ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

How the Russia-Ukraine conflict has impacted cyber-warfare

Malcolm Tuck at ESET UK explores the profound effect that war in Europe has had on cyber-warfare techniques

 

In 2022, an unprovoked and unjustified attack on Ukraine shocked the world, bringing devastating effects on the country and its population. One year in and the conflict has had a seismic impact on everything from energy prices to commodity shortfalls. It has also had a profound effect on cyber-warfare techniques.

 

Destructive tactics

The invasion drove a wedge between actors in the ransomware scene, dividing them into either supporters or opponents of the aggression. Whilst there has been no overall growth in detections, we have seen an increased use of ransomware as a destructive tactic over the past year.

 

Threat actors on both sides of the conflict have used ransomware variants to damage infrastructure and attack their adversaries’ organisations by effectively wiping their data by encrypting it with no intention of providing the decryption key.

 

One such example is the RansomBoggs attack that has targeted multiple Ukrainian organisations. Once it infiltrates the victim’s machine, RansomBoggs generates a random key and encrypts files using AES-256 in CBC mode, then appends the .chsch extension to the encrypted files. The key is then RSA encrypted and written to aes.bin.

 

Since the operators are not asking for money in exchange for data decryption, this is a case of file coder being used as a wiper. It has Sandworm – a particularly ruthless Russia-aligned APT group’s – fingerprints all over it. The attack was distributed from the victims’ domain controllers via a PowerShell script that was almost identical to the one used in both the CaddyWiper and Industroyer2 attacks in Ukraine previously.

 

Waving a flag

Of course, it wasn’t just organisations across Ukraine and Russia that were targeted with politically motivated insults and the loss of data. In October, a wiper called Azov Ransomware started spreading globally that overwrote 666-byte chunks of data at a time, with no chance of recovery. It backdoored most of the 64-bit executables it could find, increasing the risk of it being spread further.

 

In the ransom note, its creators criticised the lack of Western help for Ukraine and sent political messages asking the public to start protests. However, it is worth noting that as the malware did not target Russian organisations, it has the hallmarks of a false flag operation.

 

A ramping up of activity

In the last few months, activity appears to have ramped up. In November, several Ukrainian organisations were hit with the Somnia wiper that appears to have come from a group known as ‘From Russia with Love’. Supporting this view is an image dropped by Somnia’s first-stage executable, displaying the name of the group and the letter Z which has become used as a symbol of Russian aggression against its neighbour. Prestige ransomware has also been detected targeting logistics companies across Ukraine and Poland.

 

In potential retaliation, CryWiper was launched at several Russian governmental agencies and courts in December, destroying both systems and the data held within. This is only the second known destructive malware targeting Russia since the war broke out, though, with RURansom back in March 2022 being the first.

 

Tensions are building

The Russian invasion of Ukraine has no doubt unleashed the destructive use of ransomware more than at any conflict previously. Threat actors on both sides are using ransomware to effectively cripple government and organisation infrastructure in large numbers.

 

Whilst it has been one year since the conflict began, we only expect the already saturated ransomware scene to become even more feisty and competitive. Tensions are clearly building between individual ransomware gangs due to their ideological differences and disagreements.

 

Politics have penetrated the cyber-underworld more than ever before. We are surely set to feel the aftershocks of this in targeted, retaliatory attacks in the months to come. All we can hope as an industry is that these clashes lead to threat actors losing their focus and making mistakes that can be leveraged to create decryptors or even their arrest and prosecution.

 


 

Malcolm Tuck is the Managing Director at ESET UK

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543