Russia

Country

Russian Medical Lab Helix Hit by Ransomware Attack

July 8, 2023

Customers of the Russian medical laboratory Helix have been unable to receive their test results for several days due to a “serious” cyberattack that crippled the company’s systems over the weekend. Hackers attempted to infect the company’s systems with ransomware. The company told Russian state-owned news agency Tass that its tech team partially restored the functionality of its website, mobile app and other e-health services without paying a ransom.

No customer personal data was leaked. Service disruptions prevented the company from delivering medical test results to its customers on time. Helix did not respond to a request for comment. It is unclear which group is responsible.

read more

DoDDS Attack at Russian Flight Booking System, Leonardo, Disrupts Airport Operations

September 28, 2023

A Russian flight booking system was hit by a cyberattack on Thursday, causing delays at airports. The incident lasted about an hour and affected the operation of several Leonardo customers, including Russian air carriers Rossiya Airlines, Pobeda and flagship airline Aeroflot. DDoS attacks overwhelm websites with a flood of traffic, making them temporarily unavailable to users.

Leonardo is used by more than 50 Russian carriers and serves around 45 million passengers annually, according to the Russian news agency Interfax.

read more

Russian Natural Gas Network System Attacked by pro-Ukrainian Hacker Group

August 23, 2022

A SCADA attack targeted the natural gas system of Khanty-Mansiysk city. The attack destroyed the city’s natural gas facility, knocked out its power plant and caused a blackout at its airport, reports International Business Times. As the world’s second biggest oil producing region (before western sanctions hit Russian oil) Khanty Mansi was the center of the old Soviet oil industry. The SCADA system of Khanty-Mansiysk city’s natural gas network along with its backup system at the airport was completely destroyed in the attack.

Reportedly the pro-Ukrainian group: Team OneFist is behind the attack. The group stressed they observe the rules of war and had taken steps to avoid potential damage to hospitals and civilians. And said that the latest hack was launched by Team OneFist’s new Ukrainian team members and Voltage as a “joint training-mission” to give the new members “a feel of what a SCADA attack is like.”

read more

Satellite Communications System Serving the Russian military Knocked Offline

June 30, 2023

A group of previously unknown hackers has claimed responsibility for a cyberattack on the Russian satellite communications provider Dozor-Teleport, which is used by energy companies and the country’s defense and security services.

Doug Madory, the head of internet analysis at the network monitoring company Kentik confirmed to Record Future News that Dozor-Teleport has been disconnected from the internet and is currently unreachable. Dozor’s parent company, Amtel Svyaz, also suffered a significant outage late on Wednesday, according to Madory.

The hackers claim that they damaged some of the satellite terminals and leaked and destroyed confidential information stored on the company’s servers. The group posted 700 files, including documents and images, to a leak site, as well as some to their newly created Telegram channel.

The group claims to be affiliated with the notorious Wagner Grouphackers. There was no mention of the hack on the official Telegram channel of the Wagner Group and several experts expressed skepticism that the group was involved.

Dozor did not respond to inquiries about the attack.

read more

Pro-Ukrainian Hacktivist Groups Claim Disabling over 1000 Network Routers in Russia

January 15, 2023

The pro-Ukraine hacktivist group TeamOneFist and RoughSec conducted the operation “Turn Ruzzia Off” and claim it demolished or disabled some 1,260 network routers in 48 hours.

The operations combined 3 missions to attack Rostelecom and Beeline ISPs with the objective of creating Internet and VoIP phone outages across all of Russia in government buildings, military facilities and Oligarch homes. The goal of the attack was to cripple Russian war logistics and slow down the Russian process of reinforcing their army in Ukraine.

read more

Novosibirsk Transportation System Attacked by pro-Ukranian Hacker Group

September 2, 2022

Pro-Ukrainian hacktivist collective Team OneFist, allegedly created with the help of the IT Army of Ukraine, attacked the Novosibirsk City Transport Traffic Management System in Operation Yellow Submarine beginning at September 2nd, 2022. OneFist’s founder, named “Voltage” (@SpoogemanGhost), claimed that the operation was “long-planned” and that the IT infrastructure had been breached about a month before the attack.

Due to the attack, city transportation officials were unable to have visibility over traffic conditions and coordinate their flows. The automated bus scheduling system as well as the electronic signs on buses and trolleys were damaged to hamper quick restoration and recovery. Voltage also explained that the attack paralyzed the city and the traffic problems remained for several days until the system was restored, forcing many commuters to walk. During the attack, Team OneFist downloaded the data and was in the process of deleting data when the Russian officials mitigated the damage by removing access to the system.

read more

Operational Impact After Cyberattack at Tavr Food Processing Group in Russia

March 24, 2022

On March 24 a cyberattack was conducted on Tavr, a major Russian food processing group in the Rostov region. As per the official company statement, the company business processes, including production, were temporarily paralyzed and a significant economic loss was recorded. A company representative assessed the event as “meticulously planned and significant sabotage”. Currently, the company’s activities are carried out in a limited mode.

read more

Russia’s Largest Meat Producer Hacked with Bitlocker Ransomware

March 18, 2022

On March 18 Miratorg Holding, one of Russia’s largest meat producers, was attacked using the Bitlocker ransomware. The attack targeted warehouse and accounting IT resources. It also interrupted the processing pipeline for electronic veterinary documentation. Eighteen companies in the Miratorg group were affected.

The point of compromise was VetIS, a state information system used by veterinary services and companies engaging in the field, making it likely a supply chain compromise. To reduce the impact of the cyberattack, the federal agency will assist Miratorg in transporting goods by temporarily lifting the strict documentation requirements for the movement of products. Moreover, it will accept hand-written certificates and give access to the federal platform (Mercury) to issue formal papers where needed. To ease customer concerns about the safety of the food during these critical times, Rosselkhoznadzor underlines that Miratorg has a track record of good reputation, so this exception is being made by taking that into account.

Rosselkhoznadzor (a government agency regulating agricultural affairs) announced that the group resumed normal operations on March 28. Unlike most ransomware attacks, the attackers did not demand money, so commercial interests were not the motivation for the attack.

read more

Hackers Changed Temperature Settings at Frozen Food Facility in Russia

February 26, 2022

Hackers hacked into the management of the equipment of the Selyatino agricultural hub in the Moscow region and tried to spoil 40 thousand tons of frozen meat and fish. An unknown user nicknamed ‘Supervisor’ penetrated the refrigeration remote monitoring network. Temperature settings were changed from – 24° C to +30°. The security service of the Selyatino agricultural hub prevented the negative consequences of the hacker attack. “At the moment, the operation of the installations has been restored. The equipment is disconnected from the Internet. The parameters are controlled locally, from a computer that is not connected to the Internet,”

read more

Russian Electric Vehicle Chargers Hacked on M11 Highway as Political Protest

February 28, 2022

Russian electric vehicle charging points have been hacked to display messages supporting Ukraine. As a result stations along Russia’s M-11 motorway, between Moscow and Saint Petersburg, were deactivated.

According to a Facebook Post by Russian energy company Rosseti, the charging points were hacked by the Ukrainian company that provided some of the parts for them. The company left a backdoor in their systems and used this to set the charging points to display the error messages. It was not reported how many electric vehicle charging points were hacked or deactivated, or for how long they would be unavailable to drivers of EV.

read more