{"id":18072,"date":"2022-02-02T10:49:14","date_gmt":"2022-02-02T18:49:14","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/02\/02\/news-11805\/"},"modified":"2022-02-02T10:49:14","modified_gmt":"2022-02-02T18:49:14","slug":"news-11805","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/02\/02\/news-11805\/","title":{"rendered":"Will World War III begin in cyberspace?"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.techhive.com\/images\/article\/2015\/01\/cyberwar-thinkstock-100563260-primary.idge.jpg?auto=webp&amp;quality=85,70\"\/><\/p>\n<p><strong>Credit to Author: Steven J. Vaughan-Nichols| Date: Tue, 25 Jan 2022 03:00:00 -0800<\/strong><\/p>\n<p>People die because of cyber wars, even if no bullets are ever fired. Instead, they die in emergency rooms that no longer have power, from broken medical communication networks, and from riots. All of this has happened before. It will happen again. And now, with <a href=\"https:\/\/www.cnn.com\/videos\/world\/2022\/01\/19\/russia-ukraine-intel-tension-border-chance-pkg-vpx.cnn\" rel=\"noopener nofollow\" target=\"_blank\">Russia poised to invade Ukraine<\/a> and Russian cyberattacks already in motion, we can only hope and pray that what promises to be the first major European war since World War II doesn&#8217;t spark the next World War.<\/p>\n<p>If it does, I fear the proximate cause won&#8217;t be Russian T-90 main battle tanks trying to smash their way into Ukraine&#8217;s capital, Kyiv. It will be the Russian GRU Sandworm hacking group launching a cyberattack that perhaps wrecks the European Union power grid; or knocks out major US internet sites such as Google, Facebook, and Microsoft; or stops 4G and 5G cellular services in their tracks.<\/p>\n<p>Sound like something out of a modern-day Tom Clancy novel? I wish. This is all too real.<\/p>\n<p>Last week, the <a href=\"https:\/\/www.cisa.gov\/\" rel=\"noopener nofollow\" target=\"_blank\">US Cybersecurity and Infrastructure Security Agency (CISA<\/a>) gave notice that critical infrastructure operators should take <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/publications\/CISA_Insights-Implement_Cybersecurity_Measures_Now_to_Protect_Against_Critical_Threats_508C.pdf\" rel=\"noopener nofollow\" target=\"_blank\">&#8220;urgent, near-term steps&#8221; against cyber threats<\/a>. It&#8217;s not so much a fear that Russia will target US or UK technology resources as it is that in the past, when Russia has gone after Ukraine&#8217;s IT infrastructure, the attacks hit the West, as well.<\/p>\n<p>Malware doesn&#8217;t care about borders. Past malware such as <a href=\"https:\/\/www.csoonline.com\/article\/3233210\/petya-ransomware-and-notpetya-malware-what-you-need-to-know-now.html\" rel=\"noopener\" target=\"_blank\">NotPetya<\/a> and <a href=\"https:\/\/www.computerworld.com\/article\/3196673\/faq-are-you-in-danger-from-the-wannacrypt-ransomware.html\">WannaCry<\/a> began as nation-state attackware then quickly went well beyond their original targets. To this day, they&#8217;re still causing trouble.<\/p>\n<p>The Russian cyberattack on Ukraine has already begun. On Jan. 14, a massive website attack smeared <a href=\"https:\/\/www.reuters.com\/world\/europe\/exclusive-hackers-likely-used-software-administration-rights-third-party-hit-2022-01-14\/\" rel=\"noopener nofollow\" target=\"_blank\">Ukrainian government websites<\/a> with a warning to &#8220;<a href=\"https:\/\/www.reuters.com\/world\/europe\/expect-worst-ukraine-hit-by-cyberattack-russia-moves-more-troops-2022-01-14\/\" rel=\"noopener nofollow\" target=\"_blank\">be afraid and expect the worst<\/a>.&#8221;<\/p>\n<p>That caught headlines, but it was purely a psychological attack.<\/p>\n<p>The real attack, Microsoft revealed, was that <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2022\/01\/15\/destructive-malware-targeting-ukrainian-organizations\/\" rel=\"noopener nofollow\" target=\"_blank\">destructive malware had been injected into multiple Ukrainian government organizations<\/a> on Jan. 13. The <a href=\"https:\/\/www.microsoft.com\/security\/blog\/microsoft-security-intelligence\/\" rel=\"noopener nofollow\" target=\"_blank\">Microsoft Threat Intelligence Center (MSTIC)<\/a> reports that these programs masquerade as ransomware but they&#8217;re purely destructive and designed to ruin computers and devices rather than extort a ransom. Microsoft also warns that these programs are only the malware they&#8217;ve <em>detected<\/em>. There are almost certainly others not yet discovered.<\/p>\n<p>Russia has made such attacks (and others) before on Ukraine. Indeed, in 2016, <a href=\"https:\/\/www.computerworld.com\/article\/3039772\/ukraine-power-cyberattack-russia-itbwcw.html\">Russia turned off Kyiv&#8217;s power supply<\/a>. It&#8217;s a lead-pipe cinch they&#8217;ll try again.<\/p>\n<p>When \u2014 not if \u2014 they do, these attacks may well hit targets Russia never meant to smack.<\/p>\n<p>Or maybe Russia <em>will<\/em> want to attack Western infrastructure. Unlike the Trump Administration that kowtowed to Russian President Vladimir Putin, US President Joe Biden is pushing back against Russia&#8217;s aggression. And he&#8217;s not alone. The other NATO powers are also telling Putin that enough is enough.<\/p>\n<p>While I doubt this means we&#8217;ll see the 82nd Airborne deploying along the Dnieper River, cyberattacks are another matter entirely. After all, as President Biden said in his Jan. 19 news conference, the <a href=\"https:\/\/www.politico.com\/news\/2021\/06\/16\/biden-putin-russia-cyberattacks-494888\" rel=\"noopener nofollow\" target=\"_blank\">US could respond to future Russian cyberattacks<\/a> against Ukraine with its own cyberwar resources. In a &#8220;hack-for-hack&#8221; world, the internet we know and use every day isn&#8217;t likely to hold up for long.\u00a0<\/p>\n<p><a href=\"https:\/\/www.nytimes.com\/2021\/10\/25\/us\/politics\/russia-cybersurveillance-biden.html\" rel=\"noopener nofollow\" target=\"_blank\">Russia has already been attacking the US on the internet<\/a>. These attacks tend not to be noticed since they blur into American politics. There&#8217;s often little difference between a social network message from a rabid, but sincere, Trump supporter and one from a <a href=\"https:\/\/www.pnas.org\/content\/117\/1\/243\" rel=\"noopener nofollow\" target=\"_blank\">Russian (Internet Research Agency) IRA<\/a> troll factory.\u00a0<\/p>\n<p>But what we&#8217;re facing now is an entirely different level of cyber warfare. It&#8217;s also one that Russia&#8217;s been doing for quite some time. In the last few decades, besides Ukraine, <a href=\"https:\/\/www.bbc.com\/news\/39655415\" rel=\"noopener nofollow\" target=\"_blank\">Russia has attacked Estonia<\/a> and <a href=\"https:\/\/www.nytimes.com\/2008\/08\/13\/technology\/13cyber.html\" rel=\"noopener nofollow\" target=\"_blank\">Georgia<\/a>.<\/p>\n<p>More recently, <a href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2021\/10\/07\/digital-defense-report-2021\/\" rel=\"noopener nofollow\" target=\"_blank\">&#8220;58% of all cyberattacks from nation-states have come from Russia,<\/a>&#8221; said Tom Burt, Microsoft corporate vice president. For example, the <a href=\"https:\/\/www.zdnet.com\/article\/solarwinds-us-and-uk-blame-russian-intelligence-service-hackers-for-major-cyber-attack\/\" rel=\"noopener nofollow\" target=\"_blank\">US and UK blame the Russian Foreign Intelligence Service (SVR)<\/a> for the huge <a href=\"https:\/\/www.idginsiderpro.com\/article\/3609889\/solarwinds-its-pearl-harbor.html\" rel=\"noopener\" target=\"_blank\">SolarWinds software supply chain attack<\/a>. As Burt pointed out, Kremlin-backed hackers are becoming &#8220;increasingly effective.&#8221; That&#8217;s no surprise. After all, Russian agents have been at it for years.<\/p>\n<p>Even if you can&#8217;t find Ukraine on a map, things happening there are all too likely to affect all of us everywhere soon.<\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3647879\/will-world-war-iii-begin-in-cyberspace.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.techhive.com\/images\/article\/2015\/01\/cyberwar-thinkstock-100563260-primary.idge.jpg?auto=webp&amp;quality=85,70\"\/><\/p>\n<p><strong>Credit to Author: Steven J. Vaughan-Nichols| Date: Tue, 25 Jan 2022 03:00:00 -0800<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p>People die because of cyber wars, even if no bullets are ever fired. Instead, they die in emergency rooms that no longer have power, from broken medical communication networks, and from riots. All of this has happened before. It will happen again. And now, with <a href=\"https:\/\/www.cnn.com\/videos\/world\/2022\/01\/19\/russia-ukraine-intel-tension-border-chance-pkg-vpx.cnn\" rel=\"noopener nofollow\" target=\"_blank\">Russia poised to invade Ukraine<\/a> and Russian cyberattacks already in motion, we can only hope and pray that what promises to be the first major European war since World War II doesn&#8217;t spark the next World War.<\/p>\n<p>If it does, I fear the proximate cause won&#8217;t be Russian T-90 main battle tanks trying to smash their way into Ukraine&#8217;s capital, Kyiv. It will be the Russian GRU Sandworm hacking group launching a cyberattack that perhaps wrecks the European Union power grid; or knocks out major US internet sites such as Google, Facebook, and Microsoft; or stops 4G and 5G cellular services in their tracks.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3647879\/will-world-war-iii-begin-in-cyberspace.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[1328,10516,714],"class_list":["post-18072","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-government","tag-microsoft","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18072","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18072"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18072\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18072"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18072"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18072"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}