Cyber-attacks are nothing new. The first Denial of Service (DoS) attack dates back to 1988; a computer worm created by Robert Morris to highlight security flaws such as weak passwords.
But technology has rapidly evolved since then, with cyber-attacks having the potential to be hostile and becoming a primary weapon in modern warfare.
Since Russia’s invasion of Ukraine officially began in February, Russian sourced cyber-attacks increased over 800% in just 48 hours.
Effectiveness of attacks
Russia has often proved its capability in the online battlefield. In 2015, Russian hackers breached Ukraine’s electrical power grid causing massive widespread outages across the country.
In 2017, they unleashed the NotPeya Malware virus, which cost billions in damages and disruption to Ukraine’s virtual space.
Interestingly enough, cyberattacks directed at Ukraine have been relatively basic since the Russian invasion began. Most have been DoS attacks in which hackers bombarded Ukrainian government websites and servers with heavy traffic, making the servers unable to recognise legitimate users.
Meanwhile, Russian allies are also seizing the opportunity to launch global cyber-attacks: Iran launched a global cyber-espionage attack earlier this week targeting Europe, North America and Australia.
US and UK governments issued a warning in late February that a group known as MuddyWatter is targeting industries and private businesses in western countries. This group is part of Iran's Ministry of Intelligence and Security (MOIS) and targets a wide range of government and private-sector organisations.
Some of these industries include transportation, health care and critical infrastructure.
"MuddyWater actors are positioned both to provide stolen data and accesses to the Iranian government and to share these with other malicious cyber actors," US and UK agencies said.
The hacking collective, a group of hackers that has openly supported MOIS has been reported to employ open-source tools to gain access to sensitive information and deploy ransomware.
Attacks by these actors continue to ramp up and it seems no one is safe.
Australia is a target
As Australia is an ally of NATO, it makes us a target.
Last year, the Australian Cyber Security Centre (ACSC) warned the Iranian government-sponsored hackers were trying to gain access to Australian systems by exploiting vulnerabilities in Microsoft exchange.
A spokesperson for the ACSC said they encourage Australian organisations to adopt an enhanced cyber security protocols.
The pushback
Last week Ukraine called on its citizens to “take to their keyboards” and defend the country against the growing cyber threat.
Anonymous, the global ‘hacktivist’ community made moves against the Kremlin, officially declaring cyber war against the Russian government through twitter.
Source: Twitter
The global collective has previously claimed responsibility for attacks against a range of targets. Their attacks are often aligned with major events – such as the murder of George Floyd in 2020 – rolling with the theme of their ‘anti-oppression’ agenda.
On February 16, Anonymous TV released a video detailing a series of threats against the Russian government.
In typical Anonymous fashion, a figure dawned in a Guy Fawkes mask and distorted voice said:
“If tensions continue to worsen in Ukraine, then we can take hostage industrial control systems. Sole party to be blamed if we escalate on that will be the same one who started it in the very first place with troop buildups, childish threats and waves of unreasonable ultimatums.”
Several Russian government websites and media outlets have since been hit, as well as publishing Russian Department of Defence data.
As Russian media is heavily regulated, Anonymous went a step further to attack Russian TV channels to play uncensored news of the war to combat Russian propaganda.
While these attacks are unlikely to have a significant impact on Russia in the long run, it plays a significant role in exposing the citizens of Russia to what’s really happening. The Kremlin’s invasion of Ukraine has been filtered through a controlled media, with the government going to extreme lengths to censor Facebook and even shut down major independent media outlets.
And it’s working. Thousands of Russian citizens have taken to the streets to protest the invasion of Ukraine, defying police threats of arrest, fines and even imprisonment.
What does this mean for Australia?
Australian businesses are at serious risk of cyber-attacks due for voicing their support of Ukraine.
The Office of the Australian Information Commissioner (OAIC) says 55% of the 256 data breaches from July to December last year was the result of malicious attacks. 68% of these were identified as cyber-attacks.
The ACSC is also encouraging Australian businesses to prepare now and ensure their security is up to scratch to repel any potential attacks.
The organisation says It’s not a matter of if, but when.
Australian cybersecurity firm CyberCX says there are two primary risks involving cyberattacks from Russia:
Russian attacks would ‘spill over’ and affect Australian firms (particularly those with ties to Ukraine or NATO countries)
Russian-linked gangs may target Australian firms as part of a broader hit on Western assets.
CyberCX says they have already seen a rise in cyber extortion attacks on Australian targets in recent weeks.
How do businesses prepare?
Cyber security expert Ajay Unni suggests the following steps to be better prepared for an attack:
- Incident detection and mitigation- the first step is being able to detect and respond to security breaches. You need the right tools to identify any form of suspicious activity, such as cyber security consultants who can watch your computers and networks 24/7. If any suspicious activity is identified, a response is launched to mitigate the attack.
- Educate your employees- Cyber-talk can be confusing to the layman so it’s important to teach your employees about the likelihood of attacks, misinformation campaigns and attempts by malicious hackers to comprise systems. Unni says it’s also wise to ensure they receive regular security training.
- Re-evaluate privileged access- All new software and accounts should be monitored. Stronger authentication and overall identity and privileges can keep your company safe.
- Strengthen cyber security hygiene- Installing antivirus and malware software, keeping up to date with patches, and ensuring employees use strong passwords are all effective methods to make sure data is encrypted.
We have yet to face a war where attacks can be executed from behind a keyboard, and these are still very early days for the war in Ukraine. Cyber-attacks have the power to take down electrical grids and decimate economic infrastructure.
It is an understatement in saying cybersecurity has never been more important in the face of escalating modern war.
Written by Duncan Bailey