Ukraine on Sunday said Russia was behind a cyberattack that defaced its government websites and alleged that Russia was engaged in a growing “hybrid war” against its neighbor.
The statement from the Ministry of Digital Development came a day after Microsoft said dozens of computer systems in an unknown number of Ukrainian government agencies had been infected with destructive malware disguised as ransomware.
This disclosure suggests that the defacing attack that attracted attention on official websites last week was a diversion.
“All the evidence points to Russia being behind the cyberattack. Moscow continues to wage hybrid warfare and is actively building up its forces in information and cyberspace,” the ministry statement said.
The attack comes as the threat of a Russian invasion of Ukraine looms and diplomatic talks to resolve the tense standoff appear to have stalled.
Microsoft said in a short blog post on Saturday that it first detected the malware on Thursday. This would coincide with the attack which temporarily took some 70 Ukrainian government websites offline.
Microsoft said in a separate technical article that the affected systems “represent multiple government, nonprofit, and information technology organizations.”
He said he didn’t know how many other organizations in Ukraine or elsewhere might be affected, but said he expected to hear more infections.
A senior private sector cybersecurity official in Kyiv, Oleh Derevianko, said the intruders penetrated government networks through a shared software vendor in a supply chain attack like the Russian cyber-espionage campaign. SolarWinds of 2020 which targeted the US government.
In 2017, Russia targeted Ukraine with one of the most damaging cyberattacks on record with the NotPetya virus, causing around €10 billion in damage worldwide. This virus, also disguised as ransomware, was a so-called “windshield wiper” that wiped out entire networks.
During Friday’s massive web downgrade, a message left by the attackers claimed they had destroyed data and uploaded it, which Ukrainian authorities said did not happen.
The message told Ukrainians to “be afraid and expect the worst”.