The biggest internet service provider in Russia, Rostelecom, reports that 2022 saw a record number of Distributed Denial of Service (DDoS) attacks against Russian organisations.
According to the Rostelecom report, its experts recorded 21.5 million critical web attacks aimed at approximately 600 organizations from various industries, including critical infrastructure, financial, and the private and public sectors. DDoS assaults accounted for 80% of all cyberattacks directed at Russian entities.
Other findings suggest that 30% of all observed cyberattacks in 2022 targeted the governmental sector, followed by 25% on financial organisations and services and 16% on educational institutions.
With more than 500,000 DDoS attempts found, Moscow was the most often targeted region in 2022. The largest documented attack was 760 GB/sec, while the longest DDoS lasted nearly three months.
The fourth session of the Cybercrime Ad Hoc Committee focused on amending the consolidated document prepared by the Chair Committee with the support of the Secretariat on November 7th, 2022. The new version was amended and will be further negotiated in the upcoming sessions. In General Provisions, the protection of human rights was highlighted by the EU and its member states, Canada, and the UK, while also emphasising that state parties shall carry out their obligations under international human rights law treaties.
Within the framework of the international conference in Strasbourg, Greece became the 31st country to sign the Second Additional Protocol on enhanced co-operation and disclosure of electronic evidence to the Convention on Cybercrime (Budapest Convention).
A surge in digital crimes that occurred during the COVID-19 pandemic seems to be continuing in the Netherlands, despite a low number of burglaries, robberies, and muggings. These digital crimes include online scams and fraud. Reports on cybercrime cases stood at 4,715 in 2019 and rose to 13,949 in 2022. Conversely, while classic crimes have slightly increased since the end of the pandemic, their number still remains low compared to 2019.
Vixen Panda, a Chinese advanced persistent threat (APT) group, has been linked to a wave of attacks against the Iranian government between July and December 2022. An analysis conducted by cybersecurity researchers at the Palo Alto Networks’ Unit 42 indicates that Iranian government networks have likely been compromised by two new variants of a backdoor called Turian.
The Computer Emergency Response Team of Ukraine (CERT-UA) argues that a damaging malware attack on the national news agency Ukrinform on 17 January 2023 was carried out by the Sandworm hacking group (said to be associated with Russian armed forces).
The State Service of Special Communications and Information Protection (SSSCIP) of Ukraine announced that ‘according to preliminary data, provided by CERT-UA specialists, the attack has caused certain destructive effects on the agency’s information infrastructure, but the threat has been swiftly localized nonetheless. This enabled Ukrinform to continue its operation.’
NoName057(16), a hacktivist group described as pro-Russian, is reportedly targeting websites of candidates in the 2023 Czech presidential elections. According to SentinelLabs, the action is part of a distributed-denial-of-service (DDoS) attacks campaign that the group has been conducting against government organisations and critical infrastructures in Ukraine and NATO member states since the start of the war in Ukraine. Some of the most recent targets are said to include Denmark’s financial sector and organisations and businesses in Poland and Lithuania.
The organisation allegedly carried out these attacks utilising open Telegram channels, a DDoS payment program run by volunteers, a multi-OS supported toolkit, and GitHub.
The European Parliament’s civil liberties committee (LIBE) has voted for the parliament to move ahead with ratifying the Second Additional Protocol to the Budapest Convention on Cybercrime. More specifically, LIBE voted in favour of a draft European Parliament resolution that will give the parliament’s consent to a draft Council decision that allows EU member states to ratify the Additional Protocol.
Among other provisions, the Protocol introduces the possibility of emergency mutual assistance between signatories in addressing cybercrime, creates a legal framework for joint investigations, and makes it possible to collect evidence via videoconference where necessary.
The Protocol was criticised by civil society organisations citing incompatibilities with the EU’s Charter of Fundamental Rights. At the same time, a January 2022 opinion from the European Data Protection Supervisor (EDPS) underscored the “many safeguards” contained in the text despite the fact that some data transfers between the EU and the US would be facilitated under the agreement.
Following an unspecified ‘cyber-incident’, the UK’s Royal Mail has warned customers of ‘severe service disruption’ for items sent abroad. The National Cyber Security Centre in the UK acknowledged this, stating that they are aware of an incident affecting Royal Mail Group and are working with the company, as well as the National Crime Agency, to fully understand the impact.
Attacks using distributed denial of service (DDoS) techniques have affected the central bank and seven private banks in Denmark and disrupted their business activities. The attack also affected IT financial industry solutions developer Bankdata, which led to temporary access restrictions in the case of the websites of private banks.