March 14: discovery of CaddyWiper, the 4th wiper deployed during this conflict

March 8: RURansom, discovery of the first wiper targeting Russia

On Monday, February 21, 2022, Russian President Vladimir Putin announced the independence of the separatist regions (the Donetsk People's Republic and the Luhansk People's Republic) and began bombing the capital, Kyiv. Europe immediately condemned this decision, as did the United States, which triggered economic sanctions.

  1. A visible conflict
  2. Cyber risk: a less visible conflict
    1. The Ukrainian case
    2. THE RUSSIAN CASE
  3. Risk of escalation
  4. Cyber actions
  5. What about France?
  6. How to prepare?

A visible conflict

The effects of the war in Ukraine are undeniable. The escalation of this conflict will have direct economic consequences. Markets have already reacted sharply. The IMF remains concerned about a potential impact.

  • Economically, on one hand, because the supply chain is at risk of being disrupted: the aviation, automotive, agricultural equipment production, and certain pharmaceutical sectors are likely to be affected.
  • In terms ofenergy, the cost of gasis likely to see a significant increase. As a reminder, Russia holds the largest gas reserves. The country can therefore leverage this European dependency to apply pressure and drive up prices (even if the French government is trying to be reassuring on this subject), or even stop exports entirely. It is worth noting that Germany has suspended the Nord Stream 2 pipeline service. The price of oil will also be impacted; it had already climbed 3% on Thursday, with the price of a barrel of Brent crude already rising on its own to dangerously approach 100 USD, with many potential global impacts.
  • In terms of agriculture, Ukraine is the world's fourth-largest wheat exporter, and the current conflict has impacted its price (344 euros per ton). France is expected to be less affected.

Cyber risk: a less visible conflict

The Ukrainian case

Several organizations in Ukraine have been hit by an attack based on new malicious software known as "data wipers."

What is a wiper?

These are malwares designed to destroy a target by deleting, corrupting, or encrypting the majority of its data (caches, accounts, applications, files, settings, etc.). This renders the target unusable, and while the OS can often be reinstalled, the data is typically lost for good. This type of malware can target PCs, smartphones, or IoT devices, but in the majority of cases, they target Windows systems.

Two of these malwares have made headlines: WhisperGate and HermeticWiper. These have targeted Ukrainian infrastructure, as well as Latvia and Lithuania. Ukraine has also been the target of "DDoS" (Distributed Denial of Service) attacks, which prevented access to certain government websites.

What is it?

WHISPERGATE

The scale of recent attacks carried out against Ukraine, such as the cyberattack named " WhisperGate affected around fifteen Ukrainian government websites on January 14th; although not officially acknowledged by the Russian President, they could spread beyond Ukrainian borders.

CYCLOPS BLINK

The UK's National Cyber Security Centre (NCSC), the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) issued an alert regarding Cyclops Blink on Wednesday, February 23rd.

You can find the details of the report here:

https://www.ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Report.pdf

No attribution at this stage. However, there are possible links to the Sandworm group.

Who is Sandworm?
  • Also known as: Voodoo Bear, APT28, Fancy Bear, Sednit, Sofacy
  • Origin: Group believed to be linked to the GRU
  • Technique: phishing
  • Motivation: cyber espionage, sabotage, subversion
  • Target: Ukrainian companies and government agencies
  • Campaigns: 2015 BlackEnergy, 2016 Industroyer, 2017 Operation NotPetya, and the 2018 attacks against the Olympic Games.
Who is Cyclops Blink?

Active since 2019.

Family: successor to VPNFilter

Key feature:

  • It resists certain measures such as rebooting and firmware updates on affected systems.
  • It is deployed on devices from the network hardware company WatchGuard.

Capacity: allows for uploading and downloading files to and from its command server, as well as controlling, collecting, and exfiltrating device information. It is modular and scalable (new features can be added to it).

Recommendation:

  • Change passwords
  • Update devices
  • Apply the latest security patches
  • Use multi-factor authentication
  • Restrict communications with suspicious IPs

Follow the link below: https://detection.watchguard.com/

ISAACWIPER

According to ESET, IsaacWiper was deployed in campaigns separate from those of HermeticWiper.

IsaacWiper was reportedly used in a second attack, again against the Ukrainian government, on February 24. "IsaacWiper shares no code overlap with HermeticWiper and is significantly less sophisticated."

No official attribution has been made to date.

For a more in-depth analysis and to obtain the IoCs, here is the link to the ESET report:

https://www.welivesecurity.com/fr/2022/03/01/isaacwiper-hermeticwizard-nouveau-ver-effaceur-ukraine/

DDOS ATTACK

Numerous DDoS attacks have been discovered targeting government agencies, banks, and the Ukrainian military.

Katana

On Sunday, February 13, the Katana botnet hit the websites of several Ukrainian banks and government organizations. All were taken offline via a distributed denial-of-service attack.

Fox Blade

On February 24, Microsoft detected a new piece of malware named FoxBlade. It is believed to be a Trojan horse used for DDoS attacks.

According to Microsoft, the initial access method remains unknown at this time.

HERMETICWIPER

On Wednesday (although this malware dates back to December 28, 2021, as noted by ESET), Ukraine suffered a second assault, dubbed HermeticWiper. This is a data-wiping malware and GoLang-based ransomware. The malware targets financial and government institutions.

Family : successor to KillDisk.NCV

Aka : Win32/KillDisk.NCV

Key feature:

  • Requires initial system compromise before it can be executed. Execution has been observed following the compromise of a Windows domain controller. In other instances of the software, the initial compromise was not identified.
  • Data-wiping technique, exploited using EaseUS.
  • It directly targets Windows devices (Windows XP, Vista, 7, 10, and 11) and then manipulates the MBR (Master Boot Record). This is an area on a hard drive that allows the computer (or more precisely, the operating system) to understand how to read from and write to the storage medium. If the MBR is corrupted, the computer will never be able to boot again; everything will need to be reinstalled, and all data will be lost.
  • Targeted attack


Capability:
allows access to physical disks, leading to data corruption or total data loss.

Recommendations:

  • Enable sandboxing

CADDYWIPER

ESET analysts discovered a new wiper on March 14th, dubbed CaddyWiper. It differs from HermeticWiper, IsaacWiper, and WhisperGate.

It is a data-wiping malware.

THE TRICKY QUESTION OF ATTRIBUTION

The subject of attribution regarding these recent attacks is delicate. We must guard against making easy accusations without proof, as this requires raw data that we do not always possess. Attributing this type of attack takes time, and the recent attacks in Ukraine are too fresh. We must avoid reckless assumptions. In the case of Ukraine, the context is highly complex, even though direct cyber threats in retaliation were announced by the Russian President in the event of interference in the armed conflict.

Finally, there is also a risk that other actors may act opportunistically through the Russian aggression, or use false flags ("issuing false claims of responsibility"), and take advantage of the surrounding chaos to carry out attacks

THE RUSSIAN CASE

RURANSOM

A new malware has just been detected: RURansom. It is a wiper: it irreversibly encrypts files. It spreads like a worm and reportedly targets Russia specifically.

It was reportedly detected between February 26th and March 2nd.

Risk of escalation

We cannot say with certainty that this conflict will escalate.

What is certain is that war 3.0 has begun in Ukraine. All the ingredients are there: negotiations, digital offensives, and attempts at destabilization through disinformation.

The fear of global cyberattacks remains, and we must expect a diversification of both attacks (ransomware, DDoS) and targets.

Indeed, states do not hesitate to use cyber weapons. This was the case with the NotPetya software, which paralyzed an entire country.

This type of threat could easily spread and sow chaos within public organizations (health services, water, civilian assets), government infrastructure, private companies, and critical infrastructure, effectively paralyzing nations.

  • Companies in telecommunications and Internet infrastructure can be targeted.
  • The European Central Bank was, in fact, the first to warn of an imminent risk of attack on financial institutions.
  • The United States has reported experiencing reconnaissance attacks on its energy sector and attributes these offensives to the Russian state.
  • Manipulation and destabilization constitute another threat known as disinformation. While there may be no direct victims, the threat is insidious. Numerous false bomb threats are currently raging in Ukraine, sowing chaos and fear. False information is circulating, fostering doubt. Propaganda is a weapon.

Cyber actions

Ukraine is preparing for all eventualities, just as wiping its servers, transferring sensitive data out of Kyiv, and immediately cutting off access to compromised accounts. The United States and Europe have sent cyber experts to help Ukraine modernize its IT systems. However, as the threat has intensified, these teams have had to relocate and are now only reachable remotely, which would become complicated in the event of a cyberattack.

The Ukrainian government reportedly even called on the country's own cyberattackers to defend against potential threats and to prioritize cyber espionage. This request resonated, as messages of support quickly appeared on dark web hacker forums.

The war is also being fought on the front of disinformation. By producing numerous fake news stories, Russia is attempting to justify its military actions.

There is no shortage of examples, including the accusation that Ukraine is committing acts of aggression against the Donbas, or that Ukrainian and Polish soldiers attacked chemical plants.

In response to these attacks, Ukrainian "fact-checker" activists, with the support of journalists on the ground and Bellingcat, are doing everything possible to prove these accusations are inaccurate.

The hacker collective Anonymous has also followed suit by taking down several Russian government websites (Russia Today, RT.com).

What about France?

France remains " privileged " in certain respects; indeed, we are less dependent on gas due to our nuclear energy production and our collaboration with Norway. As for wheat, here again, we have high cereal production on French soil, shielding us from a potential shortage.

Regarding the risk of cyberattacks, France is just as exposed as other countries; therefore, the ANSSI has issued a statement calling for vigilance. It warns of potential effects in cyberspace and asks every company to strengthen its cybersecurity measures. The same applies to institutions and critical infrastructure operators (OIVs).

It also mentions small and medium-sized businesses, which are not immune to being targeted by attackers.

As a reminder, here are some links regarding digital hygiene:

https://www.ssi.gouv.fr/uploads/2017/01/guide_hygiene_informatique_anssi.pdf

https://www.ssi.gouv.fr/entreprise/bonnes-pratiques/

A potential cyber response in France is being considered by the French government, which has implemented measures and is asking all its institutions to increase their level of vigilance.

The ANSSI is on the front line; it has issued an alert bulletin, which we shared in a previous article.

French prefects have also been mobilized. President Macron has instructed them to remain at their posts and has mandated that "all mobilized and mobilizable services must be available."

Digital risk can affect any institution: town halls, regional bodies, and local authorities, as well as large corporations—either directly or indirectly through supply chain attacks. SMEs are also at risk.

In addition to these measures, cabinet meetings are being held in rapid succession, both in France and across Europe.

France and Europe must prepare for attacks; cyber warfare is now a weapon like any other. While not new, it is currently being highlighted by the media. This clearly demonstrates the role the cyber world plays on the global stage.

How can you prepare?

More than ever, it is essential for companies to prepare for potential attacks by anticipating them as much as possible through an effective and tested Business Continuity Plan (BCP) and by strengthening their technological defenses. Companies will need to be extra vigilant regarding their partners and service providers, as attackers will target supply chains. As a reminder, many Ukrainian organizations are direct suppliers to Fortune 500 companies, and 35 CAC 40 groups have operations in Russia (TotalEnergies, Renault, Auchan, etc.).

We recommend:

  1. Following CERT-FR: https://www.cert.ssi.gouv.fr/
  2. Following the recommendations of ANSSI: https://www.ssi.gouv.fr/actualite/tensions-internationales-renforcement-de-la-vigilance-cyber/
  3. Updating all of your operating systems.
  4. Reminding your employees of the importance of cyber risks and encouraging them to report any unusual activity.

If you need support or have questions about your current security measures, please contact us.

Contact TEHTRIS

Continue reading
Blog
Contactez Tehtris
Nos équipes vous recontacteront au plus vite afin d'échanger sur vos challenges cyber et évaluer comment nous pouvons vous accompagner pour les adresser.
Tehtris EDR : conçu, développé et opéré en Europe
Voir nos preuves
Derniers articles
See all