How have Russian cyberattack capabilities evolved in 2024? What changes have you observed compared with the previous year?
In 2023, we saw destructive cyberattacks by Russian hacker groups targeting IT and telecommunications companies. At least 11 internet service providers suffered from such attacks, culminating in the cyberattack on Kyivstar in December 2023. These attacks were accompanied by leaks and data publications on Russian social media networks.
In 2024, Russia gradually shifted away from publicising its cyberattacks, as it focused instead on cyber intelligence operations targeting systems linked to war and politics, aiming to remain undetected for as long as possible. The main targets were Ukraine’s security and defence sectors, as well as companies directly supporting them.
There was also a significant increase in the activity of Russian financially motivated groups in 2024, including targeted cyberattacks on large organisations and various fraud schemes. We believe these hacker groups operate under the direction or approval of the Russian government, as some engage in both financial theft and cyber espionage.
Have you observed AI-enabled cyberattacks from Russia? Has the broader use of AI led to any significant changes?
AI is already being used in cyberattacks, for example, to generate phishing emails in Ukrainian or to facilitate interactions between hackers and victims through messaging apps or email. The use of AI components will undoubtedly increase further.
In 2024, there was only one widely publicised attack on Ukraine’s critical infrastructure – the December attack on state registries. Does this suggest your defences have been largely effective? Which critical sectors faced the greatest threats last year?
Indeed, 2024 ended with a high-profile attack on the Ministry of Justice’s registries. However, attempts to target critical infrastructure were detected throughout the year.
For example, in March, preparations by UAC-0002 (also known as Sandworm) for cyberattacks were uncovered. These attacks aimed to disrupt the stable operations of approximately 20 energy, water and heating companies across ten Ukrainian regions. The attacks were attempted through compromised supply chains, specifically through Ukrainian companies developing specialist software for industrial systems.
Thanks to operational measures to detect and respond to these preparations, the attacks were thwarted. Interestingly, the timing of these activities coincided with missile strikes against Ukrainian infrastructure in the spring of 2024, which suggests the cyberattacks were intended to amplify the impact of physical strikes.
Another incident involved the discovery of malware called FrostyGoop at a Ukrainian energy-sector company. It was specifically designed to target industrial systems. This demonstrates that Russian actors continue to refine their tools and plan further attacks on critical infrastructure.
How would you characterise Russian hacktivists attacking Ukraine? Are they more of a nuisance or a serious threat?
We cannot say that Russian hacktivists significantly contribute to cyberspace warfare compared with Russia’s well-known state-backed hacker groups. However, it is important to note that in a totalitarian state like Russia, there are no truly independent hacktivists. To some extent, they are all under government control and work for the Russian state. A growing concern is that these hacktivists serve as a reserve pool for Russia’s intelligence services, which could eventually involve them in more complex cyberattacks.
Now that North Korea is increasingly involved in the conflict, have you seen more cyberattacks originating from that region?
So far, we have not identified any cyberattacks linked to North Korean hacker groups. Still, we cannot rule out the possibility of their involvement in future cyber operations, as Russia’s collaboration with North Korea is growing by the day.
What do you foresee as the biggest cyber threats in 2025, both for Ukraine and globally?
In 2025, we expect an increase in cyber intelligence operations targeting Ukraine’s security and defence sectors, as well as its defence industry.
Given Russia’s preparations for a potential war with NATO, cyber intelligence operations against military organisations in NATO member states will also intensify.
Destructive cyberattacks on critical infrastructure will become more frequent and will likely coincide with physical sabotage activities, which Russia has already initiated against NATO member states.
We are also seeing a growing number of financially motivated cyberattacks from Russia against Ukrainian commercial enterprises. This trend is expected to continue and will likely spread to NATO countries. The use of AI in conducting such cyberattacks and the cooperation between cybercriminals and the Russian government, which shields them from international prosecution, will further exacerbate the threat.
Last updated: 17.02.2025