۴ý

Skip to main content

Ukraine digital army brews cyberattacks, intel and infowar

Share
BOSTON -

Formed in a fury to counter Russia's blitzkrieg attack, Ukraine's hundreds-strong volunteer "hacker" corps is much more than a paramilitary cyberattack force in Europe's first major war of the internet age. It is crucial to information combat and to crowdsourcing intelligence.

"We are really a swarm. A self-organizing swarm," said Roman Zakharov, a 37-year-old IT executive at the center of Ukraine's bootstrap digital army.

His group's inventions run from software that lets anyone on the planet with a smartphone or computer participate in distributed denial-of-service attacks on official Russian websites to bots on the Telegram messaging platform that block disinformation, let people report Russian troop locations and offer instructions on assembling Molotov cocktails and basic first aid.

Zahkarov ran research at an automation startup before joining Ukraine's digital self-defense corps. His group is StandForUkraine. Its ranks include software engineers, marketing managers, graphic designers and online ad buyers, he said.

The movement is global, drawing on IT professionals in the Ukrainian diaspora whose handiwork includes web defacements with antiwar messaging and graphic images of death and destruction in the hopes of mobilizing Russians against the invasion.

"Both our nations are scared of a single man -- (Russian President Vladimir) Putin," said Zakharov. "He's just out of his mind." Volunteers reach out person-to-person to Russians with phone calls, emails and text messages. They send videos and pictures of dead soldiers from the invading force from virtual call centers.

Some build websites. "We did a site where Russian mothers can look through (photos of) captured Russian guys to find their sons," Zakharov said by phone from Kyiv, the Ukrainian capital.

The volunteer cyber army's effectiveness is difficult to gauge. Russian government websites have been repeatedly knocked offline, if briefly, by the DDoS attacks, but generally weather them with countermeasures.

It's impossible to say how much of the disruption -- including more damaging hacks -- is caused by freelancers working independently of but in solidarity with Ukrainian hackers.

A tool developed by Zakharov's team called "Liberator" lets anyone in the world with a digital device become part of a DDoS attack network, or botnet. The tool's programmers code in new targets as priorities change.

A top Ukrainian cybersecurity official, Victor Zhora, said at his first online news conference of the war Friday that homegrown volunteers are attacking only what they deem military targets, prioritizing government services including the financial sector, Kremlin-controlled media and railways. He did not discuss specific targets.

Zakharov did. He said Russia's banking sector was well fortified against attack but that some telecommunications networks and rail services were not. He said Ukrainian-organized cyberattacks had briefly interrupted rail ticket sales in western Russia around Rostov and Voronezh and knocked out telephone service for a time in the region of eastern Ukraine controlled by Russian-backed separatists since 2014. The claims could not be independently confirmed.

A group of Belarusian hacktivists calling themselves the Cyber Partisans also apparently disrupted rail service in neighboring Belarus this week seeking to frustrate transiting Russian troops. A spokeswoman said Friday that electronic ticket sales were still down after their malware attack froze up railway IT servers.

Over the weekend, Ukraine's minister of digital transformation, Mykhailo Fedorov, endorsed a volunteer group calling itself the IT Army of Ukraine, which now counts 290,000 followers on Telegram.

Zhora, deputy chair of the state special communications service, said one job of Ukrainian volunteers is to obtain intelligence that can be used to attack Russian military systems.

Some cybersecurity experts have expressed concern that soliciting help from freelancers could have dangerous escalatory consequences. One shadowy group claimed to have hacked Russian satellites; Dmitry Rogozin, the director general of Russia's space agency Roscosmos, called the claim false but was also quoted by the Interfax news agency as saying such a cyberattack would be considered an act of war.

Asked if he endorsed the kind of hostile hacking being done under the umbrella of the Anonymous hacktivist brand -- which anyone can claim -- Zhora said, "We do not welcome any illegal activity in cyberspace."

"But the world order changed on the 24th of February," he added, when Russia invaded.

The overall effort was spurred by the creation of a group called the Ukrainian Cyber Volunteers by a civilian cybersecurity executive, Yegor Aushev, in coordination with Ukraine's Defense Ministry. Aushev said it numbers more than 1,000 volunteers. Zakharov said his group has 900 members.

On Friday, most of Ukraine's telecommunications and internet were fully operational despite outages in areas captured by invading Russian forces, said Zhora. He reported about 10 hostile hijackings of local government websites in Ukraine to spread false propaganda saying Ukraine's government had capitulated.

Zhora said presumed Russian hackers continued trying to spread destructive malware in targeted email attacks on Ukrainian officials and -- in what he considers a new tactic -- to infect the devices of individual citizens. Three instances of such malware were discovered in the runup to the invasion.

U.S. Cyber Command has been assisting Ukraine since well before the invasion. Ukraine does not have a dedicated military cyber unit. It was standing one up when Russia attacked.

Zhora anticipates an escalation in Russia's cyber aggression -- many experts believe far worse is yet to come.

Meantime, donations from the global IT community continue to pour in. A few examples: NameCheap has donated internet domains while Amazon is offering cloud services, said Zakharov.

He said he has international collaborators he calls "the gold team" -- elite hackers and entrepreneurs so prized they don't need to work for a single employer.

"Even Google can't afford these people."

CTVNews.ca Top Stories

The president and CEO of New Brunswick-based Covered Bridge Potato Chips is taking an 'extended leave of absence' after being charged with domestic violence this past weekend.

A memorial is growing outside a Walmart in Halifax after a 19-year-old employee was found dead inside an oven in the store Saturday night.

A search has started at Prairie Green Landfill for the remains of two victims of a serial killer.

He is a familiar face to residents of a neighbourhood just west of Roncesvalles Avenue.

Canada's discount airline is suspending operations to and from Saskatoon.

Local Spotlight

He is a familiar face to residents of a neighbourhood just west of Roncesvalles Avenue.

A meteor lit up our region's sky last night – with a large fireball shooting across the horizon over Lake Erie at around 7:00 p.m.

Residents of Ottawa's Rideauview neighbourhood say an aggressive wild turkey has become a problem.

A man who lost his life while trying to rescue people from floodwaters, and a 13-year-old boy who saved his family from a dog attack, are among the Nova Scotians who received a medal for bravery Tuesday.

A newly minted Winnipegger is hoping a world record attempt will help bring awareness for the need for more pump track facilities in the city.

A Springfield, Ont. man is being hailed a 'hero' after running into his burning home to save his two infant children.

Hortense Anglin was the oldest graduate to make her way across the platform at York University's Fall Convocation ceremony this week. At the age of 87, she graduated with an Honours degree in Religious Studies.

Looking for a scare with good intentions this Halloween season? The ghosts and ghouls of Eganville, Ont. invite families to tour the Haunted Walk at Lekbor Manor.

The image of a sleepy Saskatchewan small town with 'not a lot going on' is a well-known anecdote. However, one Saskatchewan company is hoping to change that – and allow communities both on and off the beaten path to share their stories and advertise what they have to offer.