Concerns With Russian Interference in our Cyber World are Still Evident

Yesterday, new research into Russian Malware revealed a better understanding of how Russia’s malware teams work. Much like the U.S., Russia has multiple teams that do not work together. This prevents one operation from giving away another one because these teams do not share their code. 

The teams are Potao Express, BlackEnergy, and Turla, which have infiltrated European government and military computers, as well as targeted groups across Ukraine, Russia, Georgia, and Belarus to harvest information. 

But in 2016, Russia seemed to have had more malicious intent in Ukraine when two days before Christmas their national grid operator was infected with Russian malware. This caused a wide-scale blackout, but it only lasted a single hour. This brought up the question of why Russia would plant this malware just to cause an hour-long blackout.

Newer information shows that their goal was for the malware to destroy systems that would have resulted in a power outage for weeks or months. Furthermore, they planned to damage important transmission systems when Ukraine tried to turn the power back on again.  

This type of cyber-warfare could start a dangerous precedent in other nations.

This may not seem like a big deal for us here in the U.S., but an interesting story I found might suggest otherwise. A new round of ransomware attacks has recently affected 10 hospitals across the U.S. and Australia and caused their systems to be paralyzed.

Other cities in Florida and Texas also recently experienced ransomware attacks, some of them giving into ransom demands, and LabCorp and Hancock Health were hit as well. 

With what Russia is capable of and how often I feel like I see talk about them in the news, I was surprised that a Google Trends search showed that search volume for Russian Hacking has been on a steady decline since the 2016 presidential election. Note, the spike in search volume on July 15, 2018 was caused by Russia being part of The World Cup finals, but search volume overall has gone down so much, I had to remove the time of the election from my date range to see a true trend, as it dwarfs the rest of the data.

There’s no way to confirm who is planting the malware across the U.S. right now, but with another huge election coming up, I think we’d be naïve to think that these attacks aren’t possibly of Russian origin, honing in their skills for more widespread destruction this round. Especially, with recent news stories of Putin saying jokingly that Russia will be trying to affect the 2020 presidential election. While this could just be a poorly timed remark, it surely doesn’t feel like it, and it seems some Twitter users agree.

Even though we can’t be sure right now if these occurrences are all connected, what we can be sure of is that Russia is a dangerous leader in the malware world, and cyber-warfare is very dangerous up-and-coming threat.