Issue 76

Cyber Attacks Disrupt Russian Satellite Internet

30 Jun 2023: Dozor-Teleport, a Russian satellite communications provider used by the country's Ministry of Defense and security services, was hit by hackers aligned with private military corporation (PMC), Wagner. On 3 July Dozor confirmed that hackers breached its systems. According to preliminary data, "the…

30 Jun 2023: Dozor-Teleport, a Russian satellite communications provider used by the country’s Ministry of Defense and security services, was hit by hackers aligned with private military corporation (PMC), Wagner. On 3 July Dozor confirmed that hackers breached its systems. According to preliminary data, “the infrastructure on the side of the cloud provider was compromised.” Watch video.

– Attackers targeted the satellite communication provider’s infrastructure, damaging user terminals. According to a pro-Ukrainian hacker and malware historian Herm1t, attackers could’ve severely damaged client equipment and the network core.

-Attacking a satellite provider’s ground based infrastructure is reminiscent of the Viasat attack which occurred just prior to Russia’s invasion of Ukraine in February 2022.

-Experts attributed the Viasat hack to Russia’s military intelligence arm, the GRU. But Wagner mercenaries could have worked closely enough with the GRU to have picked up techniques used in that attack. If so, it would have been easier for them to turn around and use these methods against Russia’s Dozor.

– According to the Internet Outage Detection and Analysis (IODA) project, the Dozor

network was down for 14 hours from 02:00 AM UTC to approximately 4 PM UTC on June 29.

– Dozor is part of Amtel Group, partly owned by Rosatom, Russia’s state nuclear energy corporation. All Amtel companies use the cloud provider Selectel, which was breached by

hackers targeting Dozor.

– Dozor-Teleport is used by Russia’s Ministry of Defense, ships of the Northern Fleet, the Federal Security Service (FSB), Rosatom, and other organizations. The network is also used by users in remote areas, such as tankers of Russia’s energy companies like Gazprom.

– The attackers portray themselves as associated with Yevgeny Prigozhin-led PMC Wagner, which recently attempted a march on Moscow. Earlier in the week, researchers discovered a ransomware strain called Wagner, that infects user devices and invites them to join the PMC Wagner.

– Additionally the attack defaced several Russian websites, publishing a message from the PMC Wagner claiming responsibility for the attacks. However, the Telegram page of the supposed attackers is not the same one used by PMC Wagner.

The attack would not be the first time hackers targeted Russian satellite networks. Last year, pro-Ukrainian hackers said they penetrated Gonets, a Russian low Earth orbit (LEO) satellite communications network, deleting a database crucial to its functioning.

Meanwhile, a group of hackers affiliated with Anonymous, NB65, said they disrupted Russia’s vehicle monitoring system by targeting Roscosmos, the Russian space agency.

Graphic circulated by the attackers claiming responsibility for the Dozor-Teleport disruption.

Cloudflare Radar traffic chart showing the Dozor network disruption on 29 June 2023.