Masked pro-Russian activists walk down the streets of Donetsk, Ukraine on April 28.

Masked pro-Russian activists walk down the streets of Donetsk, Ukraine on April 28. Efrem Lukatsky/AP

Why Ukraine Has Already Lost The Cyberwar, Too

Why was there no cyberwar in Ukraine? Because Russia has no need to attack that which it already owns. By Patrick Tucker

Don’t wait for cyberwar between Ukraine and Russia to break out ahead of the actual shooting. Ukraine already lost that, too. Russia may have unfettered access into the Ukrainian telecommunication systems according to several experts. It’s access that Russia can use to watch Ukrainian opposition leadership, or, in the event of an escalation in the conflict, possibly cut off telecommunications within Ukraine.

The ongoing situation in Ukraine has been marked by bloody protests, sieges of government buildings, ethnic clashes and misinformation campaigns. In cyberspace, relatively low-level exchanges between hacker groups have taken the form of temporary website attacks called displacements and distributed denial of service, or DDOS, which flood sites with phony traffic rendering the site inaccessible. (For a quick timeline of Russian and Ukrainian hactivist cyber-volleying, check out Ukraine Investigation’s coverage here.)

Russia has no need to attack that which it already owns, say several experts. “Russia already had access [to the Ukrainian telecommunications infrastructure] for years. That's true for almost all of the Commonwealth of Independent States. They all rely at some point on Russian technology,” Jeffrey Carr, CEO of the cyber-security firm Taia Global and of the author of Inside Cyber Warfare: Mapping the Cyber Underworld, told Defense One.

Russia’s access stems from two factors. The first: Ukraine’s communications intercept system, which allows the Ukrainian government to tap into civilian electronic communications, very closely resembles the Russian intercept system called SORM. SORM was developed by the Russian KGB as a means to surveil electronic communications within the Soviet Union. Essentially SORM serves as a backdoor for intelligence spooks to listen in on electronic communications. Think of the NSA’s PRISM program, but far more robust in terms of capability and with far fewer legal restrictions on its use. The current iteration, SORM 3, allows the Russian Federal Security Service, or FSB, backdoor access into landline, mobile and email communications.

Ukraine has its own SORM system modeled after Russia’s. But, as Russian journalists Andei Soldatov and Irina Borogan explained in Wired in 2012, Russian companies such as IsKratel manufacture equipment that Ukraine uses to maintain its system. Other manufacturers of SORM equipment include Juniper Networks, Huawei, Cisco and Alcatel-Lucent out of France. The simple fact that SORM equipment manufacturing firms are a matter of public record suggests vulnerability to hacking. The same technology that allows Ukraine’s Intelligence Service to eavesdrop in Ukraine may give Russia the same amount of access into Ukrainian communications.

“With local Ukrainian media sources reporting Ukrtelekom outages, it is unclear what reach Russia has into the Ukraine due to its use of the SORM standard,” Scott Donnelly, open source analyst with Recorded Future, told participants of an online webinar on Thursday. “While multiple additional pieces of information are necessary to definitively conclude Russia has a backdoor into the Ukrainian telecom system, it is clear the telecom equipment and layout are quite familiar to Russian military and intelligence officials operating in the cyber arena.” Ukrtelekom is the primary landline phone operator in Ukraine, servicing 80 percent of the country’s users.

Additionally, Russian telecom firms Vimpelcom and MTS do considerable  mobile business in Ukraine. MTS reportedly has 22.4 million subscribers in the country as of September 2013, making it the second largest mobile player. “It’s Russian companies that are providing the mobile services. That gives the Russians an avenue in,” James Andrew Lewis, director and senior fellow of the Strategic Technologies Program at the Center for Strategic and International Studies, told Defense One. “There’s an advantage to having ownership, having insight, knowing the legacy system and having relationships, and being physically present in adjacent areas. That all makes it easier for them.” Russian dominance into the Ukrainian mobile space was on full display back in January when protestors taking part in street demonstrations against the pro-Russian regime of then-President Viktor Yanukovych received ominous text messages reading, “Dear subscriber, you are registered as a participant in a mass disturbance,” according to the New York Times.

A similar phenomenon occurred in the first week in March, as reported by Reuters, just before the Russian incursion into Crimea, when Ukrainian security chief Valentyn Nalyvaichenko revealed to journalists "I confirm that an.... attack is under way on mobile phones of members of the Ukrainian parliament for the second day in a row."

Private Russian companies colluding with the Russian government to give Vladimir Putin a backdoor into clients’ systems is a practice that falls in line with the way the Putin government exercises influence over sectors of the Russian economy.

“These companies invested in Ukraine to make money. But now, if their friends from the FSB show up, say ‘Can you give us a hand? Tell us about the networks that you invested in. Give us some of the technical details or specifications?’ [The companies are] not well-placed to say no to that request. The companies did this for commercial reasons, but because [the companies] are subject to Russian control, that means that at any moment when its in Russia’s interest to extend that control, they can do so,” said Andrews.

Russia has other levers to pull in exerting control over communications in Ukraine, besides technological, as demonstrated by the strange story of Ukrtelekom, which was purchased in 2013 by Ukraine’s richest man, Rinat Akhmetov. Akhmetov, a coal and mining magnate, is a native of the region of Dombass, which has been a hotbed of separatist protests and police clashes. He was a staunch ally of Yanukovych. But not long after the former President fled the country, Akmetov made a series of public comments stating his intention to use his power and resources to keep “Donbass and Ukraine are together forever.”

He may be earnest in that promise, or simply aligning himself with what he perceives to be the winds of change bellowing through Kiev. But his coal mining operations in the Donbass region, the chief source of his wealth, are extremely vulnerable to Russian meddling. Not long after Akmetov issued his statement, a deputy of the State Duma of the Russian Federation, speaking to a Russian newspaper, said that if Russia were to annex Donbass, most of the Donbass coal mines would be shut down.

Wherever Akmetov’s true loyalties rest, he’s not averse to quickly shifting sides to protect his interests.

On Friday, Feb. 28, armed gunmen broke into the Ukrtelekom’s operation center in Crimea and were able to cause phone and Internet disruptions. Western media treated the incident as unremarkable. But the annexation of Crimea probably improved Russia’s ability to derive signals intelligence from Kiev—exponentially—according to Andrews. “Where they were getting ten messages before, now maybe they’re getting 70,” he said.

Does unfettered Russian access over the communications space in Ukraine necessarily mean that Russia could stage a telecom blackout?  

The company Renesys, which monitors Internet services globally, has called the possibility of a fast Russian takedown of Ukrainian telecommunications and infrastructure unlikely. John Bumgarner, chief technology officer at the U.S. Cyber Consequences Unit agrees. “Ukraine has approximately six [trunk lines] running through the country. Most of the telecommunication points were going through Kiev.”

It’s a subject of continual dispute among experts, (see this article in Newsweek for background,) but history suggests that Russia is holding back considerably. In 2008, pro-Russian forces successfully attacked key web sites of Georgian groups, such as the site for the Ministry of Foreign Affairs as well as several news sites.  Russian groups were able to launch a similar, coordinated cyberwar campaign against Estonia in 2007. When asked if Russia could stage a Ukrainian version of the Georgia cyberattack in 2008, Andrews replied that Russia could probably do something similar to what they did to Georgia."

Bumgarner disagreed. “In Georgia, there were only two primary access points, one was through Moscow and the other through Turkey.  The Kremlin was able to control data flowing through both of these access points, thus squeezing Georgia's presence on the Internet.  Russia would have a difficult time controlling the full cyber spectrum in Ukraine,” he told Defense One.

Andrews added that he thought that a takedown of Ukraine’s telecommunications infrastructure was unlikely, not because of technological limitations, but because a blackout wasn’t in Russia’s immediate interests. “They already have total intelligence dominance. And they have achieved their political ends, they don’t need to do much more,” he said.

Carr, Taia Global’s chief, was less equivocal. “The bottom line is that if the Russian government wanted to shut down Ukraine's power and telecommunications, they could do so at will. If this becomes a full-scale war, you can expect a definite interruption of services - strategically planned. And there's nothing that Ukraine could do to stop it,” he said in an email. Such an assault would signal a departure from the stealth-invasion tactics Russia has employed to great effect so far.

Recorded Future’s analysis said that heavy DDoS activity around a few upcoming events may signal conflict escalation. On May 1, NATO will expand its air-policing mission in the Baltic. On May 11, the Eastern cities of Donetsk, Luhansk, and Kharkiv face possible referendums. Most importantly, on May 25, the Ukrainian presidential election.

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.