10 May 2022: On Tuesday, the US and European Union said Russia was responsible for a cyberattack in Feb that crippled a satellite network in Ukraine and neighboring countries, disrupting communications and a wind farm used to generate electricity.
– The 24 Feb attack unleashed wiper malware that destroyed thousands of satellite modems used by Viasat’s customers.
– Security firm SentinelOne said an analysis of the wiper malware used in the attack shared multiple technical similarities to VPNFilter, a piece of malware discovered on more than 500,000 home and small office modems in 2018.
– Multiple US government agencies attributed VPNFilter to Russian state threat actors.
– AcidRain, the name of the wiper analyzed by SentinelOne, is a previously unknown piece of malware.
– AcidRain, using an executable file for the MIPS hardware in Viasat modems, is the seventh distinct piece of wiper malware associated with Russia’s ongoing invasion of Ukraine.
– Wipers destroy data on hard drives in a way that can’t be reversed. In most cases, they render devices or entire networks completely unusable.
– “After those modems were knocked offline it wasn’t like you unplug them and plug them back in and reboot and they come back…They were down and down hard; they had to go back to the factory to be swapped out” according to NSA’s Director of Cybersecurity, Rob Joyce.
– One of the first signs of the hack occurred when more than 5,800 wind turbines belonging to the German energy company Enercon were knocked offline. The outage didn’t stop the turbines from spinning, but it prevented engineers from remotely resetting them.
– Ahead of Russia’s invasion of Ukraine, Western intelligence agencies warned of potential cyberattacks which could spread elsewhere and cause “spillover” damage on global computer networks.
– There was a flurry of cyber operations against Ukrainian targets in the weeks ahead of Russia’s invasion on Feb. 24.
– In January, researchers discovered destructive malware called WhisperGate circulating in Ukraine. WhisperGate closely mirrored a 2017 Russian cyberattack against Ukraine, known as NotPetya, that similarly destroyed data on thousands of local computer systems.
– After WhisperGate’s discovery, a spate of distributed denial of service (DDoS) attacks briefly knocked Ukrainian banking and government websites offline. The DDoS flood was later attributed to Russia by Britain and the United States.
– Another potential target for Russian cyber operations is the SpaceX Starlink network which is now in use throughout Ukraine. According to Elon Musk, “Starlink has resisted Russian cyberwar jamming & hacking attempts so far, but they’re ramping up their efforts”