Cyber Operations Keep Affecting Civilians as War Continues episode artwork

EPISODE · Aug 11, 2022

Cyber Operations Keep Affecting Civilians as War Continues

from Info Risk Today Podcast · host InfoRiskToday.com

The ISMG Security Report discusses how cyberattacks and operations tied to the Russia-Ukraine war have been affecting civilians since the start of Russia's invasion, whether a practicing cardiologist living in Venezuela is also a ransomware mastermind and effective bot management tooling strategies.

Episode metadata supplied by the publisher feed · Published Aug 11, 2022

Embed this episode

NOW PLAYING

Cyber Operations Keep Affecting Civilians as War Continues

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Cyber operations keep impacting civilians as Russia's war continues, and echolyologists stand accused of being a ransomware kingpin. But is he the victim? These stories and more on this week's ISNG security report. Hello, I'm Anna Delaney.

More than 165 days after Russia invaded Ukraine, the conflict continues. Many might not think that cyber attacks have been a major feature of the war, but experts who've been tracking the conflict have counted more than 300 such cyber operations. What joining me to discuss is Matthew Schwartz, executive editor at ISNG. Matt, there's a sense that there never really was a cyber war component to Russia's invasion, but you've reported on that being a substantial number of attacks.

Yes, more than 300 cyber attacks and cyber operations tied to the conflict have been tracked so far. That count comes from Cyber Peace Institute. It's an independent and neutral non-governmental organization based in Geneva, whose mission is to reduce the harms from cyber attacks on people's lives and promote responsible behavior, not least by governments. And it's been monitoring how such online attacks, including against critical infrastructure, have been affecting civilians since Russian Federation forces first invaded Ukraine.

I spoke with Emma Raffrak, a senior analyst at the Institute. At the core of our work, our data-centric projects in which we document cyber attacks and harm and as generated as a result of these attacks. So we launched a platform called Cyber Attacks in Times of Conflict, in which we're tracking attacks on organizations in Ukraine, the Russian Federation and other countries which have been attacked as a result of spillover effects of the conflict itself. So today, we've documented attacks on 27 countries beyond Ukraine and the Russian Federation.

And we've got an excess of 300 cyber attacks documented as of 29 July. And really the part that is most worrying in the context of the incidents that we've tracked today is that 19 different sectors have been targeted as part of these campaigns. And of these, we're seeing particularly worries and attacks against public administrations, media organizations, the financial sector, the energy sector, telecommunications and the ICT, as well as transportation networks. So yeah, these are some of the high level figures.

And so far, we've also documented attribution by third parties to 36 different threat actors ranging from nation states to hacking collectives and cyber criminal groups. Cyber Peace Institute tracks these attacks against four core categories, destruction, disruption, data, weaponization, and disinformation and propaganda. It's important to note that the cyber attacks during the armed conflict in Ukraine have destroyed data and systems, disrupted critical infrastructure and services, controlled the information space and accelerated significant volumes of data. And as you know, Cyber Peace Institute has been tracking a high number of attacks, but do you think there's a lack of awareness of the true cyber attack impacts being felt as a result of this conflict?

Definitely. There's a feeling I think that cyber war never really happened. And that's why work being done by groups such as Cyber Peace Institute is so important. Hadaloguing these attacks helps hold attackers, including governments to account not least for the unacceptable impact their operations are having on civilians.

I asked the institutes and the referee to describe that impact for me in more detail. So this is really the bread and butter of our work here at the Institute. And because of the reporting loss of life of attacks using traditional weapons in Ukraine, really the impact of cyber attacks and operations has actually been masked in a way by the reporting of what are very, very distressing scenes in the country. The volume and scope of cyber attacks Ukraine has actually been very high and would have normally drawn a much higher attention if the kinetic attacks hadn't been so severe.

And the attacks against Ukraine by the Russian state are not new. But what we're seeing really in the context of war and what is causing us a significant amount of alarm and concern is a tax on critical infrastructure and essential services that are not military targets. What are some examples of this impact, Matt? Unfortunately, there are so many.

One of the big ones that a lot of people have heard of is access to the VSSAT satellite communications network, which was knocked out on the day of the invasion. Another example is on April 8, Ukraine successfully blocked an attack, which if it hadn't succeeded, would have knocked out electricity for two million people. Another one comes from Everafre. She told me that Wiper Malware has had an impact during the war and sometimes in unexpected ways.

When we look at destructive attacks, we documented several of these in half how they've actually caused harm to the civilian population. So one of them is on the 20th of February is the Wiper attack that targets at the border control station. And this actually showed the processing of refugees crossing the border from Ukraine into Romania. So this is one very real example of how the attacks had a concrete impact in real life and on the civilian population.

Unfortunately, one of the big takeaways here is that as the war continues, so too do the online attacks and their unacceptable impact on civilians. Well, Matt, thank you very much for updating us on the conflict. Thank you, Anna. You're listening to the ISNG Security Report on ISNG Radio, ISNG, your number one source for information security news.

You may recall a few months back the astonishing story of a Venezuelan doctor being charged by the US for using and selling Tharnos Ransomware. It was not a story that ISNG's Jeremy Kirk was going to miss out on investigating in the ransomware files. In fact, the story is so intriguing, he's dedicated not one, but two episodes to it. Here's a taster.

He's a practicing cardiologist living in Venezuela, also a cyber criminal mastermind. If US prosecutors are to be believed, Moses-Louis-Sigala Gonzalez is a polymath who not only treats hard patients, but also allegedly sells malicious software on the dark web. He was charged by the US government in May with creating ransomware programs called Jigsaw and Tharnos. The government alleges he's an old-school hacker from the late 1990s who got into ransomware as a side hustle alongside his career as a cardiologist in Ciudad Bolivar as a city in southeastern Venezuela.

Here's Alexander Mindlin, who is an assistant US attorney with the eastern district of New York who will prosecute the case. He's accused essentially of conspiring with users of his ransomware to carry out ransomware attacks on victim networks. Moses is now 55 years old, which is pretty far out of the typical age range of someone in the ransomware business. By all appearances, he comes from a real high-achieving family.

There's a brother who's a dental specialist, another brother who's a lawyer, and yet another is in a high-ranking job in the national police. People who know him and his family are dumbfounded and say the accusations could absolutely not be true. I know Moses and his family, and they are a beautiful family, very united. I have never known them to be involved in anything out of the ordinary.

But Moses' wife says there's a reason for her husband's predicament and that he will defend himself. And what he says is a man of integrity, a family of men with values and principles will never lend himself to such acts. God willing, we'll get the right legal team to clear his name and negotiate him. The US government accessed what it alleges are Moses' online accounts, including one that held cryptocurrency as well as Gmail and PayPal accounts.

There's a wealth of digital evidence that's cited in the criminal complaint, including digital accounts that are under the name Moses Gala. But how does it all add up, and would it be a slam-dunk case against him if he went to trial? It seems too difficult for this to be exactly true, could anyone this smart be that sloppy? The voice you're hearing is from a digital forensics expert who has worked to complicate a case involving digital evidence.

My name is Tony Martino. I'm the Director of the Northeast Cybersecurity and Forensic Center at University in Utica, New York. Tony reviewed the government's complaint against Moses. Tony says with digital evidence, you still have to have a strong link between the cyber world and someone's body.

He's not convinced that the government has necessarily shown that in this case. But Tony cautions that the government doesn't have to show all of its cards in a criminal complaint, so it may have more compelling evidence that we haven't seen. And that's always the key in cyber investigations is who actually done it, not what user account did it, or even what IP address did it, who was at the keyboard in the mouse when it happened. And that's been a problem since the non-asider crime.

There's much, much more on this episode of the Ransomware Files. It's called Dr. Ransomware Part 2 and is part of a two-part series into this fascinating case. The second episode looks at Moses and if perhaps we're all just missing something.

You can find it on ISMG's websites or wherever you get your podcasts. For information security media group, I'm Jeremy Kirk. And finally, I spoke recently with Sandy Cariani, principal analyst at Forrester, who shared the latest bot management trends she's detailed in the Forrester Wave Bot Management Quarter 2 report. I asked her for her advice on effective bot management strategies that online businesses should consider.

Here she is. One of the things, Anna, that I think people didn't realize early on with bots is they thought it was just another application attack. And so they thought that, okay, it's a huge influx of automated traffic trying to take advantage of our application. So of course, our web application firewall or our DDoS service is going to protect us from that.

One of the trends that I think people have realized is that you actually do need a bot management solution. You do need something that looks at business logic types of attacks because that's where bots are really going after. They're not usually going after failures in web applications. There is this notion of Web Recon where bots will look for flaws in web apps in order to mount a more sophisticated attack later.

But that is less common than bots that are trying to do credential stuffing or bots that are trying to do inventory wording. That's where a lot of the news says PS5 a couple of years ago, graphics cards, now even hoarding of vaccines, hoarding of other types of things that are in low supply. Anything that people want that is hard to get, you're starting to see bots come to before. I was talking to one vendor several months ago who said, I made a joke.

I said, all right, we're going to see formula bots soon because I was at whole run on baby formula and he turned to me and said, Sandy, already seen them. So I think the important thing to note is that while you have all of your traditional web application protections, you do need that bot specific element that's going to speak to the business logic. That's it from the ISNG Security Report. Be music is by Ithaca Audio.

I'm Anna Delaney. Until next time.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on August 11, 2022.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!