ZeroHour
CyberScooppublished ()ingested @timstarks

Cyberattacks on Ukrainian websites come into clearer focus as Russia tensions escalate

criticalRansomware exploited in the wildimportance 60
Full article710 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Ukraine is more explicitly blaming Russia for the cyberattacks.

Ukraine reservist
A member of the Ukrainian Territorial Defense Forces, the military reserve of the Ukrainian Armed Forces, smokes as he pets a cat on the frontline with Russia-backed separatists near to Avdiivka, southeastern Ukraine, on January 9, 2022. (Photo by ANATOLII STEPANOV/AFP via Getty Images)

Cybersecurity researchers shed additional light over the weekend on the cyberattacks that disabled Ukrainian government websites, as Kyiv pointed to Russia as the culprit.

Microsoft and ESET both shared details on the nature of the malware that took the Ukrainian sites down.

Microsoft “assesses that the malware, which is designed to look like ransomware but lacking a ransom recovery mechanism, is intended to be destructive and designed to render targeted devices inoperable rather than to obtain a ransom,” the company wrote in a blog post Saturday.

However, Microsoft said it couldn’t yet attribute who was behind the malware, labeled WhisperGate. The Department of Homeland Security’s Cybersecurity and Infrastructure Agency recommended that network defenders review the Microsoft blog post, suggesting the possibility that the attacks could spread to include other targets.

ESET on Sunday elaborated further, saying that the malware the attackers contained code “commonly used by commodity e-crime malware.”

“It is likely that attackers were trying to avoid existing detections at the last moment before the attack, that’s why they used third party criminal services,” ESET said in a tweet thread.

Ukraine was more definitive in placing blame than Microsoft.

“All the evidence points to Russia being behind the cyberattack,” the Ukrainian digital transformation ministry said in a Sunday statement. “Moscow is continuing to wage a hybrid war.”

A Ukrainian official also told Reuters that signs point to the attacks being the work of a Belarusian intelligence-connected group known as Ghostwriter, a group that might have a Russian element.

The Kremlin has denied being involved.

The attacks on the Ukrainian government websites add to that nation’s hostilities with Russia, which U.S. intelligence believes is planning an invasion on the country’s eastern border. The incidents also surfaced around the same time Russia announced it had arrested ransomware gang members on its own soil alleged to be behind the Colonial Pipeline attack, raising suspicions that the Kremlin intends to use the arrests as diplomatic levers with the U.S., which has threatened sanctions should Russia invade Ukraine.

More Scoops

May Lim, iStock/Getty Images Plus

In a first, a court takedown goes after two cybercrime tools at once

Microsoft, with law enforcement and industry partners, disrupted more than 200 command and control servers for Amadey and StealC, often used in conjunction.

The Russian flag flies at the embassy’s compound in Washington, DC, on April 15, 2021. (Photo by MANDEL NGAN/AFP via Getty Images)

Multi-national warning issued over Russia’s targeting of logistics, tech firms

Cars drive past the headquarters of the Russian General Staff’s Main Intelligence Department (GRU) in Moscow on December 30, 2016. (Photo by NATALIA KOLESNIKOVA/AFP via Getty Images)

U.S. charges five Russian military members for destructive cyber ops, hack-and-leak campaigns

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ukraine-russia-cyberattack-microsoft-eset/