{"id":53331,"date":"2022-12-27T07:24:00","date_gmt":"2022-12-26T23:24:00","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=53331"},"modified":"2022-12-26T13:25:56","modified_gmt":"2022-12-26T05:25:56","slug":"kaspersky-reports-on-what-cyber-confrontation-looked-like-in-2022","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2022\/12\/27\/kaspersky-reports-on-what-cyber-confrontation-looked-like-in-2022\/","title":{"rendered":"Kaspersky reports on what cyber confrontation looked like in 2022"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>In their latest report, Kaspersky\u2019s experts analyze cyberspace activities relating to the Ukrainian crisis, observing their meaning in relation to the current conflict, and their impact on the cybersecurity field. This report is a part of Kaspersky Security Bulletin (KSB) \u2013 an annual series of predictions and analytical reports on key shifts within the cybersecurity world.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">2022 was marked by a 20<sup>th<\/sup> century-style military conflict \u2013 that definitely brought uncertainty to and some serious risks of spreading over the continent. While the broader geopolitical analysis of the conflict in Ukraine and its consequences are best left to experts, a number of cyber-events took place during the conflict that turned out to be very significant.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The story of the year, prepared by Kaspersky researchers within the annual Kaspersky Security Bulletin, tracks every stage of the armed conflict in Ukraine, the events that have taken place in cyberspace and how they correlated with on-the-ground operations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Significant signs and spikes in cyberwarfare in the days and weeks pre-dating military conflict were seen. February 24, 2022 saw a massive wave of pseudo-ransomware and wiper attacks indiscriminately affecting Ukrainian entities. Some were highly sophisticated, but the volume of wiper and ransomware attacks quickly subsided after the initial wave, with a limited number of notable incidents subsequently reported. Ideologically-motivated groups that presented themselves in the original wave of attacks appear to be inactive now.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/NordnetOFFICIEL\/status\/1496774782527979523\"> February<\/a> 24, Europeans relying on the ViaSat-owned satellite faced major internet access disruptions. This \u201c<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.cnbc.com\/2022\/02\/28\/ukraine-updates-viasat-says-cyber-event-disrupting-satellite-internet-service.html\">cyber-event<\/a>\u201d<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/netblocks\/status\/1498365220107997191?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1498365220107997191%7Ctwgr%5E%7Ctwcon%5Es1_&amp;ref_url=https%3A%2F%2Fnetblocks.org%2Freports%2Finternet-disruptions-registered-as-russia-moves-in-on-ukraine-W80p4k8K\"> started around 4h UTC<\/a>, less than two hours after the Russian Federation publicly<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/novayagazeta.ru\/articles\/2022\/02\/24\/my-budem-stremitsia-k-demilitarizatsii-i-denatsifikatsii-ukrainy-putin-obiavil-o-nachale-spetsoperatsii-v-ukraine-news\"> announced the beginning<\/a> of a \u201cspecial military operation\u201d in Ukraine. The ViaSat sabotage once again demonstrates cyberattacks are a basic building block for modern armed conflicts and may directly support key milestones in military operations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As the conflict has evolved, there is no evidence that the cyberattacks were part of coordinated military actions on either side. However, there are some main characteristics that defined the 2022 cyber confrontation:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Hacktivists and DDoS attacks. <\/strong>The conflict in Ukraine has created a breeding ground for new cyberwarfare activity from various groups including cybercriminals and hacktivists, rushing to support their favorite side. Some groups such as the IT Army of Ukraine or Killnet have been officially supported by governments and their Telegram channels include hundreds of thousands of subscribers. While the attacks performed by hacktivists had relatively low complexity, the experts witnessed a spike in DDoS activity during summer period \u2013 both in number of attacks and their duration: in 2022, an average DDoS attack lasted 18.5 hours \u2013 almost 40 times longer compared to 2021 (approx. 28 minutes).&nbsp;<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/ecp.yusercontent.com\/mail?url=https%3A%2F%2Flh3.googleusercontent.com%2FNygHO7G-uq5ljF76m3PmpvTa9oJg75zGUvXjr9mLVOijZn8_XU2g65v3zNPYayHsM8bYyK-LX_edUpNBZ3tkbWIKggLpxvs9eAwbZM0VQ4a5D4oNF20rDoM3QDSOX9UDgVvzHcJBJ7hvVCs6yzAna8JZpTh9mw3oY_w6v7gb-CA_l3ukEWbqIo0Puz2P_Q&amp;t=1672032232&amp;ymreqid=27f3344f-c727-c29c-1c8c-650076018c00&amp;sig=guaRV.ekC6btQHXNZm8uRQ--~D\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Total duration of DDoS attacks detected by Kaspersky DDoS Protection in seconds,\u00a0by week, 2021 vs 2022<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Hack and leak.<\/strong> The more sophisticated attacks attempted to hijack media attention with hack-and-leak operations, and have been on the rise since the beginning of the conflict. Such attacks involve breaching an organization and publishing its internal data online, often via a dedicated website. This is significantly more difficult than a simple defacing operation, since not all machines contain internal data worth releasing.&nbsp;<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Poisoned open source repositories, weaponizing open source software<\/strong>. As the conflict drags on, popular open source packages can be used as a protest or attack platform by developers or hackers alike. The impact from such attacks can extend wider than the open source software itself, propagating in other packages that automatically rely on the trojanized code.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Fragmentation.<\/strong> Following the start of the Ukraine conflict in February 2022, many western companies are exiting the Russian market and leaving their users in a delicate position when it comes to receiving security updates or support \u2013 and the security updates are probably the top issue when vendors end support for products or leave the market.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;\u201cFrom February 24 onwards, we\u2019ve been puzzled with a question, if cyberspace is a true reflection of the conflict in Ukraine, it represents the pinnacle of a real, modern \u2018cyberwar\u2019. By going through all the events that followed military operations in cyberspace, we witnessed an absence of coordination between cyber and kinetic means, and in many ways downgraded cyber-offense to a subordinate role. Ransomware attacks observed in the first weeks of the conflict qualify as distractions at best. Kinetic attacks using missiles and unmanned aerial vehicles have once again proven to be a more effective method of targeting infrastructure than cyberattacks. Nevertheless, collateral damage and cyber risks have grown for organizations in nearby countries due to the conflict, requiring advanced defensive measures more than ever,\u201d comments Costin Raiu, Director of Global Research &amp; Analysis Team at Kaspersky.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Read the full report on the 2022 cyber confrontation at<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/securelist.com\/reassessing-cyberwarfare-lessons-learned-in-2022\/108328\/\"> Securelist.com<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These are part of Kaspersky Security Bulletin (KSB) \u2013 an annual series of predictions and analytical reports on key shifts within the cybersecurity world. Follow\u202fthis<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/securelist.com\/ksb-2022\/\"> link<\/a>\u202fto learn more about other KSB pieces.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>2022 was marked by a 20th century-style military conflict \u2013 that definitely brought uncertainty to and some serious risks of spreading over the continent. While the broader geopolitical analysis of the conflict in Ukraine and its consequences are best left to experts, a number of cyber-events took place during the conflict that turned out to be very significant.<\/p>\n","protected":false},"author":6,"featured_media":53332,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[286,101,54,2103],"class_list":["post-53331","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-it-security","tag-kaspersky","tag-security","tag-security-breach"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/53331","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=53331"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/53331\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/53332"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=53331"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=53331"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=53331"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}