Inside Russia’s Laboratory of Cyber Operations — and Beyond
Jan 11, 2024
auto_awesome
Russian adversary VOODOO BEAR targets Ukrainian telecom provider Kyivstar, using it as a testing ground for cyber attacks. The hosts discuss the disruptive behavior and history of VOODOO BEAR, as well as the broader context of Russian intrusion operations. They explore the tactics and targets of the threat actor group Voodoo Bear, highlighting their involvement in destructive attacks on power infrastructure. The podcast also examines the impact of Russian cyber operations on the world stage and raises questions about the need for reassessment of security programs and partnerships.
The recent cyber attack on Ukraine's telecom provider, Kivestar, carried out by Russian military intelligence unit Voodoo Bear, exposes the ongoing conflict and the destructive techniques employed by the adversaries.
The podcast sheds light on the Russian intelligence structure and its three main organizations engaged in offensive cyber operations - FSB, SVR, and GRU - highlighting the tactics and trade craft of Voodoo Bear, a prominent threat actor associated with GRU.
The podcast episode discusses the recent cyber attack on Ukraine's telecom provider, Kivestar, carried out by a Russian military intelligence unit known as Voodoo Bear or Sand Worm. The attack resulted in the disruption of data services for millions of mobile and home internet subscribers in Ukraine. The episode explores the motivations behind the attack, which have been a part of the ongoing conflict between Russia and Ukraine. It also delves into the tactics and techniques used by Voodoo Bear, highlighting their history of targeting Ukraine and their involvement in previous disruptive attacks, such as the power outages in 2015 and 2016. The episode points out the significance of the attack on Kivestar and its potential connections to kinetic actions, suggesting a coordinated strategy by the attackers. It also mentions the presence of fake DIVA groups, such as Sultan's PEC, claiming responsibility for the attack. Overall, the episode provides insight into the evolving cyber threat landscape and the need for organizations to assess their defenses and understand the motives and techniques of Russian threat actors.
Understanding the Russian Intelligence Structure and Offensive Cyber Operations
The podcast episode provides an overview of the Russian intelligence structure and its involvement in offensive cyber operations. It discusses the three main organizations engaged in offensive cyber operations in Russia: the FSB, the SVR, and the GRU. The FSB is likened to a law enforcement and domestic intelligence agency with a focus on intelligence and counterintelligence within Russia. The SVR is associated with Cozy Bear and primarily targets diplomatic missions and collects intelligence for political purposes. The GRU, part of the military, engages in intelligence collection as well as disruptive and destructive operations. The episode highlights Voodoo Bear as a prominent threat actor associated with the GRU and explores their tactics and trade craft. It mentions their history of targeting Ukraine, including disruptive incidents in the power sector and their involvement in the Olympics and other incidents. The episode also touches on the use of fake DIV3 groups by Voodoo Bear to create deniability and confuse attribution. It concludes by discussing the motivations of Russian threat actors and their impact on geopolitical dynamics and industries.
Strategies for Defending Against Russian Adversaries
The podcast episode addresses the key considerations for organizations in defending against Russian adversaries. It emphasizes the need for continuous monitoring and assessment of the threat landscape, taking into account the industry, business size, and countries of operation. The episode highlights the importance of understanding strategic and immediate threats posed by Russian threat actors and their tactics, techniques, and procedures. It mentions the shift towards identity-based intrusions and the use of remote monitoring and management tools by threat actors to remain undetected. The episode suggests that organizations should regularly reassess their defenses and prioritize investments based on the intelligence gathered. It also acknowledges the broader impact of Russian cyber operations on geopolitical dynamics and advises organizations to assess their partnerships and prepare for potential ripple effects of attacks in their industries.
The Evolving Nature of Russian Cyber Threats and Implications for Global Security
The podcast episode explores the evolving nature of Russian cyber threats and their implications for global security. It discusses the historical context of Russian intelligence operations, highlighting the use of cyber operations as part of espionage, sabotage, and disruptive activities. The episode mentions several notable incidents linked to Russian threat actors, including the poisoning of Sergei Skripal and the SolarWinds supply chain attack. It highlights the targeted collection efforts of Russian threat actors, such as Cozy Bear and Fancy Bear, focusing on industries like energy and diplomatic missions. The episode emphasizes the need for organizations to constantly reassess their security posture in light of the changing threat landscape and the importance of understanding the motivations and tactics of Russian adversaries. It concludes by underscoring the significance of cyber operations in the broader context of politics, diplomacy, and military operations.
In mid-December 2023, an adversary CrowdStrike tracks as VOODOO BEAR targeted Ukrainian telecom provider Kyivstar, wreaking havoc and disrupting thousands of systems and assets.
The Russia-linked adversary has for years treated Ukraine as its “lab of offensive cyber operations”, testing attack techniques and demonstrating the destructive behavior it has become known for since it emerged in late 2010.
In this episode, Adam and Cristian dive into the details of the recent Kyivstar attack and how it aligns with VOODOO BEAR’s history of disruptive cyberattacks, both in Ukraine and around the world. They also pull back the curtain on the broad, complex history of Russian intrusion operations, shedding light on adversaries operating within the country and what has motivated them over the years.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode