The Times Australia
The Times World News

.

Russia is using an onslaught of cyber attacks to undermine Ukraine's defence capabilities

  • Written by Mamoun Alazab, Associate Professor, Charles Darwin University
Russia is using an onslaught of cyber attacks to undermine Ukraine's defence capabilities

As Ukrainian cities come under air attack from Russian forces, the country has also suffered the latest blows in an ongoing campaign of cyber attacks. Several of Ukraine’s bank and government department websites crashed on Wednesday, the BBC[1] reports.

The incident follows a similar attack just over a week ago[2], in which some 70 Ukrainian government websites crashed. Ukraine and the United States squarely blamed Russia.

With a full-scale invasion now evident[3], Ukraine can expect to contend soon with more cyber attacks. These have the potential to cripple infrastructure, affecting water, electricity and telecommunication services – further debilitating Ukraine as it attempts to contend with Russian military aggression.

A critical part of Russia’s operations

Cyber attacks fall under the traditional attack categories of sabotage, espionage and subversion.

They can be carried out more rapidly than standard weapon attacks, and largely remove barriers of time and distance. Launching them is relatively cheap and simple, but defending against them is increasingly costly and difficult.

After Russia’s withdrawal from Georgia in 2008, President Vladimir Putin led an effort to modernise the Russian military[4] and incorporate cyber strategies. State-sanctioned cyber attacks have since been at the forefront of Russia’s warfare strategy.

The Russian Main Intelligence Directorate (GRU) typically orchestrates these attacks. They often involve using customised malware (malicious software) to target the hardware and software underpinning a target nation’s systems and infrastructure.

Among the latest attacks[5] on Ukraine was a distributed denial of service (DDoS) attack.

According to Ukraine’s minister of digital transformation, Mykhailo Fedorov, several Ukrainian government and banking websites went offline as a result. DDoS attacks use bots to flood an online service, overwhelming it until it crashes, preventing access for legitimate users.

A destructive “data-wiping” software has also been found circulating on hundreds of computers in Ukraine, according to reports[6], with suspicion falling on Russia.

On February 15, Ukraine’s cyber police said citizens were receiving fake text messages claiming ATMs had gone offline (although this wasn’t confirmed). Many citizens scrambled to withdraw money, which caused panic[7] and uncertainty.

Ongoing onslaught

In December 2015, the GRU targeted Ukraine’s industrial control systems networks with destructive malware. This caused power outages in the western Ivano-Frankivsk region. About 700,000 homes were left without power for about six hours.

Read more: Cyberattack on Ukraine grid: here's how it worked and perhaps why it was done[8]

This happened again in December 2016. Russia developed a custom malware called CrashOverride[9] to target Ukraine’s power grid. An estimated one-fifth of Kiev’s total power capacity was cut[10] for about an hour.

More recently, US officials charged six Russian GRU officers[11] in 2020 for deploying the NotPetya ransomware. This ransomware affected computer networks worldwide, targeting hospitals and medical facilities in the United States, and costing more than US$1 billion in losses.

NotPetya was also used against Ukrainian government ministries, banks and energy companies, among other victims. The US Department of Justice called it “some of the world’s most destructive malware to date”.

Another Russia-sponsored attack[12] that began as early as January 2021 targeted Microsoft Exchange servers. The attack provided hackers access to email accounts and associated networks all over the world, including in Ukraine, the US and Australia.

Russia’s 2008 invasion of Georgia was accompanied by a well-coordinated cyber attack run by state-sponsored hackers. These were primarily DDoS attacks that forced a number of Georgian government and commercial websites offline. Getty Images

International cyber aid

Ukraine faces serious risks right now. A major cyber attack could disrupt essential services and further undermine national security and sovereignty.

The support of cyber infrastructure has been recognised as an important aspect of international aid. Six European Union countries[13] (Lithuania, Netherlands, Poland, Estonia, Romania and Croatia) are sending cyber security experts to help Ukraine deal with these threats.

Australia has also committed to providing cyber security assistance to the Ukrainian government, through a bilateral Cyber Policy Dialogue. This will allow for exchanges of cyber threat perceptions, policies and strategies. Australia has also said it will provide cyber security training[14] for Ukrainian officials.

The international implications of the Russia-Ukraine situation have been noted. Last week New Zealand’s National Cyber Security Centre released a General Security Advisory[15] encouraging organisations to prepare for cyber attacks as a flow-on effect of the crisis.

The advisory provides a list of resources for protection and strongly recommends that organisations assess their security preparedness against potential threats.

The Australian Cyber Security Centre has since issued similar warnings[16].

Evading responsibility

Historically, Russia has managed to evade much of the responsibility for cyber attacks. In conventional warfare, attribution is usually straightforward. But in cyberspace it is very complex, and can be time-consuming and costly.

It’s easy for a country to deny its involvement in a cyber attack (both Russia and China routinely do so). The Russian embassy in Canberra has also denied involvement[17] in the latest attacks against Ukraine.

One reason plausible deniability can usually be maintained is because cyber attacks can be launched from an unwitting host. For example, a victim’s compromised device (called a “zombie” device) can be used to continue a chain of attacks.

So while the operation may be run by the perpetrator’s command and control servers, tracing it back to them becomes difficult.

References

  1. ^ the BBC (www.bbc.com)
  2. ^ just over a week ago (www.bbc.com)
  3. ^ invasion now evident (www.aljazeera.com)
  4. ^ modernise the Russian military (www.nytimes.com)
  5. ^ latest attacks (www.cnbc.com)
  6. ^ reports (www.reuters.com)
  7. ^ caused panic (spravdi.gov.ua)
  8. ^ Cyberattack on Ukraine grid: here's how it worked and perhaps why it was done (theconversation.com)
  9. ^ CrashOverride (www.cisa.gov)
  10. ^ was cut (www.wired.com)
  11. ^ US officials charged six Russian GRU officers (www.justice.gov)
  12. ^ Russia-sponsored attack (www.volexity.com)
  13. ^ Six European Union countries (www.reuters.com)
  14. ^ cyber security training (www.abc.net.au)
  15. ^ released a General Security Advisory (www.cisa.gov)
  16. ^ similar warnings (www.abc.net.au)
  17. ^ denied involvement (www.abc.net.au)

Read more https://theconversation.com/russia-is-using-an-onslaught-of-cyber-attacks-to-undermine-ukraines-defence-capabilities-177638

Times Magazine

DIY Is In: How Aussie Parents Are Redefining Birthday Parties

When planning his daughter’s birthday, Rich opted for a DIY approach, inspired by her love for drawing maps and giving clues. Their weekend tradition of hiding treats at home sparked the idea, and with a pirate ship playground already chosen as t...

When Touchscreens Turn Temperamental: What to Do Before You Panic

When your touchscreen starts acting up, ignoring taps, registering phantom touches, or freezing entirely, it can feel like your entire setup is falling apart. Before you rush to replace the device, it’s worth taking a deep breath and exploring what c...

Why Social Media Marketing Matters for Businesses in Australia

Today social media is a big part of daily life. All over Australia people use Facebook, Instagram, TikTok , LinkedIn and Twitter to stay connected, share updates and find new ideas. For businesses this means a great chance to reach new customers and...

Building an AI-First Culture in Your Company

AI isn't just something to think about anymore - it's becoming part of how we live and work, whether we like it or not. At the office, it definitely helps us move faster. But here's the thing: just using tools like ChatGPT or plugging AI into your wo...

Data Management Isn't Just About Tech—Here’s Why It’s a Human Problem Too

Photo by Kevin Kuby Manuel O. Diaz Jr.We live in a world drowning in data. Every click, swipe, medical scan, and financial transaction generates information, so much that managing it all has become one of the biggest challenges of our digital age. Bu...

Headless CMS in Digital Twins and 3D Product Experiences

Image by freepik As the metaverse becomes more advanced and accessible, it's clear that multiple sectors will use digital twins and 3D product experiences to visualize, connect, and streamline efforts better. A digital twin is a virtual replica of ...

The Times Features

What Makes Certain Rings or Earrings Timeless Versus Trendy?

Timeless rings and earrings are defined by designs that withstand the test of time, quality craftsmanship, and versatility. Trendy pieces, on the other hand, often stand testimony ...

Italian Street Kitchen: A Nation’s Favourite with Expansion News on Horizon

Successful chef brothers, Enrico and Giulio Marchese, weigh in on their day-to-day at Australian foodie favourite, Italian Street Kitchen - with plans for ‘ambitious expansion’ to ...

What to Expect During a Professional Termite Inspection

Keeping a home safe from termites isn't just about peace of mind—it’s a vital investment in the structure of your property. A professional termite inspection is your first line o...

Booty and the Beasts - The Podcast

Cult TV Show Back with Bite as a Riotous New Podcast  The show that scandalised, shocked and entertained audiences across the country, ‘Beauty and the Beast’, has returned in ...

A Guide to Determining the Right Time for a Switchboard Replacement

At the centre of every property’s electrical system is the switchboard – a component that doesn’t get much attention until problems arise. This essential unit directs electrici...

Après Skrew: Peanut Butter Whiskey Turns Australia’s Winter Parties Upside Down

This August, winter in Australia is about to get a lot nuttier. Skrewball Whiskey, the cult U.S. peanut butter whiskey that’s taken the world by storm, is bringing its bold brand o...