Cyberwarfare by Russia

From HandWiki - Reading time: 20 min

Short description: Various types of cyberwarfare used by Russia against many nations

Cyberwarfare by Russia includes denial of service attacks, hacker attacks, dissemination of disinformation and propaganda, participation of state-sponsored teams in political blogs, internet surveillance using SORM technology, persecution of cyber-dissidents and other active measures.[1] According to investigative journalist Andrei Soldatov, some of these activities were coordinated by the Russian signals intelligence, which was part of the FSB and formerly a part of the 16th KGB department.[2] An analysis by the Defense Intelligence Agency in 2017 outlines Russia's view of "Information Countermeasures" or IPb (informatsionnoye protivoborstvo) as "strategically decisive and critically important to control its domestic populace and influence adversary states", dividing 'Information Countermeasures' into two categories of "Informational-Technical" and "Informational-Psychological" groups. The former encompasses network operations relating to defense, attack, and exploitation and the latter to "attempts to change people's behavior or beliefs in favor of Russian governmental objectives."[3]

Online presence

US journalist Pete Earley described his interviews with former senior Russian intelligence officer Sergei Tretyakov, who defected to the United States in 2000:

Sergei would send an officer to a branch of the New York Public Library where he could get access to the Internet without anyone knowing his identity. The officer would post the propaganda on various websites and send it in emails to US publications and broadcasters. Some propaganda would be disguised as educational or scientific reports. ... The studies had been generated at the Center by Russian experts. The reports would be 100% accurate [4]

Tretyakov did not specify the targeted web sites, but made clear they selected the sites which are most convenient for distributing the specific information. According to him, during his work in New York City in the end of the 1990s, one of the most frequent subjects was the War in Chechnya.[4]

According to a publication in Russian computer weekly Computerra, "just because it became known that anonymous editors are editing articles in English Wikipedia in the interests of UK and US intelligence and security services, it is also likely that Russian security services are involved in editing Russian Wikipedia, but this is not even interesting to prove it — because everyone knows that security bodies have a special place in the structure of our [Russian] state"[5]

Cyberattacks

It has been claimed that Russian security services organized a number of denial of service attacks as a part of their cyber-warfare against other countries, such as the 2007 cyberattacks on Estonia and the 2008 cyberattacks on Russia, South Ossetia, Georgia, and Azerbaijan.[6][7] One identified young Russian hacker said that he was paid by Russian state security services to lead hacking attacks on NATO computers. He was studying computer sciences at the Department of the Defense of Information. His tuition was paid for by the FSB.[8]

The Russian invasion of Ukraine in February 2022 saw renewed interest in information warfare, with the widespread dissemination of propaganda and misinformation on social media, by way of a large-scale Russian propaganda campaign on social media,[9] especially in countries that abstained from voting on the United Nations Resolution ES-11/1 such as India, South Africa, and Pakistan. Bots played a disproportionate role in the dissemination of pro-Russian messages and amplified its proliferation in early-stage diffusion, especially on platforms like Twitter, where pro-Russian messages received ∼251,000 retweets and thereby reached around 14.4 million users. Of these "spreaders," around 20.28% of the spreaders are classified as bots, most of which were created at the beginning of the invasion.[10]

Estonia

Main page: 2007 cyberattacks on Estonia

In April 2007, following a diplomatic row with Russia over a Soviet war memorial, Estonia was targeted by a series of cyberattacks on financial, media, and government websites which were taken down by an enormous volume of spam being transmitted by botnets in what is called a distributed denial-of-service attack. Online banking was made inaccessible, government employees were suddenly unable to communicate via e-mail, and media outlets could not distribute news. The attacks reportedly came from Russian IP addresses, online instructions were in Russian, and Estonian officials traced the systems controlling the cyberattacks back to Russia.[11][12] However, some experts held doubts that the attacks were carried out by the Russian government itself.[13] A year after the attack NATO founded the Cooperative Cyber Defence Centre of Excellence in Tallinn as a direct consequence of the attacks.[14]

In response to the 2022 Russian invasion of Ukraine, Estonia has removed a Soviet-era tank monument near Narva.[15] After its removal, Estonia was subject to "the most extensive cyberattack" since the 2007 cyberattacks.[16]

France

In 2015, the Paris-based French broadcasting service TV5Monde was attacked by hackers who used malicious software to attack and destroy the network's systems and take all twelve of its channels off the air. The attack was initially claimed by a group calling themselves the "Cyber Caliphate" however a more in-depth investigation by French authorities revealed the attack on the network had links to APT28, a GRU-affiliated hacker group.[17][18] In May 2017, on the eve of the French presidential election, more than 20,000 e-mails belonging to the campaign of Emmanuel Macron were dumped on an anonymous file-sharing website, shortly after the campaign announced they had been hacked. Word of the leak spread rapidly through the Internet, facilitated by bots and spam accounts. An analysis by Flashpoint, an American cybersecurity firm, determined with "moderate confidence" that APT28 was the group behind the hacking and subsequent leak.[19]

In February 2021 the Agence nationale de la sécurité des systèmes d'information said that "several French entities" were breached by Sandworm between late 2017 and 2020 by hacking French software company Centreon to deploy malware. Similar to the 2020 United States federal government data breach. The ANSSI said the breach "mostly affected information technology providers, especially web hosting providers." Russia has denied being behind the cyberattack. Centreon said in a statement that it "has taken note of the information" but disputed that the breach was linked to a vulnerability in their commercial software.[20][21][22]

Georgia

On 20 July 2008, the website of the Georgian president, Mikheil Saakashvili, was rendered inoperable for twenty-four hours by a series of denial of service attacks. Shortly after, the website of the National Bank of Georgia and the parliament were attacked by hackers who plastered images of Mikheil Saakashvili and former Nazi leader Adolf Hitler. During the war, many Georgian government servers were attacked and brought down, reportedly hindering communication and the dissemination of crucial information. According to technical experts, this is the first recorded instance in history of cyberattacks coinciding with an armed conflict.[23][24]

An independent US-based research institute US Cyber Consequences Unit report stated the attacks had "little or no direct involvement from the Russian government or military". According to the institute's conclusions, some several attacks originated from the PCs of multiple users located in Russia, Ukraine and Latvia. These users were willingly participating in cyberwarfare, being supporters of Russia during the 2008 South Ossetia war, while some other attacks also used botnets.[25][26]

Germany

In 2015, a high-ranking security official stated that it was "highly plausible" that a cybertheft of files from the German Parliamentary Committee investigating the NSA spying scandal, later published by WikiLeaks, was conducted by Russian hackers.[27][28] In late 2016, Bruno Kahl, president of the Bundesnachrichtendienst warned of data breaches and misinformation-campaigns steered by Russia.[29] According to Kahl, there are insights that cyberattacks occur with no other purpose than to create political uncertainty.[30][31] Süddeutsche Zeitung reported in February 2017 that a year-long probe by German intelligence "found no concrete proof of [Russian] disinformation campaigns targeting the government".[32] By 2020 however German investigators had collected enough evidence to identify one suspect.[33]

Hans-Georg Maaßen, head of the country's Federal Office for the Protection of the Constitution, noted "growing evidence of attempts to influence the [next] federal election" in September 2017 and "increasingly aggressive cyber espionage" against political entities in Germany.[34] The New York Times reported on 21 September 2017, three days before the German federal election, that there was little to suggest any Russian interference in the election.[35] In 2021 the European Commission has accused Russia of trying to interfere in European democratic processes just days before the parliamentary election on September 26 in Germany.[36]

Kyrgyzstan

Beginning in mid-January 2009, Kyrgyzstan's two main ISPs came under a large-scale DDoS attack, shutting down websites and e-mail within the country, effectively taking the nation offline. The attacks came at a time when the country's president, Kurmanbek Bakiyev, was being pressured by both domestic actors and Russia to close a U.S. air base in Kyrgyzstan.[37] The Wall Street Journal reported the attacks had been carried out by a Russian "cyber-militia".[38]

Poland

A three-year pro-Russian disinformation campaign on Facebook with an audience of 4.5 million Poles was discovered in early 2019 by OKO.press and Avaaz. The campaign published fake news and supported three Polish pro-Russian politicians and their websites: Adam Andruszkiewicz, former leader of the ultra-nationalist and neo-fascist All-Polish Youth and, (As of 2019), Secretary of State in the Polish Ministry of Digitisation; Janusz Korwin-Mikke; and Leszek Miller, an active member of the Polish United Workers' Party during the communist epoch and a prime minister of Poland during the post-communist epoch. Facebook responded to the analysis by removing some of the web pages.[39]

Romania

Main page: 2022 cyberattacks on Romania

Between late April and early May 2022, in the midst of the 2022 Russian invasion of Ukraine, multiple Romanian government, military, bank and mass media websites were taken down after a series of DDoS attacks, behind which was a pro-Kremlin hacking group, Killnet. The hacking group described the cyberattacks to be a response to a statement made by then-Senate president, Florin Cîțu that Romania would provide Ukraine with military equipment.[40][41][42]

South Korea

According to two United States intelligence officials that talked to The Washington Post , and also the findings of cybersecurity analyst Michael Matonis, Russia is likely behind the cyber attacks against the 2018 Winter Olympics in South Korea .[43] The worm responsible for these cyber attacks is known as "Olympic Destroyer".

The worm targeted all Olympic IT infrastructure, and succeeded in taking down WiFi, feeds to jumbotrons, ticketing systems, and other Olympic systems. It was timed to go off at the start of the opening ceremonies. It was unique in that the hackers attempted to use many false signatures to blame other countries such as North Korea and China .[43]

Ukraine

Main page: Russian-Ukrainian cyberwarfare

In March 2014, a Russian cyber weapon called Snake or "Ouroboros" was reported to have created havoc on Ukrainian government systems.[44] The Snake tool kit began spreading into Ukrainian computer systems in 2010. It performed Computer Network Exploitation (CNE), as well as highly sophisticated Computer Network Attacks (CNA).[45]

From 2014 to 2016, according to CrowdStrike, the Russian APT Fancy Bear used Android malware to target the Ukrainian Army's Rocket Forces and Artillery. They distributed an infected version of an Android app whose original purpose was to control targeting data for the D-30 Howitzer artillery. The app, used by Ukrainian officers, was loaded with the X-Agent spyware and posted online on military forums. CrowdStrike claims the attack was successful, with more than 80% of Ukrainian D-30 Howitzers destroyed, the highest percentage loss of any artillery pieces in the army (a percentage that had never been previously reported and would mean the loss of nearly the entire arsenal of the biggest artillery piece of the Ukrainian Armed Forces.[46]).[47] According to the Ukrainian army, this number is incorrect and that losses in artillery weapons "were way below those reported" and that these losses "have nothing to do with the stated cause".[48]

The U.S. government concluded after a study that a cyber attack caused a power outage in Ukraine which left more than 200,000 people temporarily without power. The Russian hacking group Sandworm or the Russian government were possibly behind the malware attack on the Ukrainian power grid as well as a mining company and a large railway operator in December 2015.[49][50][51][52][53][54] A similar attack occurred in December 2016.[55]

In February 2021 Ukraine accused Russia of attacking the System of Electronic Interaction of Executive Bodies a web portal used by the Ukrainian government to circulate documents by uploaded documents that contained macroscripts which if downloaded and enabled would lead to the computer to secretly download malware that would allow hackers to take over a computer.[56][57]

In January 2022, a cyberattack on Ukraine took down the website of the Ministry of Foreign Affairs and other government agencies.[58] Although an investigation has not been conclusive the cyber attacks coincide with the Russo-Ukrainian crisis.

In February 2022, before and after Russian troops entered eastern Ukraine amid an environment of escalating tensions between Ukraine and Russia, several major Ukrainian governmental and business websites were taken down by a series of cyberattacks. U.S. officials attributed the attacks to Russian attackers, although the Russian government denied involvement.[59]

2014 Ukrainian presidential election

Pro-Russian hackers launched a series of cyberattacks over several days to disrupt the May 2014 Ukrainian presidential election, releasing hacked emails, attempting to alter vote tallies, and delaying the final result with distributed denial-of-service (DDOS) attacks.[60][61] Malware that would have displayed a graphic declaring far-right candidate Dmytro Yarosh the electoral winner was removed from Ukraine's Central Election Commission less than an hour before polls closed. Despite this, Channel One Russia "reported that Mr. Yarosh had won and broadcast the fake graphic, citing the election commission's website, even though it had never appeared there."[60][62] According to Peter Ordeshook: "These faked results were geared for a specific audience in order to feed the Russian narrative that has claimed from the start that ultra-nationalists and Nazis were behind the revolution in Ukraine."[60]

United Kingdom "Brexit" referendum

In the run up to the 2016 referendum on the United Kingdom exiting the European Union ("Brexit"), Prime Minister David Cameron suggested that Russia "might be happy" with a positive Brexit vote, while the Remain campaign accused the Kremlin of secretly backing a positive Brexit vote.[63] In December 2016, Ben Bradshaw MP claimed in Parliament that Russia had interfered in the Brexit referendum campaign.[64] In February 2017, Bradshaw called on the British intelligence service, Government Communications Headquarters, then under Boris Johnson as Foreign Secretary, to reveal the information it had on Russian interference.[65] In April 2017, the House of Commons Public Administration and Constitutional Affairs Select Committee issued a report stating, in regard to the June 2016 collapse of the government's voter registration website less than two hours prior to the originally scheduled registration deadline (which was then extended), that "the crash had indications of being a DDOS 'attack.'" The report also stated that there was "no direct evidence" supporting "these allegations about foreign interference." A Cabinet Office spokeswoman responded to the report: "We have been very clear about the cause of the website outage in June 2016. It was due to a spike in users just before the registration deadline. There is no evidence to suggest malign intervention."[66][67]

In June 2017, it was reported by The Guardian that "Leave" campaigner Nigel Farage was a "person of interest" in the United States Federal Bureau of Investigation into Russian interference in the United States 2016 Presidential election.[68] In October 2017, Members of Parliament in the Culture, Media and Sport Committee demanded that Facebook, Twitter, Google and other social media corporations, to disclose all adverts and details of payments by Russia in the Brexit campaign.[69]

In December 2023 the UK and its allies have accused Russia of a sustained cyber attacks dating back at least from 2015 until 2023. These attacks have included targeting parliamentarians from various political parties as well as universities, journalists and NGOs. The star Blizzard group has been named as the group behind the attack is also thought to be subordinate to the Russian government.[70]

United States

Putin's Asymmetric Assault on Democracy in Russia and Europe: Implications for U.S. National Security

In 1999, Moonlight Maze was the US investigation of a 1996-1999 Russian cyberattack against NASA, the Pentagon, the US military, civilian academics and government agencies. The cyberattack was attributed to Russian-state-sponsored hackers.[71][72][73]

The 2008 cyberattack on the United States was connected to Russian language threat actors.[74]

In April 2015, CNN reported that "Russian hackers" had "penetrated sensitive parts of the White House" computers in "recent months." It was said that the FBI, the Secret Service, and other U.S. intelligence agencies categorized the attacks as "among the most sophisticated attacks ever launched against U.S. government systems."[75]

In 2015, CNN reported that Russian hackers, likely working for the Russian government, are suspected in the State Department hack. Federal law enforcement, intelligence and congressional officials briefed on the investigation say the hack of the State Department email system is the "worst ever" cyberattack intrusion against a federal agency.[76]

In February 2016, senior Kremlin advisor and top Russian cyber official Andrey Krutskikh told the Russian national security conference in Moscow that Russia was working on new strategies for the "information arena" that was equivalent to testing a nuclear bomb and would "allow us to talk to the Americans as equals".[77]

In 2016, the release of hacked emails belonging to the Democratic National Committee, John Podesta, and Colin Powell, among others, through DCLeaks and WikiLeaks was said by private sector analysts[78] and US intelligence services[79] to have been of Russian origin.[80][81] Also, in December 2016, Republicans and Democrats on the Senate Committee on Armed Services called for "a special select committee to investigate Russian attempts to influence the presidential election".[82][83]

In 2018, the United States Computer Emergency Response Team released an alert warning that the Russian government was executing "a multi-stage intrusion campaign by Russian government cyber actors who targeted small commercial facilities' networks where they staged malware, conducted spear phishing, and gained remote access into energy sector networks." It further noted that "[a]fter obtaining access, the Russian government cyber actors conducted network reconnaissance, moved laterally, and collected information pertaining to Industrial Control Systems."[84] The hacks targeted at least a dozen U.S. power plants, in addition to water processing, aviation, and government facilities.[85]

In June 2019, the New York Times reported that hackers from the United States Cyber Command planted malware potentially capable of disrupting the Russian electrical grid.[86] According to Wired senior writer Andy Greenberg, "The Kremlin warned that the intrusions could escalate into a cyberwar between the two countries."[86]

Over several months in 2020, a group known as APT29 or Cozy Bear, working for Russia's Foreign Intelligence Service, breached a top cybersecurity firm and multiple U.S. government agencies including the Treasury, Commerce, and Energy departments and the National Nuclear Security Administration.[87] The hacks occurred through a network management system called SolarWinds Orion. The U.S. government had an emergency meeting on 12 December 2020, and the press reported the hack the next day. When Russia's Foreign Intelligence Service performs such hacks, it is typically "for traditional espionage purposes, stealing information that might help the Kremlin understand the plans and motives of politicians and policymakers," according to The Washington Post, and not for the purpose of leaking information to the public.[88]

In February 2021 a report by Dragos stated that Sandworm has been targeting US electric utilities, oil and gas, and other industrial firms since at least 2017 and were successful in breaching these firms a "handful" of times.[89][90]

In May 2021, the Colonial Pipeline ransomware attack was perpetrated by Russian language hacking group DarkSide.[91][92] It was the largest cyberattack on an energy infrastructure target in US history. Colonial Pipeline temporarily halted the operations of the pipeline due to the ransomware attack.[93] The Department of Justice recovered the bitcoin ransom from the hackers.[94]

Venezuela

After the news website Runrun.es published a report on extrajudicial killings by the Bolivarian National Police, on 25 May 2019, the Venezuelan chapter of the Instituto de Prensa y Sociedad (IPYS), pointed out that the website was out of service due to an uncached request attack, denouncing that it originated from Russia.[95]

False alarms

On 30 December 2016, Burlington Electric Department, a Vermont utility company, announced that code associated with the Russian hacking operation dubbed Grizzly Steppe had been found in their computers. Officials from the Department of Homeland Security, FBI and the Office of the Director of National Intelligence warned executives of the financial, utility and transportation industries about the malware code.[96] The first report by The Washington Post left the impression that the grid had been penetrated, but the hacked computer was not attached to the grid. A later version attached this disclaimer to the top of its report correcting that impression: "Editor's Note: An earlier version of this story incorrectly said that Russian hackers had penetrated the U.S. electric grid. Authorities say there is no indication of that so far. The computer at Burlington Electric that was hacked was not attached to the grid."[97]

See also

References

  1. Kantchev, Georgi; Strobel, Warren P. (2 January 2021). "How Russia's 'Info Warrior' Hackers Let Kremlin Play Geopolitics on the Cheap". https://www.wsj.com/articles/how-russias-info-warrior-hackers-let-kremlin-play-geopolitics-on-the-cheap-11609592401. 
  2. State control over the internet , a talk show by Yevgenia Albats at the Echo of Moscow, 22 January 2006; interview with Andrei Soldatov and others
  3. "Military Power Publications" (in en-US). http://www.dia.mil/Military-Power-Publications/. 
  4. 4.0 4.1 Pete Earley, "Comrade J: The Untold Secrets of Russia's Master Spy in America After the End of the Cold War", Penguin Books, 2007, ISBN:978-0-399-15439-3, pages 194-195
  5. Is there only one truth? by Kivy Bird, Computerra, 26 November 2008
  6. "www.axisglobe.com". http://www.axisglobe.com/news.asp?news=14728. 
  7. Cyberspace and the changing nature of warfare . Strategists must be aware that part of every political and military conflict will take place on the internet, says Kenneth Geers.
  8. Andrew Meier, Black Earth. W. W. Norton & Company, 2003, ISBN:0-393-05178-1, pages 15-16.
  9. "Social Media as a Propaganda Tool in the Russia-Ukraine Conflict" (in en-US). 2023-03-12. https://www.thecairoreview.com/essays/social-media-as-a-propaganda-tool-in-the-russia-ukraine-conflict/. 
  10. Geissler, Dominique; Bär, Dominik; Pröllochs, Nicolas; Feuerriegel, Stefan (December 2023). "Russian propaganda on social media during the 2022 invasion of Ukraine" (in en). EPJ Data Science 12 (1): 1–20. doi:10.1140/epjds/s13688-023-00414-5. ISSN 2193-1127. https://epjdatascience.springeropen.com/articles/10.1140/epjds/s13688-023-00414-5. 
  11. McGuinness, Damien (27 April 2017). "How a cyber attack transformed Estonia". https://www.bbc.com/news/39655415. 
  12. "10 Years After the Landmark Attack on Estonia, Is the World Better Prepared for Cyber Threats?". 27 April 2017. https://foreignpolicy.com/2017/04/27/10-years-after-the-landmark-attack-on-estonia-is-the-world-better-prepared-for-cyber-threats/. 
  13. "Experts doubt Russian government launched DDoS attacks". 23 February 2018. http://searchsecurity.techtarget.com/news/1255548/Experts-doubt-Russian-government-launched-DDoS-attacks. 
  14. "NATO launches cyber defence centre in Estonia". 14 May 2008. http://www.spacewar.com/reports/NATO_launches_cyber_defence_centre_in_Estonia_999.html. 
  15. "Estonia Removes Soviet-era Monument, Citing Public Order". Associated Press. 16 August 2022. https://www.bloomberg.com/news/articles/2022-08-16/estonia-removes-soviet-monument-citing-public-order. 
  16. "Estonia hit by 'most extensive' cyberattack since 2007 amid tensions with Russia over Ukraine war". 18 August 2022. https://www.euronews.com/next/2022/08/18/estonia-hit-by-most-extensive-cyberattack-since-2007-amid-tensions-with-russia-over-ukrain. 
  17. Corera, Gordon (10 October 2016). "How France's TV5 was almost destroyed". https://www.bbc.com/news/technology-37590375. 
  18. "'Russian hackers' behind TV attack". 9 June 2015. https://www.bbc.com/news/world-europe-33072034. 
  19. "Researchers link Macron hack to APT28 with 'moderate confidence'". 11 May 2017. https://www.cyberscoop.com/researchers-link-macron-hack-to-apt28-with-moderate-confidence/. 
  20. Cimpanu, Catalin. "France: Russian state hackers targeted Centreon servers in years-long campaign" (in en). https://www.zdnet.com/article/france-russian-state-hackers-targeted-centreon-servers-in-years-long-campaign/. 
  21. "France uncovers cybersecurity breaches linked to Russian hackers" (in en). 16 February 2021. https://www.france24.com/en/france/20210216-france-uncovers-cybersecurity-breaches-linked-to-russian-hackers. 
  22. "France identifies Russia-linked hackers in large cyberattack" (in en-US). 15 February 2021. https://www.politico.eu/article/france-cyber-agency-russia-attack-security-anssi/. 
  23. Hart, Kim (14 August 2008). "Longtime Battle Lines Are Recast In Russia and Georgia's Cyberwar". The Washington Post. https://www.washingtonpost.com/wp-dyn/content/article/2008/08/13/AR2008081303623.html. 
  24. Markoff, John (13 August 2008). "Before the Gunfire, Cyberattacks". https://www.nytimes.com/2008/08/13/technology/13cyber.html. 
  25. Siobhan Gorman (18 August 2009). "Hackers Stole IDs for Attacks". https://www.wsj.com/articles/SB125046431841935299#articleTabs%3Darticle. 
  26. "Georgian cyber attacks launched by Russian crime gangs". https://www.theregister.co.uk/2009/08/18/georgian_cyber_attacks/. 
  27. "Russia behind hack on German parliament, paper reports" (in en). Deutsche Welle. http://www.dw.com/en/russia-behind-hack-on-german-parliament-paper-reports/a-36729079. 
  28. Wehner, Markus; Lohse, Eckart (11 December 2016). "Wikileaks: Sicherheitskreise: Russland hackte geheime Bundestagsakten". Faz.net (Frankfurter Allgemeine Zeitung). https://www.faz.net/aktuell/politik/inland/wikileaks-sicherheitskreise-russland-hackte-geheime-bundestagsakten-14568558.html. 
  29. "Vor Bundestagswahl: BND warnt vor russischen Hackerangriffen". Der Spiegel (SPIEGEL ONLINE). 29 November 2016. http://www.spiegel.de/politik/deutschland/bundestagswahl-2017-bnd-chef-kahl-warnt-russischen-hackerangriffen-a-1123506.html. 
  30. "Was bedeuten die neuen Cyberangriffe für die Bundestagswahl?" (in de). 1 November 2016. http://www.sueddeutsche.de/politik/leserdiskussion-was-bedeuten-die-neuen-cyberangriffe-fuer-die-bundestagswahl-1.3271551. 
  31. "BND-Präsident warnt vor Cyberangriffen aus Russland". 29 November 2016. http://www.sueddeutsche.de/politik/bundestagswahl-bnd-praesident-warnt-vor-cyberangriffen-aus-russland-1.3270995. 
  32. King, Esther (7 February 2017). "German intelligence finds no evidence of Russian meddling". http://www.politico.eu/article/german-intelligence-finds-no-evidence-of-russian-meddling/. 
  33. "German authorities charge Russian hacker for 2015 Bundestag hack | ZDNet". https://www.zdnet.com/google-amp/article/german-authorities-charge-russian-hacker-for-2015-bundestag-hack/. 
  34. "BfV: Russia is trying to destabilise Germany". AlJazeera. http://www.aljazeera.com/news/2016/12/bfv-russia-destabilise-germany-161208141856179.html. 
  35. Schwirtz, Michael (21 September 2017). "German Election Mystery: Why No Russian Meddling?". https://www.nytimes.com/2017/09/21/world/europe/german-election-russia.html. 
  36. Vasco Cotovio (24 September 2021). "Russia accused of 'Ghostwriter' cyberattacks ahead of German election". https://www.cnn.com/2021/09/24/europe/russia-accused-ghostwriter-cyberattacks-german-election-intl/index.html. 
  37. Bradbury, Danny (5 February 2009). "Danny Bradbury investigates the cyberattack on Kyrgyzstan". https://www.theguardian.com/technology/2009/feb/05/kyrgyzstan-cyberattack-internet-access. 
  38. Rhoads, Christopher (28 January 2009). "Kyrgyzstan Knocked Offline". https://www.wsj.com/articles/SB123310906904622741. 
  39. Flis, Daniel (24 April 2019). "Disinformation network on Facebook supported by Polish Deputy Minister of Digitization". vsquare.org. https://vsquare.org/disinformation-network-on-facebook-supported-by-polish-deputy-minister-of-digitization/. 
  40. "UPDATE Atacul cibernetic care a vizat site-uri guvernamentale, printre care al Executivului și al Armatei, revendicat de hackeri ruși" (in ro). 29 April 2022. https://www.digi24.ro/stiri/actualitate/site-uri-guvernamentale-printre-care-cel-al-executivului-si-al-armatei-atacate-cibernetic-carbunaru-nu-sunt-date-sensibile-afectate-1921999. 
  41. "Site-urile marilor aeroporturi din România nu funcționează. Hackerii ruși de la Killnet revendică atacul" (in ro). 2 May 2022. https://www.digi24.ro/stiri/economie/transporturi/site-urile-marilor-aeroporturi-din-romania-nu-functioneaza-hackerii-rusi-de-la-killnet-revendica-atacul-1924549. 
  42. "Ce spune Marcel Ciolacu, preşedintele Camerei Deputaţilor, despre motivele invocate de hackerii Killnet: E o greşeală acolo" (in ro). https://www.zf.ro/zf-24/ce-spune-marcel-ciolacu-presedintele-camerei-deputatilor-despre-20782673. 
  43. 43.0 43.1 "Inside Olympic Destroyer, the Most Deceptive Hack in History" (in en-us). Wired. ISSN 1059-1028. https://www.wired.com/story/untold-story-2018-olympics-destroyer-cyberattack/. Retrieved 26 August 2020. 
  44. The Christian Science Monitor (12 March 2014). "Russia's cyber weapons hit Ukraine: How to declare war without declaring war". http://www.csmonitor.com/Commentary/Global-Viewpoint/2014/0312/Russia-s-cyber-weapons-hit-Ukraine-How-to-declare-war-without-declaring-war. 
  45. Mazanec, Brain M. (2015). The Evolution of Cyber War. USA: University of Nebraska Press. pp. 221–222. ISBN 9781612347639. 
  46. Ukraine's military denies Russian hack attack , Yahoo! News (6 January 2017)
  47. "Danger Close: Fancy Bear Tracking of Ukrainian Field Artillery Units". CrowdStrike. 22 December 2016. https://www.crowdstrike.com/blog/danger-close-fancy-bear-tracking-ukrainian-field-artillery-units/. 
  48. Defense ministry denies reports of alleged artillery losses because of Russian hackers' break into software , Interfax-Ukraine (6 January 2017)
  49. "Malware Found Inside Downed Ukrainian Grid Management Points to Cyberattack". 4 January 2016. http://motherboard.vice.com/read/malware-found-inside-downed-ukrainian-power-plant-points-to-cyberattack. 
  50. "SANS Industrial Control Systems Security Blog - Potential Sample of Malware from the Ukrainian Cyber Attack Uncovered - SANS Institute". https://ics.sans.org/blog/2016/01/01/potential-sample-of-malware-from-the-ukrainian-cyber-attack-uncovered. 
  51. "First known hacker-caused power outage signals troubling escalation". 2016. https://arstechnica.com/security/2016/01/first-known-hacker-caused-power-outage-signals-troubling-escalation/. 
  52. "Ukraine power grid attacks continue but BlackEnergy malware ruled out". http://www.v3.co.uk/v3-uk/news/2440469/ukraine-investigating-suspected-russian-cyber-attack-on-power-grid. 
  53. "U.S. government concludes cyber attack caused Ukraine power outage". Reuters. 25 February 2016. https://www.reuters.com/article/us-ukraine-cybersecurity-idUSKCN0VY30K. 
  54. "BlackEnergy malware activity spiked in runup to Ukraine power grid takedown". The Register. https://www.theregister.co.uk/2016/03/04/ukraine_blackenergy_confirmation/. 
  55. "Ukraine's power outage was a cyber attack: Ukrenergo". Reuters. 18 January 2017. https://www.reuters.com/article/us-ukraine-cyber-attack-energy/ukraines-power-outage-was-a-cyber-attack-ukrenergo-idUSKBN1521BA. 
  56. "Ukraine reports cyber-attack on government document management system". https://www.zdnet.com/article/ukraine-reports-cyber-attack-on-government-document-management-system/. 
  57. "Ukraine says Russia hacked its document portal and planted malicious files". 24 February 2021. https://arstechnica.com/information-technology/2021/02/ukraine-says-russia-hacked-its-document-portal-and-planted-malicious-files/. 
  58. Harding, Luke. "Ukraine hit by 'massive' cyber-attack on government websites". The Guardian. https://www.theguardian.com/world/2022/jan/14/ukraine-massive-cyber-attack-government-websites-suspected-russian-hackers. 
  59. Lauren Feiner (2022-02-23). "Cyberattack hits Ukrainian banks and government websites". CBNC. https://www.cnbc.com/2022/02/23/cyberattack-hits-ukrainian-banks-and-government-websites.html. 
  60. 60.0 60.1 60.2 Clayton, Mark (17 June 2014). "Ukraine election narrowly avoided 'wanton destruction' from hackers". https://www.csmonitor.com/World/Passcode/2014/0617/Ukraine-election-narrowly-avoided-wanton-destruction-from-hackers. 
  61. Watkins, Ali (14 August 2017). "Obama team was warned in 2014 about Russian interference". http://www.politico.com/story/2017/08/14/obama-russia-election-interference-241547. 
  62. Kramer, Andrew E.; Higgins, Andrew (16 August 2017). "In Ukraine, a Malware Expert Who Could Blow the Whistle on Russian Hacking". https://www.nytimes.com/2017/08/16/world/europe/russia-ukraine-malware-hacking-witness.html. 
  63. S Rosenberg, 'EU referendum: What does Russia gain from Brexit?' (26 June 2016) BBC News
  64. Highly probable' that Russia interfered in Brexit referendum, Labour MP says' (13 December 2016) Independent
  65. J Kanter and A Bienkov, 'Labour MPs think the government is hiding info about Russia interfering with Brexit' (23 February 2016) Business Insider
  66. Syal, Rajeev (12 April 2017). "Brexit: foreign states may have interfered in vote, report says". https://www.theguardian.com/politics/2017/apr/12/foreign-states-may-have-interfered-in-brexit-vote-report-says. 
  67. Teffer, Peter (12 April 2017). "MPs and media create Brexit hacking scare". https://euobserver.com/uk-referendum/137581. 
  68. 'Nigel Farage is 'person of interest' in FBI investigation into Trump and Russia ' (2 June 2017) Guardian
  69. 'MPs order Facebook to hand over evidence of Russian election meddling' (24 October 2017) Telegraph
  70. "UK and allies expose Russian intelligence services for cyber campaign of attempted political interference" (in en). https://www.ncsc.gov.uk/news/uk-and-allies-expose-cyber-campaign-attempted-political-interference. 
  71. Kaplan, Fred (20 March 2016). "How the United States Learned to Cyber Sleuth: The Untold Story" (in en). https://www.politico.com/magazine/story/2016/03/russia-cyber-war-fred-kaplan-book-213746. 
  72. "New Evidence Links a 20-Year-Old Hack on the US Government to a Modern Attack Group" (in en). 4 April 2017. https://www.vice.com/en/article/vvk83b/moonlight-maze-turla-link. 
  73. Loeb, Vernon (2001-05-07). "NSA Adviser Says Cyber-Assaults On Pentagon Persist With Few Clues" (in en-US). Washington Post. ISSN 0190-8286. https://www.washingtonpost.com/archive/politics/2001/05/07/nsa-adviser-says-cyber-assaults-on-pentagon-persist-with-few-clues/cd04af8b-197c-4dce-95a1-f702542b0ff3/. 
  74. III, William J. Lynn (2020-10-16). "Defending a New Domain" (in en-US). ISSN 0015-7120. https://www.foreignaffairs.com/articles/united-states/2010-09-01/defending-new-domain. 
  75. Evan Perez; Shimon Prokupecz (8 April 2015). "How the U.S. thinks Russians hacked the White House". CNN. http://edition.cnn.com/2015/04/07/politics/how-russians-hacked-the-wh/index.html. "Russian hackers behind the damaging cyber intrusion of the State Department in recent months used that perch to penetrate sensitive parts of the White House computer system, according to U.S. officials briefed on the investigation." 
  76. Evan Perez and Shimon Prokupecz (10 March 2015). "Sources: State Dept Hack the 'worst ever'". http://www.cnn.com/2015/03/10/politics/state-department-hack-worst-ever/index.html. 
  77. Ignatius, David (18 January 2017). "Russia's radical new strategy for information warfare". The Washington Post. https://www.washingtonpost.com/blogs/post-partisan/wp/2017/01/18/russias-radical-new-strategy-for-information-warfare/. 
  78. Thielman, Sam; Ackerman, Spencer (29 July 2016). "Cozy Bear and Fancy Bear: did Russians hack Democratic party and if so, why?". The Guardian. https://www.theguardian.com/technology/2016/jul/29/cozy-bear-fancy-bear-russia-hack-dnc. 
  79. Ackerman, Spencer; Thielman, Sam (8 October 2016). "US officially accuses Russia of hacking DNC and interfering with election". https://www.theguardian.com/technology/2016/oct/07/us-russia-dnc-hack-interfering-presidential-election. 
  80. Corera, Gordon (22 December 2016). "Can US election hack be traced to Russia?". BBC. https://www.bbc.com/news/world-us-canada-38370630. 
  81. Gallagher, Sean (12 December 2016). "Did the Russians "hack" the election? A look at the established facts". https://arstechnica.com/security/2016/12/the-public-evidence-behind-claims-russia-hacked-for-trump/. 
  82. Savage, David (18 December 2016). "'How much and what damage?' Senators call for a special committee to investigate Russian hacking". Los Angeles Times. https://www.latimes.com/nation/politics/la-na-senate-russian-hacking-20161218-story.html. 
  83. Nakashima, Ellen (22 December 2016). "Cybersecurity firm finds evidence that Russian military unit was behind DNC hack". The Washington Post. https://www.washingtonpost.com/world/national-security/cybersecurity-firm-finds-a-link-between-dnc-hack-and-ukrainian-artillery/2016/12/21/47bf1f5a-c7e3-11e6-bf4b-2c064d32a4bf_story.html?postshare=9631482406341944&tid=ss_fb-bottom. 
  84. "Russian Government Cyber Activity Targeting Energy and Other Critical Infrastructure Sectors | CISA". 16 March 2018. https://us-cert.cisa.gov/ncas/alerts/TA18-074A. 
  85. Dlouhy, Jennifer; Riley, Michael (15 March 2018). "Russian Hackers Attacking U.S. Power Grid and Aviation, FBI Warns". Bloomberg. https://www.bloomberg.com/news/articles/2018-03-15/russian-hackers-attacking-u-s-power-grid-aviation-fbi-warns. 
  86. 86.0 86.1 "How Not To Prevent a Cyberwar With Russia". Wired. 18 June 2019. https://www.wired.com/story/russia-cyberwar-escalation-power-grid/. Retrieved 4 January 2021. 
  87. Bertrand, Natasha (17 December 2020). "Nuclear weapons agency breached amid massive cyber onslaught" (in en). https://www.politico.com/news/2020/12/17/nuclear-agency-hacked-officials-inform-congress-447855. 
  88. Nakashima, Ellen (13 December 2020). "Russian government spies are behind a broad hacking campaign that has breached U.S. agencies and a top cyber firm". The Washington Post. https://www.washingtonpost.com/national-security/russian-government-spies-are-behind-a-broad-hacking-campaign-that-has-breached-us-agencies-and-a-top-cyber-firm/2020/12/13/d5a53b88-3d7d-11eb-9453-fc36ba051781_story.html. 
  89. "Hackers Tied to Russia's GRU Targeted the US Grid for Years" (in en-us). Wired. ISSN 1059-1028. https://www.wired.com/story/russia-gru-hackers-us-grid/. Retrieved 2 March 2021. 
  90. Palmer, Danny. "These four new hacking groups are targeting critical infrastructure, warns security company" (in en). https://www.zdnet.com/article/these-four-new-hacking-groups-are-targeting-critical-infrastructure-warns-security-company/. 
  91. "Colonial Pipeline hack explained: Everything you need to know" (in en). https://www.techtarget.com/whatis/feature/Colonial-Pipeline-hack-explained-Everything-you-need-to-know. 
  92. "FBI Statement on Compromise of Colonial Pipeline Networks" (in en-us). https://www.fbi.gov/news/press-releases/press-releases/fbi-statement-on-compromise-of-colonial-pipeline-networks. 
  93. Gonzalez, Gloria; Lefebvre, Ben; Geller, Eric (May 8, 2021). "'Jugular' of the U.S. fuel pipeline system shuts down after cyberattack". Politico. https://www.politico.com/news/2021/05/08/colonial-pipeline-cyber-attack-485984. "The infiltration of a major fuel pipeline is "the most significant, successful attack on energy infrastructure we know of."" 
  94. "Recovery of Colonial Pipeline ransom funds highlights traceability of cryptocurrency, experts say" (in en-US). 2021-06-23. https://www.thomsonreuters.com/en-us/posts/investigation-fraud-and-risk/colonial-pipeline-ransom-funds/. 
  95. "Runrunes es víctima de ataques cibernéticos tras reportaje sobre las FAES" (in es). Tal Cual. 27 May 2019. https://talcualdigital.com/index.php/2019/05/27/runrunes-es-victima-de-ataques-ciberneticos-por-reportaje-sobre-las-faes/. 
  96. Eilperen, Juliet &, Entous, Adam (30 December 2016). "Russian operation hacked a Vermont utility, showing risk to U.S. electrical grid security, officials say". The Washington Post. https://www.washingtonpost.com/world/national-security/russian-hackers-penetrated-us-electricity-grid-through-a-utility-in-vermont/2016/12/30/8fc90cc4-ceec-11e6-b8a2-8c2a61b0436f_story.html?hpid=hp_hp-top-table-main_electrichack-810pm%3Ahomepage%2Fstory. 
  97. Eilperin, Juliet; Entous, Adam (31 December 2016). "Russian operation hacked a Vermont utility, showing risk to U.S. electrical grid security, officials say". The Washington Post. https://www.washingtonpost.com/world/national-security/russian-hackers-penetrated-us-electricity-grid-through-a-utility-in-vermont/2016/12/30/8fc90cc4-ceec-11e6-b8a2-8c2a61b0436f_story.html. 

Further reading

Template:Cyberwarfare by country




Licensed under CC BY-SA 3.0 | Source: https://handwiki.org/wiki/Social:Cyberwarfare_by_Russia
29 views | Status: cached on July 25 2024 05:45:26
↧ Download this article as ZWI file
Encyclosphere.org EncycloReader is supported by the EncyclosphereKSF