














Threat Insight
On August 24, a denial-of-service (DDoS) attack was directed against infrastructure operated by the Norwegian Digitalisation Agency. The attack impacted several Norwegian government services, as Digdir operates authentication services for many government sites, including ID-porten, MinID, Maskinporten, eFormidling, eInnsyn, the Contact and Reservation Register, and Ansattporten. [1]
The pro-Russian hacktivist group Server Killers has claimed responsibility for the attacks and says it has declared a “cyber war” against Norway, allegedly in response to Norway and Ukraine signing a drone deal to strengthen Ukraine’s defenses. [2]
The DDoS attack was the third similar attack against Norwegian digital infrastructure this summer. Two previous attacks reportedly occurred in June and on August 3. [3]
Truesec has no direct evidence that Server Killers is led by the Russian state. However, the group is linked to another Russian hacktivist group, Noname057(16), which has been exposed as the product of a Russian agency called CISM that appears to be involved in online information operations. Since Server Killers shares many characteristics with Noname057(16), including its messaging, it is likely that the group is led by the Russian state in a similar way.
Central authentication services, such as those operated by Digdir, can be effective solutions for minimizing breaches from regular cyberattacks, but they can also make DDoS attacks more effective. Authentication services for banks and other financial institutions are also popular targets for DDoS attacks.
At present, Truesec has no information about the exact extent of the DDoS attack or what DDoS protection Digdir has in place. However, as we have seen previously, even sites with strong DDoS protection can be temporarily disrupted if the attacker has sufficient resources.
Since Sweden and Ukraine have announced that Ukraine will soon begin flying Swedish Gripen fighters, it is possible that this could also trigger similar Russian DDoS attacks against Swedish sites. The risk of Russian information operations in cyberspace will also increase in conjunction with the upcoming general election in Sweden on September 13.
Heightened tensions in Northern Europe, along with warnings about a potential Russian military incursion into one of the Baltic states, also mean that the overall cyber threat landscape in Northern Europe is assessed to be at heightened risk, even if there are no specific cyber threats at this moment. [4]
[1] https://nsm.no/aktuelt/malrettede-tjenestenektangrep-mot-norske-nettsteder
[2] https://www.nrk.no/artikkel/russisk-hackergruppe-hevder-a-sta-bak-dataangrep-mot-norge-1526574
[3] https://t.me/ServerKillersRus
[4] https://www.rferl.org/a/baltics-russia-security-threat-eu-letter-nato-defense/33840594.html
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。