Ukraine cyberattacks: All you need to knowVish Gainon February 24, 2022 at 09:05 Silicon RepublicSilicon Republic
As the world watches with bated breath a full-scale invasion of Ukraine by Russian forces, there have also been reports of various cyberattacks hitting Ukrainian computers and websites over the past couple of days, likely a form of hybrid warfare by Russia.
Multiple sources have confirmed that Ukraine was the victim of a wave of cyberattacks yesterday (23 February), including targeted distributed denial of service (DDOS) attacks on Ukrainian government websites and a new malware found on “hundreds” of computers.
DDOS attacks are when hackers attempt to disrupt the normal traffic of a targeted server by overwhelming it with requests. This tactic is known to have been used by Russia in the past as part of its ‘hybrid warfare’ tactic, during incursions in Georgia in 2008 and Crimea in 2014.
Internet monitor NetBlocks tweeted yesterday that Ukrainian government websites such as the ministry of foreign affairs, defence and internal affairs, as well as those of the country’s security service and cabinet of ministers have “been impacted by network disruptions”.
Later in the day, Ukraine’s minister of digital transformation Mykhailo Fedorov said that a second series of DDOS attacks hit the country at about 4pm local time, this time targeting banks and the parliament, according to Reuters.
These are all in line with recent cyberattacks on Ukraine last month, when messages such as ‘be afraid and prepare for the worst’ were displayed on hacked government websites.
Even though Ukrainian websites have a swifter recovery this time around, likely due to increased preparedness, the cyberattack incident “is ongoing, with latency and outages continuing at the security service”, a researcher told BBC News.
‘Hermetic Wiper’ malware
While websites were still dealing with the DDOS attacks, another cybersecurity company ESET Research Labs reported a new ‘data wiper’ malware that was detected in Ukraine last night, which it found to be “installed on hundreds of machines in the country”.
In a Twitter thread, ESET said that based on the timestamp on one sample of the malware, the attacks might have been in preparation for almost two months. It named the malware Hermetic Wiper based on the name of the Cypriot company its certificate was found to be issued to, Hermetica Digital.
Breaking. #ESETResearch discovered a new data wiper malware used in Ukraine today. ESET telemetry shows that it was installed on hundreds of machines in the country. This follows the DDoS attacks against several Ukrainian websites earlier today 1/n
— ESET research (@ESETresearch) February 23, 2022
Brian Kime, vice-president at cybersecurity firm ZeroFox, told Reuters that the certification might have been designed to help the malware dodge antivirus protections, adding that faking or stealing such a certificate isn’t impossible but a sign a “sophisticated and targeted” operator.
Cyclops Blink
Meanwhile, a new joint report by intelligence agencies in the UK and US claims that a new dangerous malware dubbed Cyclops Blink, built by Russian hacker group Sandworm, has replaced the earlier VPNFilter malware that infected more than 500,000 routers in 2018.
The report found that the Sandworm actor, also known as Voodoo Bear, has replaced the exposed VPNFilter malware with a new more advanced framework. The UK and US have previously identified the Sandworm actor as part of GRU’s main centre for special technologies.
It was published yesterday and jointly made by the UK National Cyber Security Centre (NCSC), the Cybersecurity and Infrastructure Security Agency, the National Security Agency and the Federal Bureau of Investigation in the US.
The UK’s NCSC wrote in an advisory that the malware itself, which has been circulating for at least three years, is “sophisticated and modular with basic core functionality to beacon device information back to a server and enable files to be downloaded and executed”.
“There is also functionality to add new modules while the malware is running, which allows Sandworm to implement additional capability as required,” it wrote.
Network device manufacturer WatchGuard said on its website yesterday that Cyclops Blink, which is able to abuse a legitimate firmware update mechanism in infected devices and survive reboots, has infected about 1pc of the company’s network firewall devices.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
The post Ukraine cyberattacks: All you need to know appeared first on Silicon Republic.