Pro-Russia hackers were inside Ukraine government networks long before the ground war started

The cybersecurity company Trellix says pro-Russia hackers had infiltrated the networks of numerous Ukrainian government agencies long before Russia’s ground invasion started in late February. In fact, hackers had planted malicious code in the networks even before Russian troops began assembling at the Ukrainian border in 2021. These findings were part of a broader report on the global cyberthreat environment from San Jose, California-based Trellix, which was created last year via a merger between cybersecurity firms FireEye and McAfee Enterprise. The firm bases its findings on an analysis of data collected from organizations using McAfee Enterprise software. The Trellix analysts found evidence of “wiper” malware that was later activated remotely to delete all content on the hard drives of Ukrainian government computers. The malware matched the signature of malware used in the past by actors known to be associated with the Russian government, says Christiaan Beek, lead scientist and principal engineer at Trellix’s Threat Labs division. The malware also originated from the same time zone as Moscow’s, Beek says, adding that some instances of the malware may have come from others acting on Russia’s behalf. In any case, the malware had been there a while. “Somebody had longtime access,” Beek tells Fast Company. “They set up multiple entry points to target systems. They do every trick out of the book.” Trellix analysts believe the hackers used WhisperGate and HermeticWiper malware before and during the invasion to destabilize Ukrainian IT systems by destroying communications within the country. “They would try the first version of a wiper, and if that didn’t work they would try a second version,” Beek says. The actors and techniques involved in the Ukraine attacks aren’t new. The report says a hacker group called APT29 (also known as Cozy Bear), believed to conduct operations for Russian government entities, ranked most active among nation-state actors in the fourth quarter of 2021. It also notes that a plurality (46%) of total cyber incidents in Q4 2021 involved planting malware. Trellix, which examined cybercriminal behavior globally over the last six months, found that among its enterprise clients the transportation industry saw the most cyberattacks by a wide margin, followed by the shipping, manufacturing, and information technology industries. Looking at cyber activity in both the commercial and private realms, individuals remain the number-one target of cybercriminals, followed closely by healthcare institutions. “We’re at a critical juncture in cybersecurity and observing increasingly hostile behavior across an ever-expanding attack surface,” Beek says. The Trellix threat report contains recommendations for organizations on how to proactively protect their environment from tactics these actors use, including enabling multifactor authentication and disabling any nonessential ports or protocols related to remote services.

https://www.fastcompany.com/90746137/pro-russia-hackers-were-inside-ukraine-government-networks-long-before-the-ground-war-started?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Erstellt 3y | 27.04.2022, 04:20:45


Melden Sie sich an, um einen Kommentar hinzuzufügen

Andere Beiträge in dieser Gruppe

Why 1995 was the year the internet grew up

The internet wasn’t born whole—it came together from parts. Most know of ARPANET, the internet’s most famous precursor, but it was always limited strictly to government use. It was NSFNET that bro

15.07.2025, 11:50:03 | Fast company - tech
What is quantum computing? Here’s everything you need to know right now

Computing revolutions are surprisingly rare. Despite the extraordinary technological progress that separates the first general-purpose digital computer—1945’s

15.07.2025, 09:30:04 | Fast company - tech
This IBM ThinkPad was astounding in 1995—and still is

Closed, it looks pretty much like any other laptop manufactured in 1995.

To be sure, it’s more compact than most—making it, in the parlance of the day, a subnotebook. But it’s still comi

15.07.2025, 07:20:02 | Fast company - tech
This IBM ThinkPad was astounding in 1995—and still is

Closed, it looks pretty much like any other laptop manufactured in 1995.

To be sure, it’s more compact than most—making it, in the parlance of the day, a subnotebook. But it’s still comi

15.07.2025, 04:50:04 | Fast company - tech
$100,000, 100 streamers: IShowSpeed and Jynxzi’s Fortnite tournament is already drawing excitement

IShowSpeed and Jynxzi are teaming up to host a $100,000 Fortnite tournament, bringing together 100 top creators for what’s shaping up to be the biggest celebrity Fortnite match to date.

14.07.2025, 19:40:06 | Fast company - tech
Zuckerberg announces Meta’s new AI data centers for superintelligence

Mark Zuckerberg said on Monday that Meta Platforms would spend hundreds of billions of dollars to build several massive

14.07.2025, 19:40:05 | Fast company - tech
Meta’s massive data center bet is a direct challenge to OpenAI and Alphabet

Meta may not currently lead the race for AI superintelligence, but it&

14.07.2025, 19:40:04 | Fast company - tech