A country can be invaded through its borders and attacked through its login screens at the same time.
That is one of the defining realities of Russia’s war of aggression against Ukraine. Since launching its full-scale invasion on February 24, 2022, Russia has attacked Ukrainian cities with missiles, drones, artillery, aircraft, and ground forces. At the same time, Russian military and intelligence-linked operators have targeted Ukrainian government systems, energy companies, telecom networks, military personnel, logistics providers, satellite communications, and ordinary users.
The cyber campaign did not begin in 2022. Russia had already spent years turning Ukraine into a testing ground for some of the most aggressive cyber operations ever observed in the wild. Ukrainian power grids went offline. Government systems were wiped. A poisoned software update triggered a global corporate disaster. Political institutions, media organizations, banks, transportation systems, and telecommunications providers were repeatedly targeted.
But the biggest surprise of the war is not that Russia used cyber weapons.
It is that Ukraine remained online.
Government services continued functioning. Banks kept processing payments. Engineers restored damaged networks. Mobile operators rerouted traffic. Cybersecurity teams analyzed malware while missiles were falling. Critical data was moved out of vulnerable server rooms and into distributed cloud environments. Developers, system administrators, private companies, foreign governments, and volunteers became part of a national resilience system assembled under extraordinary pressure.
Ukraine has suffered serious failures and painful disruptions. The country was not perfectly prepared, and it is not invulnerable. No honest account should pretend otherwise.
What Ukraine has demonstrated is more useful than perfection: a modern state can absorb sustained cyberattack, learn faster than its attacker expects, and continue operating.
That lesson matters far beyond Ukraine.
Cyber war is not just hackers attacking computers
The phrase “cyber warfare” tends to produce ridiculous mental images. Hooded hackers. Green text. A dramatic countdown. Someone typing fast enough to defeat an entire intelligence service before lunch.
Real cyber operations are usually less cinematic and much more methodical.
A wartime intrusion may begin with a reused password, an unpatched VPN appliance, a malicious archive, a compromised router, or a message from what appears to be a trusted colleague. The attacker may then spend days or months collecting credentials, mapping the network, reading email, searching file shares, and identifying systems whose failure would create the most useful disruption.
That activity can serve several different objectives:
- Espionage against government, military, diplomatic, or industrial targets
- Theft of military plans, personnel records, logistics data, or technical documents
- Credential theft and long-term access to cloud services
- Destruction of workstations and servers with wiper malware
- Disruption of telecommunications and satellite connectivity
- Attacks against electricity generation, transmission, and distribution systems
- DDoS attacks that make websites or public services temporarily unavailable
- Website defacement and psychological operations
- Hack-and-leak campaigns involving stolen or manipulated data
- Supply-chain compromises that turn trusted software into an intrusion path
- Disinformation amplified through compromised accounts or fabricated personas
- Cybercriminal activity that supports, overlaps with, or simply exploits the war
A cyberattack does not need to blow up a building to have military value. If it delays a railway operator, disables a communications channel, exposes the location of military equipment, steals information about an aid shipment, or forces defenders to spend thousands of hours rebuilding systems, it has created friction.
Friction matters in war.
Russia’s cyber operations have been used to gather battlefield intelligence, create communications blackouts, disrupt public services, support psychological operations, and place additional pressure on a country already defending itself from physical invasion. A 2026 UK government profile of GRU cyber activity described Russian objectives in Ukraine as including battlefield advantage, combined cyber and military effects, psychological pressure, and technical capability development. (UK government)
Cyber warfare is therefore best understood as another operational layer. It sits beside electronic warfare, intelligence collection, propaganda, sabotage, missile attacks, drone warfare, and conventional military operations.
It does not replace any of them.
For Ukraine, the cyber war started long before 2022
Russia’s full-scale invasion began in February 2022, but its wider war against Ukraine began in 2014 with the occupation and illegal annexation of Crimea and Russian aggression in the Donbas.
The cyber component followed the same pattern: pressure, infiltration, experimentation, escalation.
On December 23, 2015, attackers disrupted electricity distribution in western Ukraine. Operators lost control of systems, substations were taken offline, and roughly 225,000 people lost power for periods ranging from one to six hours. The attackers had studied the environment, compromised business networks, stolen credentials, crossed into operational systems, interfered with control interfaces, and deployed destructive components to complicate recovery. (CISA)
This was not simply malware running on an office PC. It was an attack in which access to information technology systems was converted into a real-world electricity outage.
A second major power-grid attack followed in December 2016. The malware associated with that operation, known as Industroyer or CrashOverride, was designed to interact with industrial communication protocols used in electric power systems. Part of Kyiv lost power for more than an hour. UK authorities have attributed both the 2015 BlackEnergy operation and the 2016 Industroyer operation to GRU Unit 74455, commonly associated with the group known as Sandworm. (UK government)
These incidents taught Ukraine several harsh lessons before most countries had seriously considered the possibility of a state-backed digital attack producing an electricity outage.
They also gave Russian operators practical knowledge of Ukrainian infrastructure, institutions, administrative habits, software dependencies, and incident-response procedures.
Ukraine had become a live-fire cyber range.
NotPetya was not ransomware in any meaningful sense
If one incident captures the global danger of Russia’s cyber operations against Ukraine, it is NotPetya.
On June 27, 2017, organizations across Ukraine began experiencing what initially appeared to be a ransomware outbreak. Infected machines displayed a payment demand, and the malware borrowed visual and technical elements associated with earlier ransomware.
But calling NotPetya “ransomware” is misleading.
The payment and recovery process was functionally useless. The malware’s design made reliable restoration through payment impossible. Its real purpose was destruction.
The initial distribution was tied to the compromise of M.E.Doc, widely used Ukrainian accounting and tax software. A malicious update gave the operation access to a large number of Ukrainian organizations through a trusted supply-chain relationship. Once inside networks, NotPetya used several techniques to spread rapidly, including credential reuse and Windows networking mechanisms. Systems were rendered unbootable, operations stopped, and organizations were forced into large-scale recovery. (UK National Crime Agency)
Ukraine was the main target, particularly its government, financial, energy, transportation, and commercial sectors. The damage did not stay inside Ukraine.
Multinational companies with Ukrainian systems or business connections carried the infection into global networks. Shipping, pharmaceuticals, logistics, manufacturing, health care, and other industries experienced major disruption. The U.S. Department of Justice later said that three named victims alone suffered nearly USD 1 billion in losses. That figure is not a total estimate for every affected organization. It is a narrower, documented measure that demonstrates how quickly the damage accumulated. (U.S. Department of Justice)
The United States, United Kingdom, and other governments attributed NotPetya to Russia’s military intelligence service, specifically GRU Unit 74455. The UK assessed that the attack masqueraded as criminal activity but was principally intended to disrupt Ukraine. (UK government)
NotPetya should permanently kill the idea that destructive malware can be neatly contained by geography.
Modern companies share identity systems, VPNs, directory services, management tools, cloud tenants, suppliers, and software platforms across borders. Malware released against one country can move through those connections with machine speed. An operation intended to punish Ukraine became a worldwide business and public-safety incident.
That is the first great lesson of this cyber war: blast radius is not the same thing as target selection.
The invasion began with digital preparation
In the weeks before Russia’s full-scale invasion, Ukrainian banks, government services, and public websites experienced DDoS attacks, defacements, credential attacks, and destructive malware operations.
The UK assessed that the GRU was almost certainly involved in DDoS attacks against Ukraine’s financial sector on February 15 and 16, 2022. In January, the WhisperGate operation targeted Ukrainian organizations with malware that presented itself as ransomware while destroying data in a way that made recovery through payment impossible. (UK National Cyber Security Centre)
Then came a wave of wipers.
HermeticWiper, also called FoxBlade by Microsoft, appeared in Ukrainian networks on February 23, hours before the full-scale invasion. Other destructive families and components included HermeticRansom, IsaacWiper, CaddyWiper, DoubleZero, and platform-specific tools intended to damage Windows, Linux, or Solaris systems.
Not every attempt succeeded. Some affected only a limited number of organizations. Others were detected before achieving their intended impact. But taken together, the campaigns showed clear operational intent: steal information where possible, destroy systems where useful, create uncertainty, and force Ukrainian defenders to fight on yet another front. (ESET)
In April 2022, Ukrainian defenders and ESET disrupted an attempt to deploy Industroyer2 against a Ukrainian energy company. The operation involved malware capable of interacting with high-voltage substation equipment, accompanied by multiple wipers that appeared intended to damage the surrounding IT environment, delay recovery, and erase traces. (ESET)
This incident deserves attention precisely because it failed.
Cyber operations are often discussed only when they cause visible damage. That creates a distorted picture. Defenders may identify an intrusion, isolate systems, remove persistence, or interrupt execution minutes before the public would have noticed anything.
A prevented blackout does not generate the same headlines as an actual blackout. It may still represent one of the most important defensive victories of the war.
Viasat showed how cyberattacks can reach into space infrastructure
At approximately 3:02 a.m. UTC on February 24, 2022, the same morning Russia launched its full-scale invasion, the KA-SAT satellite broadband network experienced a deliberate cyberattack.
The satellite itself was not hacked or physically damaged. Instead, the attackers compromised the ground-based management environment supporting a consumer-oriented KA-SAT service partition.
According to Viasat, the attackers exploited a misconfiguration in a VPN appliance, reached a trusted management segment, moved laterally, and issued legitimate management commands to large numbers of modems. Key data in flash memory was overwritten, leaving the devices unable to connect until they were reset or replaced. Several thousand customers in Ukraine and tens of thousands elsewhere in Europe were affected. Viasat eventually shipped nearly 30,000 replacement modems to distributors. (Viasat)
Researchers at SentinelLabs identified AcidRain, a MIPS-based wiper designed to erase modems and routers, and Viasat later said the analysis of the destructive executable was consistent with its incident findings. The outage also interrupted remote monitoring and control connectivity for approximately 5,800 wind turbines in Germany, although the turbines themselves continued generating electricity. (SentinelOne)
The European Union, United States, and United Kingdom attributed the operation to Russia. The EU stated that it occurred roughly one hour before the invasion and facilitated Russia’s military aggression. (Council of the European Union)
It is important not to overstate what is publicly confirmed. Viasat reported that its directly managed government users on KA-SAT were not affected, and the precise battlefield consequences remain partly classified or otherwise unavailable. Claims about specific Ukrainian military units should therefore be treated cautiously.
What is confirmed is significant enough: Russia attacked satellite communications infrastructure at the opening of its invasion, disrupted users across multiple countries, and did so without destroying a satellite.
For developers and infrastructure engineers, the architecture is more important than the science-fiction imagery. The vulnerable point was not an object in orbit. It was the management plane on Earth.
That pattern appears again and again in cybersecurity. Attackers do not always defeat the strongest cryptography or most exotic hardware. They find an administrative interface, supplier account, edge device, VPN configuration, or trusted control channel that has more authority than it should.
The cyberattack that does not level a city can still help an army
Early discussion of the invasion sometimes asked why Russia had not produced a spectacular “cyber Pearl Harbor” that instantly switched off Ukraine.
That was the wrong expectation.
Cyber operations are rarely a reliable substitute for explosives. Access may disappear when software is patched. Malware can fail in an unfamiliar environment. Network diagrams may be outdated. Operators make mistakes. An intrusion that took six months to prepare may produce only a few hours of disruption.
Even a technically successful attack may not create a strategic effect.
A government website can be restored. Traffic can move to another provider. Administrators can rebuild systems from known-good images. Manual procedures can replace automation. A DDoS attack may generate frightening headlines while changing nothing on the battlefield.
Russia still relies overwhelmingly on physical violence to destroy Ukrainian infrastructure. Missiles, drones, artillery, sabotage, and occupation forces have caused devastation that cyber operations have not approached.
But this does not make cyber operations irrelevant.
Russia does not need malware to accomplish what a missile can do more reliably. Cyber operations are useful when they can quietly collect intelligence, expose military movement, disrupt a specific dependency, create an information vacuum, or impose costs without consuming a missile.
In 2025, the UK and nine partner countries exposed a GRU Unit 26165 campaign targeting organizations involved in delivering aid to Ukraine. The targets included logistics providers, defense companies, IT services, ports, airports, transportation systems, and air-traffic organizations. Russian operators also sought access to internet-connected cameras near border crossings and military installations, potentially allowing them to monitor aid movements. (UK National Cyber Security Centre)
That is what cyber support to conventional warfare looks like.
Not a single red button. A chain of small advantages.
Who is actually attacking Ukraine?
Threat-actor naming is one of the most confusing parts of cybersecurity.
The same organization can have a designation from CERT-UA, several vendor aliases, a military unit number, and different labels for separate operational clusters. Groups change infrastructure and malware. Researchers sometimes split or merge clusters as evidence develops.
A few names appear repeatedly in the Ukrainian conflict:
- Sandworm, also tracked by some vendors as APT44, Seashell Blizzard, Voodoo Bear, or FROZENBARENTS, is associated with GRU Unit 74455. It has been linked to the Ukrainian power-grid attacks, NotPetya, Industroyer2, destructive wipers, and the 2023 Kyivstar telecommunications attack.
- APT28, also known as Fancy Bear, Forest Blizzard, STRONTIUM, Sofacy, or the Sednit group, is associated with GRU Unit 26165. Its activity includes espionage, credential attacks, malware deployment, targeting of logistics networks, and operations against organizations supporting Ukraine.
- Gamaredon, tracked by CERT-UA as UAC-0010 and also known as Primitive Bear, Trident Ursa, or Aqua Blizzard, is associated by Ukrainian authorities with Russia’s FSB. It has conducted persistent espionage against Ukrainian government and defense organizations, frequently using phishing, messaging platforms, removable media, and rapidly changing infrastructure.
- Turla, also called Secret Blizzard, VENOMOUS BEAR, SUMMIT, or UAC-0194, is a long-running Russia-linked intelligence actor. In June 2026, Google described its STOCKSTAY backdoor, which had been used against Ukrainian government and military organizations.
- APT29, commonly called Midnight Blizzard or Cozy Bear, is associated with Russia’s SVR. Its operations are more often focused on strategic espionage against governments, diplomatic targets, think tanks, technology companies, and organizations across NATO countries than on destructive frontline attacks.
- NoName057(16), Killnet, and similar pro-Russian communities are better understood as hacktivist or cybercrime-style ecosystems, although relationships between such personas and Russian state interests vary considerably.
These categories matter.
A Russian-speaking ransomware operator is not automatically a GRU officer. A group attacking Ukraine for money is not necessarily receiving direct orders from the Kremlin. A Telegram channel claiming responsibility for an outage may be exaggerating, recycling someone else’s data, or taking credit for a routine technical failure.
At the same time, the gray zone is real. Microsoft reported in its 2025 Digital Defense Report that Russian state actors were increasingly outsourcing parts of operations, co-opting criminal infrastructure, and favoring commodity tools over distinctive custom capabilities. This can lower costs while making attribution more difficult. Microsoft’s dedicated Ukraine tracking found that Ukraine accounted for 25 percent of the Russian operations it observed, making it Russia’s primary cyber target. (Microsoft Digital Defense Report 2025)
Google has also documented how Russian intelligence services use genuine and fabricated hacktivist personas to publish stolen information, amplify narratives, and blur the boundary between espionage and influence operations. Not every pro-Russian group is state-controlled, but some allegedly independent personas have functioned as fronts for state activity. (Google Threat Intelligence)
Attribution is evidence, not magic
Cyber attribution is rarely based on a single IP address or a filename written in Russian.
Serious attribution may combine:
- Malware code and development history
- Reused infrastructure or certificates
- Command-and-control patterns
- Working hours and operational timing
- Target selection and victimology
- Phishing themes and language
- Previously compromised accounts
- Tactics observed across multiple incidents
- Intelligence unavailable to private researchers
- Legal evidence, warrants, sanctions, or indictments
- Mistakes made by operators
Confidence levels matter. “Almost certainly,” “high confidence,” and “medium confidence” are not interchangeable. Government attribution may include classified intelligence that cannot be published. Vendor attribution may have excellent technical visibility but lack the human intelligence necessary to connect operators to a specific agency.
Credible analysis should be comfortable saying “we do not know.”
It should also recognize when separate governments, incident responders, intelligence agencies, and security companies reach compatible conclusions from different evidence. That is what happened with many major GRU operations, including NotPetya and the KA-SAT attack.
Uncertainty is not the same thing as innocence.
The war has shifted toward identities, endpoints, and quiet espionage
The most visible early phase of the full-scale invasion featured DDoS attacks, defacements, and wipers. Those operations never disappeared, but the conflict increasingly emphasized espionage, credential theft, endpoint compromise, and persistent access.
That shift is logical.
Destroyed systems tell the attacker nothing after they are gone. A working mailbox, military laptop, Signal account, router, or cloud identity can keep producing intelligence.
In February 2025, Google reported increasing attempts by several Russia-aligned actors to compromise Signal accounts used by military personnel, politicians, journalists, activists, and other intelligence targets. Some campaigns tried to trick users into linking an attacker-controlled device to the victim’s Signal account, allowing messages to be received without breaking Signal’s encryption. (Google Threat Intelligence)
That distinction is critical.
End-to-end encryption protects messages while they travel between trusted endpoints. It cannot save you if an attacker persuades the service that the attacker’s device is one of those endpoints.
Similarly, Microsoft exposed Void Blizzard, a Russia-affiliated actor that relied heavily on password spraying and stolen credentials rather than technically exotic exploits. The group compromised organizations in Ukrainian education, transportation, aviation, and defense-related sectors. (Microsoft Security)
In 2025, CERT-UA processed 5,927 cyber incidents, 37 percent more than in 2024. Phishing incidents more than doubled, from 843 to 1,727. Local governments, central government organizations, the security and defense sector, energy companies, IT providers, and health care organizations all remained targets. (SSSCIP)
Gamaredon remained especially active. Ukrainian reporting for the first half of 2025 identified 164 incidents associated with UAC-0010, with email and infected USB media serving as major initial-access vectors. (SSSCIP)
By 2026, the same emphasis on stealing authentication material had reached basic network infrastructure. In April, the UK’s National Cyber Security Centre reported that APT28 had been exploiting vulnerable routers, altering DHCP and DNS settings, and redirecting selected traffic through attacker-controlled systems. That created opportunities for adversary-in-the-middle attacks against passwords and OAuth tokens. Some of the routers investigated were located in Ukraine. (UK National Cyber Security Centre)
Also in 2026, Google documented Turla’s STOCKSTAY backdoor, deployed against Ukrainian military and government organizations. Researchers said the malware had been under continued development since at least December 2022, illustrating the long timelines behind strategic espionage. (Google Threat Intelligence)
The modern Russian cyber campaign is therefore not defined by one superweapon. It is a continuous production line of phishing, credential theft, malware delivery, edge-device compromise, exploitation of known vulnerabilities, data collection, and influence activity.
Often, the simplest technique that works is the one that gets used.
Ukraine did not remain online by accident
Ukraine’s resilience is sometimes described as if the country simply got lucky or Russia proved less capable than expected.
Neither explanation is sufficient.
Ukraine had years of painful experience before 2022. Its defenders had already investigated power-grid intrusions, destructive malware, government compromises, and supply-chain attacks. CERT-UA, the State Service of Special Communications and Information Protection, the Security Service of Ukraine, military cyber units, critical-infrastructure operators, and private incident responders had been forced to develop real operational knowledge.
That preparation was strengthened by international assistance.
Before the full-scale invasion, Ukraine invited a U.S. Cyber Command hunt-forward team to work alongside Ukrainian specialists on selected networks. Cyber Command described it as its largest hunt-forward deployment at the time. The joint work helped Ukrainian defenders find and address malicious activity before Russia’s invasion. (U.S. Cyber Command)
After the invasion, cooperation expanded through real-time intelligence sharing, malware analysis, security tooling, training, infrastructure assistance, and incident response. CISA and Ukraine’s SSSCIP signed a cooperation agreement covering incident information, critical-infrastructure security, training, and exercises. The UK expanded its Ukraine Cyber Programme. European institutions, NATO members, and private companies provided additional support. (CISA)
Private-sector visibility proved unusually important. Microsoft, Google, ESET, Mandiant, Cisco, Amazon Web Services, Cloudflare, telecommunications companies, satellite providers, and many smaller organizations could see different portions of the attack surface.
No single company or government had the complete picture. Together, they could detect more.
Moving the government to the cloud became a form of evacuation
Before the invasion, many Ukrainian government workloads depended on servers physically located inside Ukraine. That created an obvious wartime risk.
A server can be well patched and still lose an argument with a cruise missile.
Ukraine amended legal restrictions shortly before the invasion so government data could be moved into public cloud environments outside the country. Microsoft reported that, within ten weeks, critical workloads from ministries, state agencies, and state-owned enterprises had been transferred into distributed European data centers. (Microsoft)
This was not merely an IT modernization project. It was the digital equivalent of moving archives, command functions, and essential administrative capacity away from the front.
Cloud migration did not make Ukraine magically secure. Misconfigured cloud identities, stolen tokens, malicious OAuth applications, weak administrative roles, and compromised endpoints remain dangerous. Russian intelligence actors have adapted to cloud environments and increasingly target identities rather than physical servers. (UK National Cyber Security Centre)
What the cloud provided was resilience against certain failure modes:
- A destroyed government building did not have to mean destroyed government data.
- Workloads could run across infrastructure beyond the reach of Russian ground forces.
- Security providers could apply telemetry and threat intelligence at scale.
- Services could be restored without waiting for replacement hardware in a war zone.
- Administrators could separate public availability from a single physical location.
The deeper lesson is not “put everything in the cloud.”
It is “do not let one building, administrator, provider, region, credential, or management plane become the country’s single point of failure.”
Resilience does not mean Ukraine never gets hurt
Ukraine’s success should not be turned into a superhero story.
On December 12, 2023, a major cyberattack disrupted Kyivstar, Ukraine’s largest mobile operator. Essential services were blocked, connectivity failed, and users were pushed toward Wi-Fi and alternative providers. The company served roughly 24 million customers. Ukrainian authorities later linked the operation to Sandworm and GRU Unit 74455. (SSSCIP)
The incident was strategically meaningful. Telecommunications are not an abstract IT service during war. People use mobile networks to receive air-raid warnings, contact relatives, coordinate emergency response, access banking, and maintain everyday life.
A major attack against Ukrainian Ministry of Justice registries in December 2024 produced another serious disruption. Ukrainian reporting said the incident affected key government services, border and customs processes, and systems used by a large portion of the population. The government’s own review concluded that the incident exposed weaknesses in backup strategies and the dependence of public services on centralized digital infrastructure. (SSSCIP)
Acknowledging these incidents does not weaken the case for Ukraine’s resilience. It strengthens it.
Resilience is not the absence of failure. It is the ability to continue functioning, restore service, investigate honestly, and redesign the system so the same failure is harder to repeat.
The civilian cyber front is part of everyday survival
Ukraine’s cyber defense is not limited to intelligence officers sitting in secure facilities.
It includes the developer maintaining a government API during an air raid. The telecom engineer restoring a damaged link. The hospital administrator switching to offline procedures. The cloud architect moving a workload out of a threatened data center. The security analyst triaging phishing messages sent to military families. The small-business owner providing public Wi-Fi after a mobile outage.
Power cuts and internet disruptions forced Ukrainian companies and households to become practical infrastructure planners. Backup batteries, generators, multiple SIM cards, satellite terminals, cached documents, offline authentication options, mirrored services, and alternative communication channels stopped being “business continuity features.” They became survival tools.
Ukrainian civilians also participated more directly through volunteer technology communities and the IT Army of Ukraine. Activities associated with these communities have included DDoS campaigns, intelligence gathering, propaganda disruption, data analysis, website attacks, and the development of tools supporting the wider defense effort. Academic studies describe the IT Army as a novel, crowdsourced cyber auxiliary, but research also suggests that its impact has sometimes been overstated and that many volunteer operations produced temporary disruption rather than strategic effects. (Journal of Strategic Security)
That is an important correction.
A large Telegram channel is not a military cyber command. A successful DDoS attack is not equivalent to persistent access inside a defense ministry. Claims made by anonymous participants should not be treated like verified incident reports.
Still, civilian participation has changed the character of the conflict. Skills once considered narrowly technical became part of national defense. Developers and administrators discovered that architecture, authentication, availability, data integrity, and incident response can have consequences far outside the IT department.
Hacktivism has created a messy legal and operational gray zone
Both pro-Ukrainian and pro-Russian hacktivists have participated in the conflict.
Typical activity includes:
- DDoS attacks
- Website defacement
- Doxxing
- Publication of stolen databases
- Claims of infrastructure disruption
- Propaganda distribution
- Account takeover
- Hack-and-leak operations
- Automated attack participation through downloadable tools
Some groups are genuine activists. Some are criminals looking for attention. Some mix ideological and financial motives. Others may be influenced, tolerated, supported, tasked, or secretly operated by state services.
In July 2025, Europol coordinated Operation Eastwood against NoName057(16), a pro-Russian network known for DDoS attacks against Ukraine and countries supporting it. Authorities disrupted more than 100 computer systems, issued arrest warrants, and contacted more than 1,000 supporters. Europol described many participants as Russian-speaking sympathizers using automated tools in exchange for ideological rewards or incentives, rather than highly skilled government operators. (Europol)
Yet pro-Russian hacktivist activity remains a security concern. The UK warned in 2026 that groups such as NoName057(16) continued targeting government and critical-infrastructure organizations, often through DDoS operations coordinated on Telegram. (UK National Cyber Security Centre)
The distinction between hacktivism, crime, intelligence activity, and military operations is not pedantic. It affects attribution, legal responsibility, escalation, intelligence analysis, and defensive priorities.
A criminal botnet rented for a patriotic campaign does not become a formal Russian military unit. A fabricated hacktivist persona operated by intelligence officers is not independent simply because it has a Telegram logo.
The internet allows all of these actors to occupy the same space, sometimes using the same hosting providers, malware loaders, leaked credentials, and attack tools.
That ambiguity is useful to Russia. It offers noise, deniability, and disposable intermediaries.
Why this matters to the rest of Europe
Ukraine is the primary target, but the attack surface has always extended beyond Ukraine.
NotPetya disrupted companies around the world. KA-SAT affected users across Europe. GRU operators have targeted logistics organizations, transportation systems, defense suppliers, ports, airports, technology companies, and internet-connected cameras connected to the flow of aid.
Microsoft’s 2025 data found that every country outside Ukraine in its top ten list for Russian cyber activity was a NATO member. The company also observed growing interest in smaller businesses that could serve as lower-security pathways into larger organizations. (Microsoft Digital Defense Report 2025)
European security depends on interconnected systems:
- Cross-border energy networks
- Telecommunications providers
- Cloud platforms
- Rail and port logistics
- Satellite services
- Financial systems
- Defense contractors
- Software vendors
- Government identity platforms
- Elections and political institutions
Russia does not need to attack all of these systems at once. It can choose a supplier, an overlooked router, an administrator’s personal device, or a small contractor with trusted access.
Ukraine is not only defending Ukrainian networks. It is collecting operational experience against tools and methods that can be redirected toward Poland, Germany, the Baltic states, the United Kingdom, the United States, or any country helping Ukraine resist Russian aggression.
Europe should treat that experience as an early warning, not as a distant regional case study.
What developers and defenders should actually learn
The war has produced more cybersecurity lessons than any generic checklist can capture. A few deserve special attention.
Assume credentials will be stolen
Russian groups repeatedly use phishing, password spraying, malicious login pages, token theft, compromised accounts, and adversary-in-the-middle techniques.
MFA remains essential, but not every MFA method is equal. SMS codes and easily approved push notifications are weaker than phishing-resistant passkeys or hardware-backed security keys. Session tokens, OAuth grants, device enrollment, recovery workflows, and linked messaging devices need monitoring too.
An attacker who cannot break your encryption may simply try to become an authorized endpoint.
Treat network equipment as computers
Routers, firewalls, VPN concentrators, hypervisors, remote-management appliances, and satellite modem platforms are not plumbing. They are privileged computers.
The KA-SAT operation exploited the management environment. APT28’s 2024 to 2026 activity manipulated DNS through compromised routers. These devices often receive less monitoring than laptops while controlling far more important traffic. (Viasat)
Keep management interfaces away from the public internet. Patch supported firmware. Replace end-of-life devices. Centralize logs. Back up configurations. Monitor DNS and DHCP changes. Know which administrators can modify the control plane.
Segment systems according to failure impact
The 2015 power-grid attack demonstrated the danger of pathways from business networks into operational environments. Industroyer2 showed that attackers continued trying to reach industrial systems years later.
Segmentation is not drawing colorful VLAN boxes in a diagram. It means enforcing boundaries, minimizing trust, monitoring administrative paths, and making sure one stolen account cannot move from office email to safety-critical control systems.
Build recovery before you need it
A backup that has never been restored is a theory.
NotPetya, the wiper campaigns, the Kyivstar disruption, and the attack on Ukrainian government registries all demonstrate that defenders need more than copies of data. They need known-good infrastructure configurations, isolated or immutable backups, replacement hardware plans, offline credentials, documented dependencies, and authority to rebuild quickly.
Recovery objectives should reflect real operational priorities. During war, the most important service may not be the most profitable or technically impressive one.
Design for degraded operation
Ukraine has repeatedly maintained services through network outages, physical destruction, power cuts, and cyberattacks.
Systems should fail in controlled ways. Critical information may need offline access. Public services may require low-bandwidth modes. Operators may need manual fallback procedures. Administrative access must remain available during DDoS attacks. Multiple providers should be used where the risk justifies the cost.
High availability is not only about keeping every feature online. Sometimes it means preserving the one function people actually need.
Protect the supply chain as part of your own network
NotPetya entered through trusted Ukrainian software. Ukraine’s later reporting found attackers increasingly targeting suppliers and specialized software developers as direct attacks against hardened critical infrastructure became more difficult. (SSSCIP)
Organizations should know what their software can update, which identities those updates use, whether packages are signed, how build systems are protected, and what happens if a trusted vendor is compromised.
“Third party” does not mean “someone else’s risk.”
Log what will matter during the worst week of your company’s life
Authentication events, privilege changes, remote-management activity, OAuth consent, endpoint alerts, DNS configuration changes, software deployment, and administrative actions need sufficient retention and central visibility.
Attackers destroy logs because logs are useful.
Ukraine’s experience also shows the value of EDR and active threat hunting. Signature-based antivirus alone is not enough against operators using built-in tools, legitimate services, stolen credentials, and constantly changing infrastructure.
Practice incident response as an organizational function
A destructive incident cannot be solved by the security team alone.
Legal staff, communications teams, executives, developers, cloud engineers, identity administrators, physical-security personnel, vendors, and government contacts all become part of the response.
Decide in advance who can isolate a network, disable an identity provider, switch providers, take a public service offline, restore from backup, contact national authorities, or communicate with customers.
During an actual emergency, ambiguity becomes downtime.
Ukraine’s advantage is not invulnerability. It is adaptation.
It would be careless to call Ukraine the best cybersecurity country in the world. There is no meaningful scoreboard for that, and Ukraine still has legacy systems, uneven security maturity, resource constraints, administrative problems, and vulnerable organizations.
Its real advantage is more specific.
Ukraine has spent more than a decade defending against a determined state adversary under increasingly realistic conditions. Since 2022, it has done so while its territory was occupied, infrastructure was physically destroyed, personnel were displaced, and military operations consumed national resources.
Ukrainian defenders have learned that expensive security products do not compensate for weak architecture. They have learned that a government can lose buildings without losing all of its digital state. They have learned that intelligence sharing has to move at operational speed. They have learned that recovery can be as strategically valuable as prevention.
Most importantly, they have learned to assume failure.
Networks will be penetrated. Credentials will be stolen. Providers will go offline. Malware will execute. A data center may become unreachable. A supplier may be compromised. An employee will click something convincing.
The question is whether one failure becomes national paralysis.
Ukraine has repeatedly answered: not necessarily.
The invisible front is still a human front
It is easy to discuss this war in terms of malware families, threat clusters, unit numbers, and incident counts.
Behind those abstractions are people.
A telecommunications outage means someone cannot reach a relative after an air raid. A compromised military account may expose personnel to physical danger. A damaged government registry can delay documents, property transactions, customs processing, or access to public services. An energy-sector intrusion means engineers working to keep heat and electricity available while Russia is physically attacking the grid.
Ukraine did not choose this war. Russia launched the full-scale invasion and remains the aggressor. Ukraine is defending its territory, its population, its sovereignty, and its right to exist as an independent democratic state.
That reality should not be blurred by the technical complexity of attribution or the messy participation of hacktivists and criminals.
Russia has used cyber operations as part of a broader campaign of aggression. Ukraine has responded not only by blocking attacks, but by changing how a modern country organizes digital resilience.
The rest of the world should pay attention.
Cybersecurity is no longer an internal IT concern to be reviewed once a year by an audit committee. It is connected to energy security, military logistics, telecommunications, public trust, health care, transportation, diplomacy, and the basic continuity of government.
Russia’s war has also exposed the limitations of offensive cyber power. Malware is not magic. Access expires. Systems can be restored. Defenders learn. Private companies can see attacks that governments miss. International cooperation can disrupt operations before their intended effect appears.
But limitation is not insignificance.
Cyber operations do not need to win a war on their own. They only need to make the victim slower, less informed, less connected, and more afraid.
Ukraine’s achievement is that Russia has repeatedly tried to produce those effects, and Ukraine has continued to function.
The next major conflict may not begin with a missile launch alone. Some parts of it may already be happening inside email accounts, software supply chains, routers, cloud tenants, telecom management systems, and forgotten administrative interfaces.
Ukraine is showing the world what defending against that future looks like.
Sources and further reading
- CERT-UA: Cyber incidents processed in 2025
- SSSCIP: 2025 Cyber Threat Report
- SSSCIP: War and Cyber, Three Years of Struggle and Lessons
- UK NCSC: Profile of GRU cyber and hybrid threat operations
- CISA: Russian state-sponsored cyber threats to critical infrastructure
- U.S. Department of Justice: GRU officers charged over destructive malware operations
- UK government attribution of NotPetya
- Viasat: KA-SAT cyberattack overview
- SentinelLabs: AcidRain modem wiper analysis
- Council of the European Union: Attribution of the KA-SAT attack to Russia
- ESET: Industroyer2 analysis
- ESET: A year of wiper attacks in Ukraine
- Microsoft: Defending Ukraine, Early Lessons from the Cyber War
- Microsoft Digital Defense Report 2025
- Google Threat Intelligence: Russia-aligned targeting of Signal
- Google Threat Intelligence: Turla’s STOCKSTAY backdoor
- UK NCSC: APT28 router exploitation and DNS hijacking
- UK NCSC: GRU targeting of Western logistics organizations
- U.S. Cyber Command: Hunt-forward operations in Ukraine
- Europol: Operation Eastwood against NoName057(16)
Top comments (0)