Russia Behind DDoS Cyberattacks That Took Down Ukraine Banks: US, UK why ?

US claims Russia's military agency was seen transmitting high volumes of communication to Ukraine-based IP addresses and domains. Russian military hackers were behind a spate of distributed denial of service (DDoS) attacks that briefly knocked Ukrainian banking and government websites offline, the United States and the United Kingdom said on Friday. US deputy national security adviser Anne Neubauer told journalists at the White House that Washington was seeking to hold Russia to account for its aggressive moves in cyberspace. Russia likes to move in the shadows and counts on a long process of attribution, Neuberger said. "In light of that, we're moving quickly to attribute the DDoS attacks. We believe the Russian government is responsible for widespread attacks on Ukrainian banks this week." Neuberger said that Americans have data showing that infrastructure connected with Russia's military agency, generally known as the GRU, "was seen transmitting high volumes of communication to Ukraine-based IP addresses and domains. "In a simultaneous announcement, British officials said the GRU was "almost certainly involved" in the DDoS, which works by flooding targeted websites with a fire hose of data. "The attack showed a continued disregard for Ukrainian sovereignty," Britain's Foreign Commonwealth and Development Office (FCDO) said in a statement. "This activity is yet another example of Russia's aggressive acts against Ukraine." "This disruptive behavior is unacceptable," the FCDO said. Russia has denied any role in the DDoS, which inflicted relatively limited disruption on Tuesday. Kyiv had already blamed Moscow for the DDoS amid heightened tensions since Russia began massing troops near the border, raising fears Russia was planning to attack. The Kremlin has denied it plans to push deeper into the country. Neuberger said that while the denial of service had "limited impact," the recent spate of malicious digital activity could be a prelude to "more disruptive cyberattacks accompanying a potential further invasion of Ukraine's sovereign territory." Cybersecurity experts say that if Russia does plan to invade Ukraine, it would undoubtedly use cyberattacks as a key part of its strategy — just as the country has done in previous military campaigns over the past decade-and-a-half. The secretary-general of NATO, Jens Stoltenberg, said there’s no evidence that Russia is pulling back on its forces near Ukraine, despite claims by the Russian military that it was starting to withdraw. “We do not see any sign of de-escalation on the ground,” Stoltenberg said, according to the BBC. A spokesperson for the Kremlin denied Russian involvement in the DDoS attack, according to the New York Times report. “We know nothing about it, but we are not surprised that Ukraine is continuing to blame Russia for everything,” the spokesperson, Dmitri S. Peskov, reportedly said. “Russia has nothing to do with any DDoS attacks. ”The attack targeting Ukrainian servers on Tuesday was indeed a powerful DDoS attack, according to findings from cyber firm CrowdStrike. “Telemetry acquired during the attacks indicates a large volume of traffic three orders of magnitude more than regularly observed traffic,” said Adam Meyers, senior vice president of intelligence at CrowdStrike, in an email statement. In the attack, 99% of the traffic consisted of HTTPs requests, “indicating the attackers were attempting to overwhelm Ukrainian servers,” Meyers said.

 

 

 

Enjoyed this article? Stay informed by joining our newsletter!

Comments

You must be logged in to post a comment.

About Author