NCSC Annual Review 2022
Looking back at the National Cyber Security Centre's sixth year and its key developments and highlights, between 1 September 2021 and 31 August 2022.
Pages
Page 8 of 33
State threats
The UK is a responsible, democratic cyber power that seeks to maintain its competitive edge in the rapidly developing cyber domain and uses the UK’s full spectrum of levers to detect, disrupt and deter its adversaries. However, there are some state actors, with malign intent, that do not operate under the same legal and democratic framework. Over the last year, the NCSC has continued to see state actors present a significant threat towards the UK and global cyber security.
While many countries use malign cyber capabilities to some extent, including to control their domestic information environments, the regimes that continued to present the most acute cyber threat to the UK and its interests were Russia, China, Iran and North Korea.
The type of cyber security threats that these states present varies widely, including:
-
Cyber-enabled espionage
unauthorised access or transfer of secret, classified or sensitive information to gain advantage over rivals
-
Destructive cyber capabilities
using tools such as wiper malware to damage IT systems or institutions
-
Cyber-enabled theft
to further strategic advantage or domestic control, for example of Intellectual Property or personal data of citizens
-
Hack and leak
stealing and publishing sensitive or restricted information to embarrass states or institutions or to undermine social cohesion
These actions are used to target the local and national Governments of other states and their critical national infrastructure, institutions and internal political processes.
In the coming years, with the proliferation of commercially available capabilities, the NCSC anticipates a wider number of states possessing the ability to pose threats to the UK’s cyber security.
Russia

The most significant development in the cyber security threat internationally was Russia’s illegal invasion of Ukraine and their use of cyber operations within it.
Since its creation in 2016 the NCSC has viewed Russia’s cyber capabilities and intentions as an acute and persistent threat to the UK’s interests – and this year was no different. Russia’s intelligence services are malign actors in cyberspace and have advanced cyber capabilities which they use to target their adversaries, including Western institutions. The UK Government has attributed cyber activity to all three Russian intelligence services, these are:
- The GRU: Military intelligence
- The SVR: Foreign Intelligence Service
- The FSB: Federal Security Service
In the last year, this threat was underlined by Russia’s invasion of Ukraine – a conflict in which they sought to use cyber capabilities to maximise their operational impact.
As Jeremy Fleming, Director of GCHQ, wrote in March:
we have seen the Russian state try to align and co-ordinate cyber capabilities alongside more traditional facets of military power. To date, this hybrid intent has not succeeded; the impact has been less than we (and they) expected. In part, this is because Ukraine has proved itself to be an extremely effective cyber defender. Since the annexation of Crimea in 2014, it has painstakingly developed a digital fortress.
In many ways, the first shots fired in the Russian invasion of Ukraine in 2022 were in cyberspace. A month before the Russian invasion, the GRU deployed WhisperGate wiper malware against Ukrainian Government targets. As the invasion drew closer, they launched Distributed Denial of Service (DDoS) attacks against Ukrainian Government websites and in the hours before the invasion, conducted a cyber attack against ViaSat, the communications company. The aim of the ViaSat attack was to impact Ukrainian military targets, but it also disrupted other customers.
While UK organisations did not experience significant cyber impact resulting from Russia’s invasion of Ukraine, Russia continues to be a persistent and active threat to the UK and its interests, which is why the NCSC continues to advise against complacency. In response to recent setbacks Russia has experienced on the battlefield in Ukraine, they could change their approach in the cyber domain of the conflict. The NCSC continues to recommend organisations follow its advice on operating in periods of heightened tensions.
The Russian cyber activities seen in Ukraine are the most recent examples of Russian activity in cyberspace, including against the UK. In recent years, the NCSC has called out the Russian State for its involvement in the compromise of SolarWinds, targeting the COVID vaccine supply chain and destructive cyber attacks against Georgia and Ukraine. In the last year, the NCSC published a technical advisory highlighting new malware – often known as “Sandworm” – used by the Russian GRU’s Main Centre for Special Technologies, the group behind the NotPetya attacks in 2017.
China

As the Government’s Integrated Review and National Cyber Strategy made clear, China’s technical development and evolution is likely to be the single biggest factor affecting the UK’s cyber security in the years to come.
China has also identified several existing and emerging technologies as being vital to its future national security. It has directed significant resources into emerging tech research and development and continues to push not only for parity with Western countries, but for technical supremacy. The technologies that China seeks to achieve dominance in include artificial intelligence (AI), quantum computing and semiconductors.
Since taking power nearly a decade ago, President Xi has overseen extensive reform of China’s intelligence and military apparatus, with a key priority being the fusion of military and civilian cyber capabilities. Since then, China’s Ministry of State Security (MSS) has emerged as a prolific and pervasive actor in cyberspace, undertaking a substantial global espionage campaign to meet political, socio-economic, and strategic objectives.
Following reforms, there has been a notable increase in the operational security, sophistication and ambition of both the MSS and the People’s Liberation Army (PLA). Electronic warfare, cyber and space capabilities have been consolidated into a single structure to enhance the military’s cyber power and information operations capabilities.
The Chinese cyber forces are also by far the largest in the world. In April 2022, FBI Director Christopher Wray judged that China has "a bigger hacking program than that of every other major nation combined.
The global scale of activity from these organisations has been well documented and the UK Government has called out various examples of malign Chinese behaviour in cyberspace, including the compromise of thousands of enterprises' Exchange servers around the world, through exploitation of a zero-day vulnerability.
Chinese activity has become ever more sophisticated, with China increasingly targeting third-party technology and service supply chains, as well as successfully exploiting software vulnerabilities. This approach shows no sign of abating.
Iran

The threat of cyber activity by the Iranian State first came to prominence in 2011, when it launched a campaign of DDoS attacks against the US financial sector, which continued into 2013. Using this relatively unsophisticated method, Iran was able to inflict damage which cost tens of millions of dollars to mitigate.
Iran remains an aggressive cyber actor with a range of espionage, disruptive and destructive cyber capabilities. Cyber actors associated with the Iranian State have also been implicated in attacks against victims in many countries. An example of this approach in the last year has been Iran’s attacks against the Government of Albania, which the UK Government recently called out. This attack involved the destruction of Government data and the disruption of essential government services, including in healthcare and education.
Although Iranian cyber actors’ capabilities are thought to be always improving, they rarely use the most advanced or up-to-date capabilities to conduct their operations. Iranian actors do not rely on zero-day vulnerabilities (recently discovered vulnerabilities that are not yet publicly known), as they have had success using published vulnerabilities to gain access to unpatched systems. In November 2021, the NCSC joined the Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) in the US and the Australian Cyber Security Centre (ACSC) to highlight that an Iranian state backed group were exploiting Microsoft Exchange and Fortinet vulnerabilities.
North Korea (DPRK)

While not as sophisticated as Russia, China and Iran, North Korea (DPRK) remains a capable actor in cyberspace. A key focus of North Korea’s malign cyber activity is cyber theft, using its cyber capability to bolster its poor economic situation through cyber crime. It also uses cyber activity to further consolidate the current regime, and to strengthen and maintain the DPRK’s ability to defend itself against perceived hostile actors.