband streaming services Wink, Ivi, and TV channels Russia 24, Channel One, and Moscow 24 to broadcast alleged war footage.<\/p>\n<p>Google\u2019s Threat Analysis Group <a href=\"https:\/\/blog.google\/threat-analysis-group\/update-threat-landscape-ukraine\/\">reported<\/a> widespread phishing attacks by someone in Belarus against Polish military personnel and Ukrainian officials. A hacktivist crew \u201cInternational Information Technology Battalion 300\u201d (ILIT300) was particularly creative in its use of <a href=\"https:\/\/thecryptosphere.com\/2022\/03\/08\/hacktivist-crew-ilit300-phone-bombs-russians-with-message-of-support-for-ukraine\/\">phone bombing software<\/a> developed by Ukrainian hacktivists to bypass Russian TV censors and send messages directly to Russian citizens in hopes that they would speak out against the conflict. Telegraph Moscow correspondent Nataliya Vasilyeva <a href=\"https:\/\/www.csoonline.com\/article\/3647072\/a-timeline-of-russian-linked-cyberattacks-on-ukraine.html?page=2\">confirmed<\/a> receipt of one of these calls.<\/p>\n<p>Russia was again on the receiving end of a malware attack that <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/russian-government-sites-hacked-in-supply-chain-attack\/\">compromised several<\/a> of its federal agency websites in a supply chain attack. The malware hacked the stats widget used to track visitor numbers and used it to publish invalid content. The affected websites included the Energy Ministry, the Federal State Statistics Service, the Federal Penitentiary Service, the Federal Bailiff Service, the Federal Antimonopoly Service, the Culture Ministry, and other Russian state agencies.<\/p>\n<p>Unsurprisingly, cyber criminals <a href=\"https:\/\/blog.talosintelligence.com\/2022\/02\/current-executive-guidance-for-ongoing.html\">were discovered by Cisco Talos<\/a> researchers to be trying to exploit the war and Ukrainian sympathizers by selling them supposedly offensive cyber tools that were in fact malware designed to steal credentials and cryptocurrency-related information back to the gangs. The criminals have also collected money from well-meaning donors under the pretext of supporting refugees when in fact the money was going into their own coffers.<\/p>\n<p>In late March, Sberbank \u2013 Russia\u2019s largest bank \u2013 <a href=\"https:\/\/www.technologyreview.com\/2022\/03\/21\/1047489\/activists-are-targeting-russians-with-open-source-protestware\/\">warned users<\/a> against updating their banking software due to the threat of \u201cProtestware\u201d; open source projects whose authors modified their code to protest the Ukraine invasion with antiwar messages and in one case, wiper code. Such protestware against Russia and Belorussia was reported by <a href=\"https:\/\/arstechnica.com\/information-technology\/2022\/03\/sabotage-code-added-to-popular-npm-package-wiped-files-in-russia-and-belarus\/\">Ars Technica<\/a> on March 18<sup>th<\/sup>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-1798 alignleft\" src=\"https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Electrical_Grid.jpg\" alt=\"\" width=\"610\" height=\"406\" \/><\/p>\n<p>Finally, Google\u2019s Threat Analysis Group <a href=\"https:\/\/blog.google\/threat-analysis-group\/tracking-cyber-activity-eastern-europe\/\">reported<\/a> in late March that government-backed actors from China, Iran, North Korea and Russia, plus various unaffiliated groups, were using Ukraine war-related themes to get targeted users to activate malicious emails or links.<\/p>\n<p>Bottom line: The cyber tactics and tools being used today in Ukraine will likely show up closer to home in the near future and any company that believes itself immune won\u2019t be properly prepared to respond. The attack could entail any of the following:<\/p>\n<ul>\n<li>Temporary denial-of-service (DOS)<\/li>\n<li>Crippling ransomware<\/li>\n<li>Wiper malware<\/li>\n<li>Deliberate sabotage of operational software causing permanent damage by overloading systems to destruction or by altering the function of cooling pumps or centrifuges (think Iranian <a href=\"https:\/\/spectrum.ieee.org\/the-real-story-of-stuxnet\"><em>Stuxnet<\/em> incident<\/a>)<\/li>\n<\/ul>\n<p>If it can be imagined, it will eventually happen. You need someone on your side who knows what to look for and not coincidentally, that\u2019s why Ardent-Security exists. We have the experience, training and certifications needed to prepare your company for whatever comes next.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\">Call <a href=\"https:\/\/ardent-security.com\/en\/\"><strong>Ardent Security<\/strong><\/a> today.<\/p>\n<p style=\"text-align: center;\"><strong>647-478-2600<\/strong><\/p>\n<p style=\"text-align: center;\"><strong>We can help.<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cyberattacks in Ukraine: Could It Lead to a First World Cyberwar? When the US needed a place to test its Cold War atomic weapons, it used an isolated atoll named \u201cBikini\u201d in the Marshall Islands of the Pacific. The 25 mile long ring-shaped coral atoll witnessed more than 20 tests from 1946 into the 1960s. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1795,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[5,6,8],"tags":[21,19,20],"class_list":["post-1799","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-article","category-cybersecurity","category-english","tag-canada-pentesting-hacking","tag-cybersecurity-penetrationtesting-toronto","tag-ontario"],"rttpg_featured_image_url":{"full":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine.jpg",1365,768,false],"landscape":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine.jpg",1365,768,false],"portraits":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine.jpg",1365,768,false],"thumbnail":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine-150x150.jpg",150,150,true],"medium":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine-300x169.jpg",300,169,true],"large":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine-1024x576.jpg",1024,576,true],"tf-client-image-size":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine-120x120.jpg",120,120,true],"1536x1536":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine.jpg",1365,768,false],"2048x2048":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine.jpg",1365,768,false],"trp-custom-language-flag":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine-16x9.jpg",16,9,true],"et-pb-post-main-image":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine-400x250.jpg",400,250,true],"et-pb-post-main-image-fullwidth":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine-1080x675.jpg",1080,675,true],"et-pb-portfolio-image":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine-400x284.jpg",400,284,true],"et-pb-portfolio-module-image":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine-510x382.jpg",510,382,true],"et-pb-portfolio-image-single":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine-1080x608.jpg",1080,608,true],"et-pb-gallery-module-image-portrait":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine-400x516.jpg",400,516,true],"et-pb-post-main-image-fullwidth-large":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine.jpg",1365,768,false],"et-pb-image--responsive--desktop":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine-1280x720.jpg",1280,720,true],"et-pb-image--responsive--tablet":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine-980x551.jpg",980,551,true],"et-pb-image--responsive--phone":["https:\/\/ardent-security.com\/wp-content\/uploads\/2022\/04\/ArdentSecurity_Cyberwarfare_Ukraine-480x270.jpg",480,270,true]},"rttpg_author":{"display_name":"Ardent Security","author_link":"https:\/\/ardent-security.com\/en\/author\/ardentsecurity\/"},"rttpg_comment":25,"rttpg_category":"<a href=\"https:\/\/ardent-security.com\/en\/category\/article\/\" rel=\"category tag\">article<\/a> <a href=\"https:\/\/ardent-security.com\/en\/category\/cybersecurity\/\" rel=\"category tag\">Cybersecurity<\/a> <a href=\"https:\/\/ardent-security.com\/en\/category\/english\/\" rel=\"category tag\">English<\/a>","rttpg_excerpt":"Cyberattacks in Ukraine: Could It Lead to a First World Cyberwar? When the US needed a place to test its Cold War atomic weapons, it used an isolated atoll named \u201cBikini\u201d in the Marshall Islands of the Pacific. The 25 mile long ring-shaped coral atoll witnessed more than 20 tests from 1946 into the 1960s.&hellip;","_links":{"self":[{"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/posts\/1799","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/comments?post=1799"}],"version-history":[{"count":0,"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/posts\/1799\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/media\/1795"}],"wp:attachment":[{"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/media?parent=1799"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/categories?post=1799"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ardent-security.com\/en\/wp-json\/wp\/v2\/tags?post=1799"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}