Cyberwarfare
Cyberwarfare is the use of cyberattack, cyber attacks against an enemy State (polity), state, causing comparable harm to actual warfare and/or disrupting vital computer systems. Some intended outcomes could be espionage, sabotage, propaganda, ...
is a component of the confrontation between
Russia
Russia, or the Russian Federation, is a country spanning Eastern Europe and North Asia. It is the list of countries and dependencies by area, largest country in the world, and extends across Time in Russia, eleven time zones, sharing Borders ...
and
Ukraine
Ukraine is a country in Eastern Europe. It is the List of European countries by area, second-largest country in Europe after Russia, which Russia–Ukraine border, borders it to the east and northeast. Ukraine also borders Belarus to the nor ...
since the
Revolution of Dignity
The Revolution of Dignity (), also known as the Maidan Revolution or the Ukrainian Revolution, took place in Ukraine in February 2014 at the end of the Euromaidan protests, when deadly clashes between protesters and state forces in the capit ...
in 2013–2014. While the first attacks on information systems of private enterprises and state institutions of Ukraine were recorded during mass protests in 2013, Russian cyberweapon
Uroburos
Turla or Uroboros (Russian: Турла) is a Trojan package that is suspected by computer security researchers and Western intelligence officers to be the product of a Russian government agency of the same name.
High infection rates of the viru ...
2015 Ukraine power grid hack
On December 23, 2015, the power grid in two western oblasts of Ukraine was hacked, which resulted in power outages for roughly 230,000 consumers in Ukraine for 1-6 hours. The attack took place during the ongoing Russo-Ukrainian War (2014-present) ...
at Christmas 2015 and again in 2016, paralysis of the State Treasury of Ukraine in December 2016, a Mass hacker supply-chain attack in June 2017 and attacks on Ukrainian government websites in January 2022.
History
Russian–Ukrainian
cyberwarfare
Cyberwarfare is the use of cyberattack, cyber attacks against an enemy State (polity), state, causing comparable harm to actual warfare and/or disrupting vital computer systems. Some intended outcomes could be espionage, sabotage, propaganda, ...
is a component of the confrontation between Russia and Ukraine since the
Revolution of Dignity
The Revolution of Dignity (), also known as the Maidan Revolution or the Ukrainian Revolution, took place in Ukraine in February 2014 at the end of the Euromaidan protests, when deadly clashes between protesters and state forces in the capit ...
in 2013–2014. Russian cyberweapon
Uroburos
Turla or Uroboros (Russian: Турла) is a Trojan package that is suspected by computer security researchers and Western intelligence officers to be the product of a Russian government agency of the same name.
High infection rates of the viru ...
had been around since 2005. However, the first attacks on information systems of private enterprises and state institutions of Ukraine were recorded during mass protests in 2013. In 2013, Operation Armageddon, a Russian campaign of systematic cyber espionage on the information systems of government agencies, law enforcement, and defense agencies, began, thought to help Russia on the battlefield.
Between 2013 and 2014, some information systems of Ukrainian government agencies were affected by a computer virus known as Snake / Uroborus / Turla. In February–March 2014, as Russian troops entered Crimea communication centers were raided and Ukraine's fibre optic cables were tampered with, cutting connection between the peninsula and mainland Ukraine. Additionally Ukrainian Government websites, news and social media were shut down or targeted in DDoS attacks, while cell phones of many Ukrainian parliamentarians were hacked or jammed. Ukrainian experts also stated the beginning of a cyberwar with Russia.
Cybersecurity companies began to register an increase in the number of cyberattacks on information systems in Ukraine. The victims of Russian cyberattacks were government agencies of Ukraine, the EU, the United States, defense agencies, international and regional defense and political organizations, think tanks, the media, and dissidents. As of 2015, researchers had identified two groups of Russian hackers who have been active in the Russian-Ukrainian cyber war: the so-called
APT29
Cozy Bear is a Russian advanced persistent threat hacker group believed to be associated with Russian foreign intelligence by United States intelligence agencies and those of allied countries. Dutch signals intelligence (AIVD) and American i ...
(also known as Cozy Bear, Cozy Duke) and APT28 (also known as Sofacy Group, Tsar Team, Pawn Storm,
Fancy Bear
Fancy Bear is a Russian cyber espionage group. American cybersecurity firm CrowdStrike has stated with a medium level of confidence that it is associated with the Russian military intelligence agency GRU. The UK's Foreign and Commonwealth Offic ...
* Operation "Armageddon", 2013
* Operation "Snake", February 2014
* Attacks on the automated system "Elections", May 2014
* First Ukraine power grid hack, December 2015. Attacks using the Trojan virus BlackEnergy on energy companies in Ukraine which provide energy to Kyiv, Ivano-Frankivsk and Chernivtsi regions This was the first successful cyber attack on a power grid.
* Second Ukraine power grid hack, December 2016.
* Paralysis of the State Treasury of Ukraine, December 2016
*
2017 cyberattacks on Ukraine
A series of powerful cyberattacks using the Petya malware began on 27 June 2017 that swamped websites of Ukrainian organizations, including banks, ministries, newspapers and electricity firms. Similar infections were reported in France, Germ ...
, Mass hacker supply-chain attack, June 2017 using Petya virus According to the US Presidential Administration, this attack became the largest known hacker attack.
*
2022 Ukraine cyberattack
During the prelude to the Russian invasion of Ukraine and the Russian invasion of Ukraine, multiple cyberattacks against Ukraine were recorded, as well as some attacks on Russia. The first major cyberattack took place on 14 January 2022, and ...
, attacks on Ukrainian government websites, January 2022, one day after US-Russian negotiations on Ukraine's future in NATO failed.
* Attacks in February 2022, after Russian troops invaded eastern regions of Ukraine, took down several major Ukrainian governmental and banking websites. U.S. intelligence attributed the attacks to Russian attackers, although the Russian government denied involvement.
*Russia has tried to block Starlink in Ukraine, which provides
Internet access
Internet access is a facility or service that provides connectivity for a computer, a computer network, or other network device to the Internet, and for individuals or organizations to access or use applications such as email and the World Wide ...
via satellite services. Starlink has countered those attacks by hardening the service's software.
Cyberattack
A cyberattack (or cyber attack) occurs when there is an unauthorized action against computer infrastructure that compromises the confidentiality, integrity, or availability of its content.
The rising dependence on increasingly complex and inte ...
s against Starlink appear to have been ineffective, in part because
SpaceX
Space Exploration Technologies Corp., commonly referred to as SpaceX, is an America, American space technology company headquartered at the SpaceX Starbase, Starbase development site in Starbase, Texas. Since its founding in 2002, the compa ...
quickly updates the system's software, according to ''
The Economist
''The Economist'' is a British newspaper published weekly in printed magazine format and daily on Electronic publishing, digital platforms. It publishes stories on topics that include economics, business, geopolitics, technology and culture. M ...
Five Eyes
The Five Eyes (FVEY) is an Anglosphere intelligence alliance comprising Australia, Canada, New Zealand, the United Kingdom, and the United States. These countries are party to the multilateral UKUSA Agreement, a treaty for joint cooperat ...
report found that Russian hackers planted malwares designed to steal data to Starlink from the
Android
Android most commonly refers to:
*Android (robot), a humanoid robot or synthetic organism designed to imitate a human
* Android (operating system), a mobile operating system primarily developed by Google
* Android TV, a operating system developed ...
tablets of Ukrainian soldiers.Ukrainian Security Services said to have blocked some of the hacking attempts and conceded Russians had captured tablets on the battlefield and planted
malware
Malware (a portmanteau of ''malicious software'')Tahir, R. (2018)A study on malware and malware detection techniques . ''International Journal of Education and Management Engineering'', ''8''(2), 20. is any software intentionally designed to caus ...
s on them.
Ukrainian cyberattacks
* Operation "Prikormka (Groundbait)", May 2016
* Operation "May 9", 2016 (9 successful hacks of the sites of the separatist group "
Donetsk People's Republic
The Donetsk People's Republic (DPR; , ) is Russian-occupied territories of Ukraine, occupied territory in Ukraine that the Russian Federation has claimed to annex and declared as a Republics of Russia, republic of Russia, comprising parts o ...
", as well as Russian sites of anti-Ukrainian propaganda and resources of Russian private military companies.)
* “ Channel One” break, June 2016 (hacking of the corporate server of the Russian "Channel One" by the
Ukrainian Cyber Alliance
The Ukrainian Cyber Alliance (UCA; Ukrainian: ''Український кіберальянс'', УКА) is a community of cyberactivity from Ukraine and around the world. The UCA was formed in the spring of 2016 by the merger of two cyberact ...
of hackers FalconsFlame, Trinity and Rukh8)
* The
Surkov Leaks
In October 2016, Ukrainian hacker group CyberHunta leaked over a gigabyte of emails and other documents alleged to belong to Russian political operative and senior Kremlin official Vladislav Surkov. Known as Russia's " grey cardinal", Surkov ser ...
, October 2016 — a leak of 2,337 e-mails and hundreds of attachments, which reveal plans for seizing Crimea from Ukraine and fomenting separatist unrest in Donbas (documents dated between September 2013 and December 2014).
* The IT Army of Ukraine was established by
Mykhailo Fedorov
Mykhailo Albertovych Fedorov (, ; born 21 January 1991) is a Ukrainian politician, and businessman. He served as a Deputy Prime Minister and Minister Digital Transformation from 2019 to March 2023.First Vice Prime Minister and Minister of Digital Transformation, on 25 February 2022. The effort was initiated during the
2022 Russian invasion of Ukraine
On 24 February 2022, , starting the largest and deadliest war in Europe since World War II, in a major escalation of the Russo-Ukrainian War, conflict between the two countries which began in 2014. The fighting has caused hundreds of thou ...
. The primary aim is
cyberwarfare
Cyberwarfare is the use of cyberattack, cyber attacks against an enemy State (polity), state, causing comparable harm to actual warfare and/or disrupting vital computer systems. Some intended outcomes could be espionage, sabotage, propaganda, ...
against Russia. Fedorov requested the assistance of cyber specialist and tweeted a
Telegram
Telegraphy is the long-distance transmission of messages where the sender uses symbolic codes, known to the recipient, rather than a physical exchange of an object bearing the message. Thus flag semaphore is a method of telegraphy, whereas pi ...
with a list of 31 websites of Russian business and state organizations.
Russian-Ukrainian cyberwarfare amidst Russian invasion of Ukraine in 2022
In June 2022,
Microsoft
Microsoft Corporation is an American multinational corporation and technology company, technology conglomerate headquartered in Redmond, Washington. Founded in 1975, the company became influential in the History of personal computers#The ear ...
published the report on Russian cyber attacks, and concluded that state-backed Russian hackers "have engaged in "strategic espionage" against governments, think tanks, businesses and aid groups" in 42 countries supporting Kyiv.
In April 2022, Microsoft report shared new details on Russian cyberwarfare against Ukraine, for instance Microsoft has reported that in some cases, hacking and military operations worked in tandem against Ukraine related target.
See also
*
WannaCry ransomware attack
The WannaCry ransomware attack was a worldwide cyberattack in May 2017 by the WannaCry ransomware cryptoworm, which targeted computers running the Microsoft Windows operating system by encrypting data and demanding ransom payments in the form ...
, May 2017
*
Chinese cyberwarfare
Cyberwarfare is the strategic use of computer technology to disrupt the functions of a state or organization, specifically through the deliberate targeting of information systems for military or tactical purposes. In the People's Republic of Chin ...
*
Cyberwarfare by Russia
Cyberwarfare by Russia includes denial of service attacks, hacker attacks, dissemination of disinformation and propaganda, participation of state-sponsored teams in political blogs, internet surveillance using SORM technology, persecution of ...
*
Cyberwarfare in the United States
Cyberwarfare is the use of computer technology to disrupt the activities of a state or organization, especially the deliberate attacking of information systems for strategic or military purposes. As a major developed economy, the United States ...
*
Cyberwarfare and Iran
Cyberwarfare is a part of the Iranian government's "soft war" military strategy. Being both a victim and wager of cyberwarfare, Iran is considered an emerging military power in the field. Since November 2010, an organization called "The Cyber Def ...
*
List of cyber warfare forces
Many countries around the world maintain military units that are specifically trained to operate in a cyberwarfare environment. In several cases these units act also as the national computer emergency response team for civilian cybersecurity thre ...
*
Starlink satellite services in Ukraine
In February 2022, two days after Russia's full-scale invasion, Ukraine requested that the American aerospace company SpaceX activate their Starlink satellite internet service in the country, to replace internet and communication networks degra ...
*
Vulkan files leak
The Vulkan files are a leaked set of emails, and other documents, implicating the Russian company NTC Vulkan () in acts of cybercrime, political interference in foreign affairs (such as in the 2016 United States presidential election) through soc ...