AIRLINK 191.84 Decreased By ▼ -1.66 (-0.86%)
BOP 9.87 Increased By ▲ 0.23 (2.39%)
CNERGY 7.67 Increased By ▲ 0.14 (1.86%)
FCCL 37.86 Increased By ▲ 0.16 (0.42%)
FFL 15.76 Increased By ▲ 0.16 (1.03%)
FLYNG 25.31 Decreased By ▼ -0.28 (-1.09%)
HUBC 130.17 Increased By ▲ 3.10 (2.44%)
HUMNL 13.59 Increased By ▲ 0.09 (0.67%)
KEL 4.67 Increased By ▲ 0.09 (1.97%)
KOSM 6.21 Increased By ▲ 0.11 (1.8%)
MLCF 44.29 Increased By ▲ 0.33 (0.75%)
OGDC 206.87 Increased By ▲ 3.63 (1.79%)
PACE 6.56 Increased By ▲ 0.16 (2.5%)
PAEL 40.55 Decreased By ▼ -0.43 (-1.05%)
PIAHCLA 17.59 Increased By ▲ 0.10 (0.57%)
PIBTL 8.07 Increased By ▲ 0.41 (5.35%)
POWER 9.24 Increased By ▲ 0.16 (1.76%)
PPL 178.56 Increased By ▲ 4.31 (2.47%)
PRL 39.08 Increased By ▲ 1.01 (2.65%)
PTC 24.14 Increased By ▲ 0.07 (0.29%)
SEARL 107.85 Increased By ▲ 0.61 (0.57%)
SILK 0.97 No Change ▼ 0.00 (0%)
SSGC 39.11 Increased By ▲ 2.71 (7.45%)
SYM 19.12 Increased By ▲ 0.08 (0.42%)
TELE 8.60 Increased By ▲ 0.36 (4.37%)
TPLP 12.37 Increased By ▲ 0.59 (5.01%)
TRG 66.01 Increased By ▲ 1.13 (1.74%)
WAVESAPP 12.78 Increased By ▲ 1.15 (9.89%)
WTL 1.70 Increased By ▲ 0.02 (1.19%)
YOUW 3.95 Increased By ▲ 0.10 (2.6%)
BR100 11,930 Increased By 162.4 (1.38%)
BR30 35,660 Increased By 695.9 (1.99%)
KSE100 113,206 Increased By 1719 (1.54%)
KSE30 35,565 Increased By 630.8 (1.81%)

Kyiv believes a hacker group linked to Belarusian intelligence carried out a cyberattack that hit Ukrainian government websites this week and used malware similar to that used by a group tied to Russian intelligence, a senior Ukrainian security official said.

Serhiy Demedyuk, deputy secretary of the national security and defence council, told Reuters that Ukraine blamed Friday’s attack - which defaced government websites with threatening messages - on a group known as UNC1151 and that it was cover for more destructive actions behind the scenes.

“We believe preliminarily that the group UNC1151 may be involved in this attack,” he said.

His comments offer the first detailed analysis by Kyiv on the suspected culprits behind the cyberattack on dozens of websites. Officials on Friday said Russia was probably involved but gave no details. Belarus is a close ally of Russia.

The cyberattack splashed websites with a warning to “be afraid and expect the worst” at a time when Russia has massed troops near Ukraine’s borders, and Kyiv and Washington fear Moscow is planning a new military assault on Ukraine.

Russia has dismissed such fears as “unfounded”.

The office of Belarusian President Alexander Lukashenko did not immediately respond to a request for comment about Demedyuk’s remarks.

Russia’s foreign ministry also did not immediately respond to a request for comment on his remarks. It has previously denied involvement in cyberattacks, including against Ukraine.

“The defacement of the sites was just a cover for more destructive actions that were taking place behind the scenes and the consequences of which we will feel in the near future,” Demedyuk said in written comments.

In a reference to UNC1151, he said: “This is a cyber-espionage group affiliated with the special services of the Republic of Belarus.”

Demedyuk, who used to be the head of Ukraine’s cyber police, said the group had a track record of targeting Lithuania, Latvia, Poland and Ukraine and had spread narratives decrying the NATO alliance’s presence in Europe.

“The malicious software used to encrypt some government servers is very similar in its characteristics to that used by the ATP-29 group,” he said, referring to a group suspected of involvement in hacking the Democratic National Committee before the 2016 U.S. presidential election.

“The group specializes in cyber espionage, which is associated with the Russian special services (Foreign Intelligence Service of the Russian Federation) and which, for its attacks, resorts to recruiting or undercover work of its insiders in the right company,” Demedyuk said.

The messages left on the Ukrainian websites on Friday were in three languages: Ukrainian, Russian and Polish. They referred to Volhynia and Eastern Galicia, where mass killings were carried out in Nazi German-occupied Poland by the Ukrainian Insurgent Army (UPA). The episode remains a point of contention between Poland and Ukraine.

Demedyuk suggested the hackers had used Google Translate for the Polish translation.

“It is obvious that they did not succeed in misleading anyone with this primitive method, but still this is evidence that the attackers ‘played’ on the Polish-Ukrainian relations (which are only getting stronger every day),” he said.—Reuters

Comments

Comments are closed.