Advertisement
Advertisement

Ukraine says it thwarted Russian cyberattack on electricity grid

By:
Reuters
Updated: Apr 12, 2022, 14:36 UTC

LONDON (Reuters) - Russian hackers attempted to launch a destructive cyberattack on Ukraine's electricity grid last week, Ukrainian officials and cybersecurity researchers said on Tuesday.

Building cranes and power lines connecting pylons of high-tension electricity are seen in Kyiv

By James Pearson

LONDON (Reuters) -Ukraine said on Tuesday it had thwarted an attempt by Russian hackers last week to damage its electricity grid with a cyberattack.

“This is a military hacking team,” said government spokesman Victor Zhora. “Their aim was to disable a number of facilities, including electricity substations.”

“They did not succeed, and we’re investigating.”

Kyiv blamed the attack on a group dubbed “Sandworm” by researchers and previously tied to cyberattacks attributed to Russia. The attack was likely carried out to support Russian military activities in eastern Ukraine, Zhora said.

Russian officials could not be immediately reached for comment on Tuesday. Moscow has consistently denied accusations it has launched cyberattacks on Ukraine.

The Computer Emergency Response Team of Ukraine (CERT-UA) said in a statement the hackers had targeted computers controlling high voltage substations in Ukraine, belonging to an energy company which CERT-UA did not identify.

The hackers had struck in two waves, first compromising the power network no later than February, before the second attack, which included a plan to shut substations and harm infrastructure last Friday evening, it said.

Ukraine managed to prevent the attack from taking place, and there was no damage to the grid.

Slovakian cybersecurity firm ESET, which said it had worked with Ukraine to foil the attack, described the malware as an upgraded version of a programme which had caused power blackouts in Kyiv in 2016.

One piece of malware was designed to take over computer networks at the energy provider “in order to cut power”, while a second programme was deployed to wipe out data to slow attempts to get power back online.

“Sandworm is an apex predator, capable of serious operations, but they aren’t infallible,” John Hultquist of U.S. cybersecurity firm Mandiant said.

“It’s increasingly clear that one of the reasons attacks in Ukraine have been moderated is because defenders there are very aggressive and very good at confronting Russian actors.”

(Reporting by James Pearson; editing by David Evans and Gareth Jones)

About the Author

Reuterscontributor

Reuters, the news and media division of Thomson Reuters, is the world’s largest international multimedia news provider reaching more than one billion people every day. Reuters provides trusted business, financial, national, and international news to professionals via Thomson Reuters desktops, the world's media organizations, and directly to consumers at Reuters.com and via Reuters TV. Learn more about Thomson Reuters products:

Did you find this article useful?

Advertisement