Oleg Shakirov Profile picture
Jul 28 6 tweets 4 min read Read on X
A major cyber incident in Russia: two groups, Cyber Partisans & Silent Crow, took credit for a cyber attack on Aeroflot, claiming they destroyed its internal IT systems. Aeroflot didn't acknowledge the attack but canceled nearly 100 flights & delayed some more due to an 'outage' Image
Russia's Office of Prosecutor-General said that the incident was caused by a hacker attack & opened a criminal case under art. 272 of the Criminal Code (illegal access to computer info)

t.me/genprocrf/5308

See Aeroflot statements here t.me/aeroflot_pr
The immediate impact for Aeroflot goes beyond passengers' discontent & crowds at Sheremetyevo (msk1.ru/text/transport…) & includes its stocks plunging (rbc.ru/quote/news/art…)

It remains to be seen how soon the airline will recover & whether it would face legal consequences Image
Cyber Partisans formed in fall 2020 on the backdrop of the protests following presidential elections in Belarus. Initially it mostly targeted Belarusian gov't & organizations, but starting in 2022 also hit Russian targets

See x.com/shakirov2036/s… & x.com/shakirov2036/s…
Silent Crow emerged on Telegram in January & leaked several datasets allegedly stolen from Russian firms (at least 2 cases were confirmed in court: t.me/cyberguerre/29…, t.me/cyberguerre/32…). Acc. to @bizone_en researchers, Silent Crow is rebranded DumpForums Image
The alleged attackers have already collaborated before: in late March they claimed a hack of the Belarusian national CERT, apparently exaggerating the impact of the attack

tochka.by/articles/life/…

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Oleg Shakirov

Oleg Shakirov Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @shakirov2036

Nov 19, 2024
Putin signed the updated version of the basic principles of nuclear deterrence



Thread with big and small changes in RU with my comments

1/publication.pravo.gov.ru/document/00012…
The document expands the scope of states whom Russia seeks to deter. In addition to states with nukes and other WMD nuclear deterrence is now also aimed at states that provide land, air, sea & resources under their control for preparing and carrying out aggression against RU

2/ Image
An aggression by any ally against Russia is considered an aggression by the whole alliance. An aggression by a non-nuclear state with the participation or support of a nuclear states is considered as their joint attack

3/
Read 11 tweets
Nov 11, 2023
Came across a story that illustrates the tension in the USSR between smuggling computers & maintaining security. Translation in ALT, short summary below

In 1984, Lithuania was planning to import a Siemens 7536 computer — apparently, in some shady way — to be used at Gosplan We also pay attention to the prevention of possible technical penetration of the enemy into our secrets using imported equipment. Thus, we received a signal from the agent "Vilnius" […] that [Siemens] had known long in advance about the plans to install and use the imported Siemens 7536 computer at the [research institute of Lithuanian Gosplan]. The machine was assembled by foreign specialists. According to the contract, the firm will perform warranty repair service […] on their own.  In view the above, to prevent possible interception of aggregated secret data on the economic pot...
The Lithuanian KGB learned from its agent nicknamed
(sic!) "Vilnius" that Siemens, a West German firm, knew long in advance where this computer would be installed & operated. Not only did the Germans assemble it, under the contract they would independently repair it
This, from the KGB perspective, created the possibility that "intelligence tools" could be implanted into the computer to intercept secret data about Lithuania's economic situation — Gosplan, the State Planning Committee, would be the best plan to do just that
Read 6 tweets
Nov 6, 2023
Russia officially withdrew from the Conventional Forces in Europe Treaty on midnight of Nov 7 (Moscow time apparently)

Here's a statement from @mfa_russia describing the history of CFE and key lessons learned by Russia

mid.ru/ru/foreign_pol…
Image
Parity Lost...

Image
Image
Image
When shall Europa see thy like again?
Read 4 tweets
Oct 31, 2023
New cyber conflict-related criminal cases in Russia. Two men were separately arrested by the FSB in Tomsk & Kemerovo Oblast for their involvement w/ Ukrainian hackers. Notably both were charged with state treason (article 275) rather than computer crimes

kommersant.ru/doc/6311348
AFAIK, these are the 4th & 5th cases

Previously, 3 men were separately sentenced to 2-3 years & fines for participating in DDoS attacks launched by pro-Ukrainian hackers early in the war. Each was convicted for unlawful interference with critical infrastructure (article 274.1)
Read 5 tweets
Jun 19, 2023
Recently, a Western colleague raised a question, with some skepticism: "Are there really any significant cyber incidents in Russia? Not defacements or websites taken down for a day or two"

It's hard to overstate how different the situation has been since the start of the war
I wouldn't say that nothing was happening before, but as far as publicly known incidents are concerned they weren't plenty

Now, almost every other day there's a data breach or some kind of attack that would have deserved nation-wide coverage before; now everyone got used to them
Even with many stories unreported, there is so much activity that it's kind of overwhelming. There are different opininions in the Russian infosec community, but many people describe the current situation as cyber war and Russia as a testing range for all kinds of attacks
Read 19 tweets
Mar 31, 2023
Short thread on cyber issues in Russia's updated Foreign Policy Concept

mid.ru/en/foreign_pol…
Probably the most remarkable change is in para 26: an explicit mention that in the event of an unfriendly acts by foreign states or their groups including the use of modern ICT Russia would consider it lawful to respond in symmetrical or asymmetrical manner Image
This is significant because previously neither the Foreign Policy Concept nor other strategic document explicitly stated that the use of ICT against Russia could trigger a response
Read 8 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(