Ukraine hit by more cyberattacks, destructive malware
BOSTON (AP) — Ukraine’s parliament and other government and banking websites were hit with another punishing wave of distributed-denial-of-service attacks Wednesday, and cybersecurity researchers said unidentified attackers had also infected hundreds of computers with destructive malware.
Early Thursday local time in Ukraine, as fears of a Russian invasion heightened, the foreign ministry and council of ministers were unreachable and other sites were slow to load, suggesting the DDoS attacks were continuing, though there was no official confirmation.
Officials have long expected cyber attacks to precede and accompany any Russian military incursion, and analysts said the activity hewed to Russia’s playbook of wedding cyber operations with real-world aggression.
ESET Research Labs said it detected a previously unseen piece of data-wiping malware Wednesday on “hundreds of machines in the country.” It was not clear how many networks were affected.
“With regards whether the malware was successful in its wiping capability, we assume that this indeed was the case and affected machines were wiped,” said ESET research chief Jean-Ian Boutin. He would not name the targets but said they were “large organizations.” ESET was unable to say who was responsible.
Symantec Threat Intelligence detected three organizations hit by the wiper malware — Ukrainian government contractors in Latvia and Lithuania and a financial institution in Ukraine, said Vikram Thakur, its technical director.
All three had “close affiliation with the government of Ukraine,” said Thakur, indicating the targeted attacks. He said roughly 50 computers at the financial outfit were impacted, some with data wiped.
Asked about the wiper attack, senior Ukrainian cyber defense official Victor Zhora had no comment.
Boutin said the malware’s timestamp indicated it was created in late December.
“Russia likely has been planning this for months, so it is hard to say how many organizations or agencies have been backdoored in preparation for these attacks,” said Chester Wisniewski, principal research scientist at the cybersecurity firm Sophos. He guessed the Kremlin intended with the malware to “send the message that they have compromised a significant amount of Ukrainian infrastructure and these are just little morsels to show how ubiquitous their penetration is.”
Word of the wiper follows a mid-January attack that Ukrainian officials blamed on Russia in which the defacement of some 70 government websites was used to mask intrusions into government networks in which at least two servers were damaged with wiper malware masquerading as ransomware.
Thakur said it was too early to say if the malware attack discovered Wednesday was as serious as the variety that damaged servers in January.
Cyberattacks have been a key tool of Russian aggression in Ukraine since before 2014, when the Kremlin annexed Crimea and hackers tried to thwart elections. They were also used against Estonia in 2007 and Georgia in 2008.





