NCSC Annual Review 2023
Pages
Page 8 of 16
Case study: Russia - an acute and chronic cyber threat

Introduction
In cyberspace, Russia continues to be one of the world’s most prolific cyber actors. It dedicates significant resources towards conducting cyber operations around the globe and poses a significant and enduring threat to the UK. But what have we learnt from Russia’s cyber operations in Ukraine so far, and how might the value of cyber operations or use of capabilities differ depending on context to achieve their strategic objectives?
Russian cyber activity against Ukraine
On 24 February 2022, a cyber attack against Viasat, a US satellite communications company, began approximately one hour before Russia launched its further invasion of Ukraine. It was an attempt to cripple Ukrainian military operations and communications which spilled over into Europe affecting both organisations and citizens.
This was followed by destructive and disruptive cyber attacks on Ukrainian CNI, telecoms providers, government entities and an attempted attack on power grids. There has been a significant amount of wiper activity and these attacks have often accompanied military operations.
The integration of Russian cyber operations into its wider military campaign objectives has had an effect, but not on the scale many were expecting.
Since at least Russia’s illegal annexation of Crimea in 2014, Ukraine has worked tirelessly to build its cyber resilience and with western support, their defences have stood up robustly to Russia’s initial onslaught.
Attacks in the latest stages of the conflict now seem opportunistic rather than strategic.
But why haven’t we seen more destructive activity from Russian cyber actors? This could be due to a number of factors: the presence of state-aligned actors contributing to a ‘chaotic’ landscape; Russia not having enough coordination between different military actors; Russia taking a more cautious approach as to when to ‘burn’ its best capabilities; Russian actors relying on some elements of Ukrainian infrastructure themselves; and, fundamentally, the incredible resolve of Ukrainian cyber defences in rapidly responding to cyber attacks, and bringing themselves back online.
Whatever the case, it is clear cyber defenders have more of a say in what happens in this conflict than some of the rhetoric on Russia’s offensive cyber capabilities suggests.
Russian information advantage
In this conflict, much of the battle has been in the information space, with Russian actors waging operations to gain intelligence on adversaries to contest the very information about the war itself and the nature of the conflict, shaping the information space to its advantage.
And, while Russian cyber actors remain an acute threat, causing high-profile incidents, the impact is becoming more chronic as the targeting shifts to reflect Russia’s new geopolitical reality.
Cyber espionage continues to be used as an important tactical weapon, strategically and operationally, in supporting Russian political and economic objectives in Ukraine and around the world.
Since Russia’s further invasion of Ukraine, their cyber operations have expanded to include anything or anyone with a connection to Ukraine which seeks to gain an information advantage on the battlefield, and geopolitically.
This has obviously included traditional military and government targets, although cyber has provided Russia with new means to achieve their objectives. In August, along with the Security Service of Ukraine and Five Eyes partners, we publicly revealed that Russian military intelligence service (GRU) capabilities are targeting Ukrainian battlefield information, in this case from Android devices.
However, the reach of Russia’s cyber operations has also stretched to academics, think tanks, logistics and transport hubs, manufacturing companies, supply chains, charities and unassuming Internet of Things (IoT) devices.
For example, as stated publicly by Rob Joyce, Director of Cybersecurity at the NSA, Russia has targeted IoT surveillance cameras to aid their warfighting efforts, and routinely target the transport sector. Microsoft warned in December 2022 of Russia potentially targeting countries that provide vital supply chains of weaponry and humanitarian aid.
The point here is to not assume you are not important enough for Russian spies to take an interest, if it furthers their aims and objectives.
An initial interaction with an individual or organisation (in the form of an unsolicited approach on LinkedIn or an email with a malicious link) is all it could take to allow hostile actors into your networks, and find the information they want to use for their advantage.
The risk of supply chain compromise also continues to loom large. In 2021, we and our US partners attributed the unauthorised access of SolarWinds Orion software and subsequent targeting to Russia’s Foreign Intelligence Service (SVR).
These incidents are part of a wider pattern of cyber intrusions by the SVR who have previously attempted to gain access to governments across Europe and NATO members, and who continue to exploit vulnerabilities to this day.
A chain is only as strong as its weakest link.
Russian patriotic hackers
Over the past 18 months we have seen a new class of Russian cyber adversary emerge. State-aligned actors (the favoured language used by the UK government to describe these groups) are often sympathetic to Russia’s further invasion and are ideologically, rather than financially, motivated.
They have been emboldened to act with impunity, regardless of whether or not they have Russia’s backing.
Our Canadian allies wrote publicly about the emergence of the groups and highlighted how Russia has sought to project power by deploying destructive cyber attacks against the strategic CNI targets of their adversaries as geopolitical crises escalate. This includes aspirations to sabotage the operational technology (OT) utilised across CNI. We share their concerns; some non-state groups probably have a higher risk appetite than state groups we have tracked for years.
Some such groups may seek to tamper with any vulnerable CNI networks they can access, without being able to understand or control the impact of their actions.
These state-aligned actors might seemingly offer the Russian state ‘plausible deniability’ in its attacks, but that is where attributions by the UK government and our allies, together with technical advisories by the NCSC, are critical in unmasking the Russian state’s intent, and holding such actors to account.
These groups create a new set of unintended consequences, operating without constraints in a conflict – including unpredictable behaviour, heightening the risk of miscalculation. They also ask profound questions about who gets to operate in cyberspace and how.
Russian speaking ransomware organised crime gangs (OCGs)
Russian language criminals operating Ransomware and ‘Ransomware as a Service’ (RaaS), continue to be responsible for the most high-profile cyber attacks against the UK. Several of these groups are known to have varying links with the Russian state and many of their activities are tolerated.
Sanctions, indictments, and rewards levied on the likes of EvilCorp and the group behind Conti has seen them draw on the wider ecosystem to distance themselves from the larger OCG branding.
The ransomware model continues to evolve, with a well-developed business model, facilitating the proliferation of capabilities through RaaS. This is lowering the barriers to entry and smaller criminal groups are adopting ransomware and extortion tactics which are making a huge impact.
It is possible that Russia, or indeed any state, could purchase access to supportive companies and low equity/disposable capabilities to enact attacks, including destructive attacks, through ransomware. This would help them distance themselves from attribution and enable them to scale without having to garner accesses themselves.
However, most ransomware incidents are not due to sophisticated attack techniques. Success for the criminals is usually due to the result of poor cyber hygiene. Organisations are often not following NCSC advice and there are still very large volumes of victims.. In fact, ransomware attacks are rising. If organisations are not taking the correct protective measures, the threat will continue unabated as threat actors seek to exploit opportunities and maximise profits.
Russian attempts to manipulate democratic institutions
It is no secret that Russia seeks to weaken and divide their adversaries by interfering in elections, using mis and dis-information, cyber attacks, and other methods.
The UK government assesses that it is almost certain that Russian actors sought to interfere in the 2019 General Election. In the coming months, with UK and US elections on the horizon, we can expect to see the integrity of our systems tested again.
Protecting our democratic and electoral processes against foreign interference, whether from Russia or any other state, is and always will be an absolute priority for the NCSC and we will continue to support the government’s critical work in this area.
In the ‘Defending Democracy’ paper later in this report, we explore this theme in greater depth and identify the threats and security challenges our democracy faces online and how a collective effort across the whole of society and in partnership with allies is required to ensure our democratic institutions, traditions and values are well-prepared for this new phase in digital development.
What can cyber defenders do about it?
We may not necessarily be able to anticipate specific cyber attacks from Russia but we do prepare for all outcomes by investing in the UK’s cyber resilience.
And while NCSC services like Cyber Essentials are not intended to prevent attacks from sophisticated adversaries, the controls outlined are a good foundation on which to build and make them work a little harder.
Russia’s cyber activity may seem erratic, but it is targeted and dependent on its goals and motivations. They act in their own interests, and they are challenging our notion of what we consider to be critical and how we prioritise resilience across society.
Regardless of the threat, where it is coming from, and which methods are used, put simply we need to implement better cyber hygiene. We have the information and tools at our disposal to defend ourselves. We just need to use them better.