Massive cyberattack takes Ukraine military, big bank websites offline
(2022/02/15)
- Reference: 1644954342
- News link: https://www.theregister.co.uk/2022/02/15/ukraine_cyberattack/
- Source link:
The websites of the Ukrainian military and at least two of the nation's biggest banks were knocked offline in a cyberattack today.
Ukraine's Ministry of Defense website is still unavailable at time of publication. On social media, [1]it reported "technical works on restoration of regular functioning" are underway after it was "probably attacked by DDoS: an excessive number of requests per second was recorded." Other military sites are also apparently suffering outages.
In what appears to have been a coordinated internet attack, Ukraine's biggest commercial banking operation PrivatBank and big-three financial institution Oschadbank were also hit around the same time, knocking out some online transactions and ATMs across the country.
[2]
Oschadbank is now back up and running albeit in a limited way. PrivatBank's website is still unavailable to use and instead shows a vandalized homepage.
[3]
Not a good look for one of your largest banks ... A screenshot of PrivatBank's defaced website. Click to enlarge
"PrivatBank has suffered a DDoS attack," the Ukraine government's Centre for Strategic Communications said [4]on Facebook though a defaced page suggests there's something more serious afoot than a distributed denial-of-service.
"For one hour during the attack, some services (ATM, TSO) were not working," the center added. "Starting at 1630 these services have been restored.
[5]
[6]
"Oshchadbank also suffered a DDoS attack. Work is currently underway to restore the system. It is already working in stable mode. There is only a slow entry to the Oshchad24/7 system due to an additional load on the communication channels."
The DDoS strikes should set off alarms in the minds of security engineers. Denial-of-service attacks are frequently used as a distraction while intrusion attempts are made or tested, and these are high-profile targets.
[7]Ukraine blames Belarus for PC-wiping 'ransomware' that has no recovery method and nukes target boxen
[8]Sniff those Ukrainian emails a little more carefully, advises Uncle Sam in wake of Belarusian digital vandalism
[9]Ukraine shrugs off mass govt website defacement as world turns to stare at Russia
[10]Russia starts playing by the rules: FSB busts 14 REvil ransomware suspects
Given [11]similar incidents last month against Ukrainian government websites attributed to Russia and its satellite-state [12]Belarus , not to mention a [13]five-year record of such shenanigans – and more than 100,000 Russian Armed Force troops near Ukraine's border – you'd have thought the Ukrainian military would have been better prepared for an online assault. It appears commercial operations are still getting the best talent.
Incidentally, Russian state-media org Tass [14]reports Russia is pulling back some troops from the border after "scheduled drills." ®
Get our [15]Tech Resources
[1] https://twitter.com/DefenceU/status/1493628291844083723
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YgwwlzkusxuBn5xxRjVfegAAABQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://regmedia.co.uk/2022/02/15/privatbank_cropped.jpg
[4] https://www.facebook.com/StratcomCentreUA
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YgwwlzkusxuBn5xxRjVfegAAABQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YgwwlzkusxuBn5xxRjVfegAAABQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2022/01/17/ukraine_pc_wiping_malware_belarus_accusations/
[8] https://www.theregister.com/2022/01/19/us_cisa_ukraine_cross_infection_warning/
[9] https://www.theregister.com/2022/01/14/ukraine_cyberattack_gov_websites_defaced/
[10] https://www.theregister.com/2022/01/14/russia_revil_ransomware_gang_charged/
[11] https://www.theregister.com/2022/01/14/ukraine_cyberattack_gov_websites_defaced/
[12] https://www.theregister.com/2022/01/17/ukraine_pc_wiping_malware_belarus_accusations/
[13] https://www.theregister.com/2016/08/04/smart_tvs_satellites_and_billboards_all_hacked_in_ukrainian_war/
[14] https://tass.com/defense/1403483
[15] https://whitepapers.theregister.com/
Ukraine's Ministry of Defense website is still unavailable at time of publication. On social media, [1]it reported "technical works on restoration of regular functioning" are underway after it was "probably attacked by DDoS: an excessive number of requests per second was recorded." Other military sites are also apparently suffering outages.
In what appears to have been a coordinated internet attack, Ukraine's biggest commercial banking operation PrivatBank and big-three financial institution Oschadbank were also hit around the same time, knocking out some online transactions and ATMs across the country.
[2]
Oschadbank is now back up and running albeit in a limited way. PrivatBank's website is still unavailable to use and instead shows a vandalized homepage.
[3]
Not a good look for one of your largest banks ... A screenshot of PrivatBank's defaced website. Click to enlarge
"PrivatBank has suffered a DDoS attack," the Ukraine government's Centre for Strategic Communications said [4]on Facebook though a defaced page suggests there's something more serious afoot than a distributed denial-of-service.
"For one hour during the attack, some services (ATM, TSO) were not working," the center added. "Starting at 1630 these services have been restored.
[5]
[6]
"Oshchadbank also suffered a DDoS attack. Work is currently underway to restore the system. It is already working in stable mode. There is only a slow entry to the Oshchad24/7 system due to an additional load on the communication channels."
The DDoS strikes should set off alarms in the minds of security engineers. Denial-of-service attacks are frequently used as a distraction while intrusion attempts are made or tested, and these are high-profile targets.
[7]Ukraine blames Belarus for PC-wiping 'ransomware' that has no recovery method and nukes target boxen
[8]Sniff those Ukrainian emails a little more carefully, advises Uncle Sam in wake of Belarusian digital vandalism
[9]Ukraine shrugs off mass govt website defacement as world turns to stare at Russia
[10]Russia starts playing by the rules: FSB busts 14 REvil ransomware suspects
Given [11]similar incidents last month against Ukrainian government websites attributed to Russia and its satellite-state [12]Belarus , not to mention a [13]five-year record of such shenanigans – and more than 100,000 Russian Armed Force troops near Ukraine's border – you'd have thought the Ukrainian military would have been better prepared for an online assault. It appears commercial operations are still getting the best talent.
Incidentally, Russian state-media org Tass [14]reports Russia is pulling back some troops from the border after "scheduled drills." ®
Get our [15]Tech Resources
[1] https://twitter.com/DefenceU/status/1493628291844083723
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YgwwlzkusxuBn5xxRjVfegAAABQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://regmedia.co.uk/2022/02/15/privatbank_cropped.jpg
[4] https://www.facebook.com/StratcomCentreUA
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YgwwlzkusxuBn5xxRjVfegAAABQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YgwwlzkusxuBn5xxRjVfegAAABQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2022/01/17/ukraine_pc_wiping_malware_belarus_accusations/
[8] https://www.theregister.com/2022/01/19/us_cisa_ukraine_cross_infection_warning/
[9] https://www.theregister.com/2022/01/14/ukraine_cyberattack_gov_websites_defaced/
[10] https://www.theregister.com/2022/01/14/russia_revil_ransomware_gang_charged/
[11] https://www.theregister.com/2022/01/14/ukraine_cyberattack_gov_websites_defaced/
[12] https://www.theregister.com/2022/01/17/ukraine_pc_wiping_malware_belarus_accusations/
[13] https://www.theregister.com/2016/08/04/smart_tvs_satellites_and_billboards_all_hacked_in_ukrainian_war/
[14] https://tass.com/defense/1403483
[15] https://whitepapers.theregister.com/
Defacement
diodesign
Yeah, noted.
C.
Somebody pulled down a poster
Anonymous Coward
https://imgs.xkcd.com/comics/cia.png
Defaced website? Bit more than a DDOS then, isn't it?