Russia

Country

Cyberattack on Russian Telecommunications Provider

January 9, 2024

Hackers linked to Ukraine’s main spy agency have breached computer systems at a Moscow-based internet provider in retaliation for a Russian cyber attack against Ukrainian telecom giant Kyivstar, a source with direct knowledge of the operation told Reuters on Tuesday.
The hacking group, dubbed “Blackjack”, has previously been linked to the Security Service of Ukraine (SBU). The hackers deleted 20 terrabytes of data at M9 Telecom, a small Russian internet and TV provider, leaving some Moscow residents without internet, the source said.

read more

Russian Drone Control Programs Breached by HUR

February 8, 2024

Ukrainian hackers working within Ukraine’s Military Intelligence (HUR) have successfully breached Russian drone control programs. The servers responsible for the “friend or foe” identification system for Russian drones ceased functioning, resulting in its military losing access to its drones.

read more

Meduza Media Outlet Faces “most Intense Cyber Campaign Ever”

February 12, 2024

The Russian independent media organization Meduza said that it has been targeted by an “unprecedented” cyber campaign ahead of the upcoming presidential election this month. “In February 2024, the Russian authorities launched a series of cyberattacks against Meduza, more intense than any we’ve ever faced,” the organization said in a statement on Monday.

There is no evidence so far that the attacks were conducted by the Russian state, apart from Meduza’s statement.

read more

Alleged Cyberattack on Delivery Service in Russia

May 28, 2024

A little-known hacker group claimed responsibility for an attack that has disrupted service for days at CDEK, one of Russia’s largest delivery companies. The Russian-speaking hackers, who call themselves Head Mare, said they encrypted the company’s servers with ransomware and destroyed backup copies of its corporate systems.

CDEK hasn’t attributed the disruption to a cyberattack, but an anonymous source within the company told Russian media outlet Vedomosti that it was a ransomware attack. Recorded Future News couldn’t verify this claim, as CDEK couldn’t be reached for comment.

The company attributed disruption to its services over the weekend to a “massive technical failure” that affected the functionality of its website and mobile application. CDEK also suspended parcel shipments “to avoid errors during manual processing.” “On Monday, we made significant progress in restoring full operation, but unfortunately we were not ready to resume our service,” the company said. “All your parcels are safe, and we are doing everything necessary to ensure that they reach you as quickly as possible.”

read more

Mass Cyberattack on Internet Servers and Online Industrial Platforms in Russia

August 24, 2024

Hackers of Ukraine’s military intelligence agency (HUR) carried out on Aug. 24 a mass cyberattack on the servers of Russian Internet providers and blocked “dozens” of online platforms of industrial facilities in Russia, a military intelligence source told the Kyiv Independent. The recent attack affected at least 33 servers and 283 office computers at industrial facilities, took down 21 websites, and destroyed 15 cloud and file storages. Ukrainian hackers also left pro-Ukrainian messages on the affected online platforms, according to the source.

Ukrainian hackers targeted the network infrastructure of factories and companies that produce equipment for Russian law enforcement agencies, aircraft and helicopter components, as well as supply hardware and software, servers, and processors, among other products.

read more

Threat Actor targets Russia’s Aviation Sector.

June 7, 2024

A threat actor known as “Sticky Werewolf” is using layered infection chains to compromise organizations involved with Russia’s aviation industry. The group has been around since at least April 2023, and seems to be interested in espionage relating to the conflict between Russia and Ukraine.

The group was targeting public organizations in Russia and Belarus, but recent targets have included a pharmaceutical company and a Russian research institute involved in microbiology and vaccine development. In prior campaigns, Sticky Werewolf phishing emails included links to download malicious files. Now, its infections are notably more complex. The final payload will be some sort of commercial remote access Trojan (RAT).

read more

Ransomware Attack at Russian Medical Laboratory

July 18, 2023

Customers of the Russian medical laboratory Helix have been unable to receive their test results for several days due to a “serious” cyberattack that crippled the company’s systems over the weekend. According to a statement the lab issued Monday, hackers attempted to infect the company’s systems with ransomware.

read more

Ukrainian Hacktivists Temporarily Disabled Internet Services in some Russia Occupied Territories

October 27, 2023

Ukrainian hackers have temporarily disabled internet services in parts of the country’s territories that have been occupied by Russia. The group of cyber activists known as the IT Army said on Telegram that their distributed denial-of-service (DDoS) attack took down three Russian internet providers — Miranda-media, Krimtelekom, and MirTelekom — operating in the territories.

Early on Friday, Russian internet operators confirmed that they had experienced an “unprecedented level of DDoS attacks from Ukrainian hacker groups,” temporarily disrupting their operations. The attack affected services such as cellular networks, phone calls, and internet connections.

read more

Russian Railways Website Suffers DoDDS Cyberattacks

February 26, 2023

The Russian Railways website has suffered serious cyber attacks. The portal may experience disruptions, the company’s press service warned about this on February 26. “Our website is subject to regular, serious DDoS attacks. <…> The official mobile application of Russian Railways works normally. We are also increasing the number of operating ticket offices at stations so that all our passengers have the opportunity to buy tickets,” says a message published by Russian Railways on Telegram.

read more

Russian RZD Railway Cyberattack Disrupts Online Ticket Sales

July 5, 2023

The Russian state-owned railway company RZD said Wednesday that its website and mobile app were down for several hours due to a “massive” cyberattack, forcing passengers to only buy tickets at railway stations. RZD’s system was down for at least six hours, but the company said later on Wednesday that it had restored its operation despite ongoing attacks. Some of the company’s online services are still unavailable due to the increased load, RZD said.

read more