Cyber Attacks

Over 200 Russian cyberattacks against Ukraine documented by Microsoft

0

Microsoft reported that at least six different Russia-aligned threat actors have launched over 237 cyberattacks against Ukraine from February 23 to April 8, which includes 38 discrete destructive attacks that irrevocably destroyed files in hundreds of systems across dozens of organizations in the country.

The Digital Security Unit (DSU) of the company stated that collectively, the cyber and kinetic actions work to disrupt or degrade Ukrainian government and military functions and undermine the public’s trust in those same institutions.

Some of the main malware families that were used for launching destructive activity as part of Russia’s digital assaults include: WhisperGate, HermeticWiper (FoxBlade aka KillDisk), HermeticRansom (SonicVote), IssacWiper (Lasainraw), CaddyWiper, DesertBlade, DoubleZero (FiberLake), and Industroyer2.

  • WhisperGate, HermeticWiper, IssacWiper, and CaddyWiper are data wipers that could overwrite data and render machines unbootable.
  • DoubleZero is a .NET malware capable of data deletion.
  • DesertBlade is also a data wiper that was launched against an unnamed broadcasting company in Ukraine on March 1.
  • SonicVote is a file encryptor detected in conjunction with HermeticWiper to disguise the intrusions as a ransomware attack.
  • Industroyer2 targets operational technology to sabotage critical industrial production and processes.

Microsoft attributed HermeticWiper, CaddyWiper, and Industroyer2 to a Russian state-sponsored actor named Sandworm (aka Iridium). The WhisperGate attacks have been tied to a previously unknown cluster dubbed DEV-0586, which is believed to be affiliated to Russia’s GRU military intelligence.

Of the total 38 destructive attacks, 32% are estimated to have singled out Ukrainian government organizations at the national, regional and city levels, and more than 40% of the attacks targeted organizations in critical infrastructure sectors.

Besides, Microsoft also found Nobelium, the threat actor responsible for the 2020 SolarWinds supply chain attack, trying to breach IT firms serving government customers in NATO member states, using the access to siphon data from Western foreign policy organizations.

Other malicious attacks involve phishing campaigns targeting military entities (Fancy Bear aka Strontium) and government officials (Primitive Bear aka Actinium) as well as data theft (Energetic Bear aka Bromine) and reconnaissance (Venomous Bear aka Krypton) operations.

Tom Burt, corporate vice president of customer security and trust stated that as Russian threat actors have been mirroring and augmenting military actions, cyberattacks are believed to continue to escalate as the conflict rages. He added that it is likely that the attacks observed so far are only a fraction of activity targeting Ukraine.

Image Credits : Euronews

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Organizations in India to report security breaches within 6 hrs to CERT-In

Previous article

U.S. DoD tricked into paying millions to phishing actor

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *