Russian hackers preparing new cyber assault against Ukraine: Microsoft

The report, authored by the tech giant’s cyber security research and analysis team, outlines a series of new discoveries about how Russian hackers have operated during the Ukraine conflict and what may come next.

Russian hackers appear to be preparing a renewed wave of cyber attacks against Ukraine, including a "ransomware-style" threat to organizations serving Ukraine's supply lines, a research report by Microsoft said on Wednesday.

The report, authored by the tech giant's cyber security research and analysis team, outlines a series of new discoveries about how Russian hackers have operated during the Ukraine conflict and what may come next.

"Since January 2023, Microsoft has observed Russian cyber threat activity adjusting to boost destructive and intelligence gathering capacity on Ukraine and its partners' civilian and military assets," the report reads. One group "appears to be preparing for a renewed destructive campaign."

The findings come as Russia has been introducing new troops to the battlefield in eastern Ukraine, according to Western security officials. Ukraine Defense Minister Oleksiy Reznikov last month warned that Russia could accelerate its military activities surrounding the Feb. 24 anniversary of its invasion.

The Russian embassy in Washington did not immediately respond to a request for comment.

Experts say the tactic of combining physical military operations with cyber techniques mirrors prior Russian activity.

"Pairing kinetic attacks with efforts to disrupt or deny defenders' ability to coordinate and to use cyber-dependent technology is not a new strategic approach," said Emma Schroeder, associate director of the Atlantic Council's Cyber Statecraft Initiative.

Microsoft found that a particularly sophisticated Russian hacking team, known within the cyber security research community as Sandworm, was testing "additional ransomware-style capabilities that could be used in destructive attacks on organizations outside Ukraine that serve key functions in Ukraine's supply lines."

A ransomware attack typically involves hackers penetrating an organization, encrypting their data and extorting them for payment to regain access. Historically, ransomware has also been used as cover for more malicious cyber activity, including so-called wipers that simply destroy data.

Since January 2022, Microsoft said it had discovered at least nine different wipers and two types of ransomware variants used against more than 100 Ukrainian organizations.

These developments have been paired with a growth in more stealthy Russian cyber operations designed to directly compromise organizations in countries allied to Ukraine, according to the report.

"In nations throughout the Americas and Europe, especially Ukraine's neighbors, Russian threat actors have sought access to government and commercial organizations involved in efforts to support Ukraine," said Clint Watts, general manager for Microsoft's Digital Threat Analysis Center.

X
Sitelerimizde reklam ve pazarlama faaliyetlerinin yürütülmesi amaçları ile çerezler kullanılmaktadır.

Bu çerezler, kullanıcıların tarayıcı ve cihazlarını tanımlayarak çalışır.

İnternet sitemizin düzgün çalışması, kişiselleştirilmiş reklam deneyimi, internet sitemizi optimize edebilmemiz, ziyaret tercihlerinizi hatırlayabilmemiz için veri politikasındaki amaçlarla sınırlı ve mevzuata uygun şekilde çerez konumlandırmaktayız.

Bu çerezlere izin vermeniz halinde sizlere özel kişiselleştirilmiş reklamlar sunabilir, sayfalarımızda sizlere daha iyi reklam deneyimi yaşatabiliriz. Bunu yaparken amacımızın size daha iyi reklam bir deneyimi sunmak olduğunu ve sizlere en iyi içerikleri sunabilmek adına elimizden gelen çabayı gösterdiğimizi ve bu noktada, reklamların maliyetlerimizi karşılamak noktasında tek gelir kalemimiz olduğunu sizlere hatırlatmak isteriz.