{"id":21062,"date":"2023-01-24T04:30:06","date_gmt":"2023-01-24T12:30:06","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2023\/01\/24\/news-14795\/"},"modified":"2023-01-24T04:30:06","modified_gmt":"2023-01-24T12:30:06","slug":"news-14795","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2023\/01\/24\/news-14795\/","title":{"rendered":"How Microsoft is helping Ukraine\u2019s cyberwar against Russia"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/idge\/imported\/imageapi\/2022\/04\/15\/08\/stop-russia-2-shutterstock_1576413886-100924629-small.jpg\"\/><\/p>\n<p>One of the big surprises in Russia\u2019s war against Ukraine has been how well <a href=\"https:\/\/www.computerworld.com\/article\/3658951\/russia-is-losing-the-cyberwar-against-ukraine-too.html\">Ukraine has fended off Russian cyberattacks<\/a>. Ad hoc groups of white-hat hackers have helped, as have a number of nations and the US government.<\/p>\n<p>Less well known is that tech companies, including Microsoft, are part of the effort. That aid ranges from giving advice to identifying attacks, offering fixes for them, and providing Ukraine with free tech and security services.<\/p>\n<p>Microsoft isn\u2019t just trying to help defend a country under siege from an aggressive, more-powerful neighbor. Russian cyberattacks against Ukraine can also get loose in the wild and do damage to enterprises and organizations that rely on Microsoft technology. (Russia could also deliberately target private companies with those attacks.)<\/p>\n<p>By helping Ukraine, Microsoft also helps its customers \u2014 and it happens to be good PR, as well.<\/p>\n<p>So just what kind of help does Microsoft give, and how might it help you or your organization? Here\u2019s what we know.<\/p>\n<p>In April 2022, Microsoft\u2019s Digital Security Unit <a href=\"https:\/\/query.prod.cms.rt.microsoft.com\/cms\/api\/am\/binary\/RE4Vwwd\" rel=\"noopener nofollow\" target=\"_blank\">released a 21-page overview of Russian cyberattacks on Ukraine<\/a> up until that date, and detailed what Microsoft had done to help.<\/p>\n<p>The day before the ground invasion began, Russia\u2019s military intelligence service, the GRU, \u201claunched destructive wiper attacks on hundreds of systems in Ukrainian government, IT, energy, and financial organizations,\u201d according to Microsoft.<\/p>\n<p>The cyber assault didn\u2019t let up after that. Russia attempted to infiltrate, disrupt, and destroy government networks, sometimes in concert with missile attacks. It set out to damage vital IT hardware and resources and launched disinformation campaigns to sap Ukraine\u2019s will to fight. Russia poured a lot into these disinformation campaigns because, as the report explained it, many Russian military officials believe \u201coperations to degrade troop morale, discredit the leadership, and undermine the military and economic potential of the enemy via information means can at times be more effective than traditional weapons.\u201d<\/p>\n<p>Microsoft offered a week-by-week account of Russia\u2019s cyberattacks and listed \u00a0some of the most dangerous pieces of malware being used, many of which target networks, Windows PCs, and .<a href=\"https:\/\/dotnet.microsoft.com\/en-us\/learn\/dotnet\/what-is-dotnet\" rel=\"noopener nofollow\" target=\"_blank\">NET, Microsoft\u2019s open source developer platform<\/a>.<\/p>\n<p>To fight back, Microsoft uncovered and tracked malware, and offered a variety of ways to defend against it and eradicate it. In some cases, the advice was surprisingly simple. For example, Microsoft recommended that Ukrainian organizations enable Windows\u2019 controlled folder access capabilities, which is turned off by default. Turning it on mitigates damage done by wiper malware. It also recommended the use of multi-factor authentication, which has paid off.<\/p>\n<p>The company also studied how Ukrainian organizations use Microsoft\u2019s endpoint detection and response (EDR) solutions; based on what it found, the company offered alternatives that could be even more effective.<\/p>\n<p>Microsoft\u2019s Tom Burt, corporate vice president for customer security and trust, <a href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2022\/04\/27\/hybrid-war-ukraine-russia-cyberattacks\/\" rel=\"noopener nofollow\" target=\"_blank\">said in a blog post last year<\/a> that Microsoft\u2019s Threat Intelligence Center (MSTIC) found wiper malware in more than a dozen Ukrainian networks, alerted the Ukrainian government to it, and opened a 24\/7 cybersecurity hotline to help fight it.<\/p>\n<p>Microsoft has also helped Ukraine harden its computing infrastructure, notably by moving it to the cloud to keep it safe. Microsoft President <a href=\"https:\/\/www.geekwire.com\/2022\/interview-microsofts-president-on-turbulent-times-for-the-company-country-and-world\/\" rel=\"noopener nofollow\" target=\"_blank\">Brad Smith explained to GeekWire<\/a> that the company spent $107 million \u201cto literally move the government and much of the country of Ukraine from on-premises servers to the cloud.\u201d The move also helped protect data centers Microsoft runs throughout Europe. According to Smith, this \u201chas been one of the indispensable elements in defending Ukraine.\u201d<\/p>\n<p>Microsoft plans to continue its assistance. Smith said\u00a0the company will offer <a href=\"https:\/\/www.geekwire.com\/2022\/microsoft-extends-ongoing-tech-support-for-ukraine-to-protect-digital-services-and-data-during-war\/\" rel=\"noopener nofollow\" target=\"_blank\">approximately $100 million in free tech aid and services to Ukraine in 2023<\/a>. (That\u2019s in addition to the estimated $400 million already spent.)<\/p>\n<p>Keep in mind that Microsoft isn\u2019t the only company offering help; Amazon has <a href=\"https:\/\/www.aboutamazon.com\/news\/community\/amazons-assistance-in-ukraine\" rel=\"noopener nofollow\" target=\"_blank\">done similar work using its considerable cloud expertise<\/a> and Google <a href=\"https:\/\/www.meritalk.com\/articles\/google-expands-support-for-ukraine-in-their-fight-against-russia\/\" rel=\"noopener nofollow\" target=\"_blank\">has offered cybersecurity and other kinds of aid<\/a>.<\/p>\n<p>All this work by governments and private companies has paid off. Part of a <em>New York<\/em> <em>Times\u00a0<\/em><a href=\"https:\/\/www.nytimes.com\/interactive\/2022\/12\/16\/world\/europe\/russia-putin-war-failures-ukraine.html\" rel=\"noopener nofollow\" target=\"_blank\">comprehensive investigation into how Russia has failed<\/a> focused on cyberwarfare. The story noted that before the war, \u201cOfficials in Washington, who had been working closely with the Ukrainians to bolster their cyberdefenses for years, had been holding their breath. States had mainly used hacking for acts of espionage and financial thievery, for subversion and sabotage. But nobody really knew how it would play out in a full-scale military conflict.\u201d<\/p>\n<p>Here&#8217;s how it played out, the <em>Times<\/em> concluded: Ukraine has so far defeated Russia in the cyberwar. Russia\u2019s once-feared hackers threw everything they had against Ukraine, including trying to shut down the power grid, disable government networks, and kill satellite communications.<\/p>\n<p>They failed every time.<\/p>\n<p>There are lessons here you can apply to your organization. Much of what Ukraine has done (with the help of governments and private industry) you can do on your own. Simple changes like using multi-factor authentication, turning on controlled folder access, and improving endpoint protection can go a long way to fending off hackers and cyberattacks. Keeping everything patched and up-to-date (which Microsoft also recommended to Ukraine) can pay off tremendously. A move to the cloud increases security as well.<\/p>\n<p>You don\u2019t need to be on a war footing to do all that. But if you\u2019re going to succeed, it makes sense to act as though you\u2019re fighting a war against hackers. That\u2019s certainly what the hackers believe.<\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3685939\/how-microsoft-is-helping-ukraine-s-cyberwar-against-russia.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/idge\/imported\/imageapi\/2022\/04\/15\/08\/stop-russia-2-shutterstock_1576413886-100924629-small.jpg\"\/><\/p>\n<article>\n<section class=\"page\">\n<p>One of the big surprises in Russia\u2019s war against Ukraine has been how well <a href=\"https:\/\/www.computerworld.com\/article\/3658951\/russia-is-losing-the-cyberwar-against-ukraine-too.html\">Ukraine has fended off Russian cyberattacks<\/a>. Ad hoc groups of white-hat hackers have helped, as have a number of nations and the US government.<\/p>\n<p>Less well known is that tech companies, including Microsoft, are part of the effort. That aid ranges from giving advice to identifying attacks, offering fixes for them, and providing Ukraine with free tech and security services.<\/p>\n<p>Microsoft isn\u2019t just trying to help defend a country under siege from an aggressive, more-powerful neighbor. Russian cyberattacks against Ukraine can also get loose in the wild and do damage to enterprises and organizations that rely on Microsoft technology. (Russia could also deliberately target private companies with those attacks.)<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3685939\/how-microsoft-is-helping-ukraine-s-cyberwar-against-russia.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[10516,714,24580,10525],"class_list":["post-21062","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-microsoft","tag-security","tag-small-and-medium-business","tag-windows"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/21062","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=21062"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/21062\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=21062"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=21062"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=21062"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}