Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-disruptioncritical-infrastructure-threatgovernment-diplomatic-threatfinancial-sector-threat

Russian-Linked Cyberattacks Hit Ukraine and Spill Into Wider European Targets

Updated 28d agoFirst seen May 25, 202620 sources

Ukrainian government, military, banking, and energy targets were repeatedly disrupted by cyber operations tied to Russia and the war around Ukraine. Reports describe attacks on a Ukrainian power station, outages affecting the websites of Ukraine’s defense ministry and major banks, and broader disruptive activity against the country’s financial sector. The UK government later said technical analysis by the National Cyber Security Centre assessed that Russia’s GRU was almost certainly involved in the February 2022 distributed denial-of-service attacks on Ukrainian banking targets, framing the incidents as part of continued Russian aggression.

The campaign also expanded beyond Ukraine through both state-linked and pro-Russian actors. Killnet, a Russia-aligned hacktivist group, claimed retaliatory DDoS attacks on Lithuanian government and business websites after restrictions affecting transit to Kaliningrad, while other reporting said Russian-backed actors continued destructive operations against Ukraine, including wiper malware and attempted power-grid attacks. At the same time, pro-Ukrainian hackers mounted hack-and-leak operations against Russian institutions, underscoring how the conflict evolved into a broader regional cyber confrontation affecting governments, critical infrastructure, and financial services.

Share:
Russian-Linked Cyberattacks Hit Ukraine and Spill Into Wider European Targets
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

17 events from the most recent confirmed update back to the earliest known activity.

17 EVENTS
May 21, 20251y ago

Russia accused of targeting border cameras to disrupt aid to Ukraine

By May 2025, Russia was accused of attempting to hack security cameras at border crossings used to move assistance into Ukraine. The alleged activity represented a cyber effort aimed at interfering with logistics and aid delivery rather than the previously documented attacks on banks, telecoms, or the power grid.

Russia accused of trying to hack border security cameras to disrupt Ukraine aid | Russia | The Guardian
Dec 12, 20233y ago

Russian cyberattack disrupts Kyivstar and wipes thousands of systems

In December 2023, Ukraine's largest telecom operator Kyivstar was hit by a destructive cyberattack attributed to Russia that caused major service outages. The company's CEO later said the attack wiped thousands of virtual servers and PCs, highlighting the scale of the intrusion.

CEO of Ukraine's largest telecom operator describes Russian cyberattack that wiped thousands of computers | The Record from Recorded Future News
Apr 11, 20233y ago

Russian hackers target cameras inside Ukraine for surveillance

By 2023-04-11, reporting said Russian hackers were attempting to access internet-connected security cameras inside Ukraine, including devices in locations such as coffee shops. The activity suggested an effort to gather real-time visual intelligence from civilian and commercial environments during the war.

Russian hackers ‘target security cameras inside Ukraine coffee shops’ | Ukraine | The Guardian
Jun 27, 20224y ago

Killnet launches DDoS attacks on Lithuanian government and business sites

In June 2022, pro-Russian hacktivist group Killnet conducted distributed denial-of-service attacks against Lithuanian government and business websites, including the State Tax Inspectorate and accounting provider B1.lt. The group said the operation was retaliation for Lithuania's restrictions on transit to Kaliningrad and threatened further disruption.

Apr 22, 20224y ago

Russian-linked actors launch hack-and-leak campaign against Russian institutions

By April 2022, hackers aligned with Ukraine or sympathetic to its cause claimed breaches of dozens of Russian institutions, including Roskomnadzor and the F.S.B., and released emails and internal documents online. The leaks were presented as part of the cyber dimension of the Russia-Ukraine war, though much of the material was difficult to independently verify.

Apr 8, 20224y ago

Sandworm attempts Industroyer2 attack on Ukrainian substations

In April 2022, Russian state-linked Sandworm actors attempted to deploy Industroyer2 malware against Ukrainian electrical substations. Ukrainian defenders disrupted the operation before it could cause a larger power outage, revealing a new phase of cyber targeting against the country's energy infrastructure.

Ca Ccs
Mar 4, 20224y ago

Ukraine reports propaganda site hijacks and destructive malware campaigns

By 2022-03-04, a senior Ukrainian cyber official said Russian operators had hijacked about 10 local government websites to post false surrender messages and were running targeted email campaigns that delivered destructive malware. He also said Ukraine had identified attempts to infect individual citizens' devices, indicating an expansion of Russian cyber tactics beyond earlier DDoS and phishing activity.

Ukraine cyber official: We only attack military targets | The Independent
Feb 28, 20224y ago

Tech companies mobilize to help Ukraine defend against cyberattacks

By 2022-02-28, major technology companies including Microsoft were publicly described as assisting Ukraine in defending government and critical networks against ongoing Russian cyberattacks during the invasion. The support marked a notable private-sector response alongside the previously documented disruptive attacks on Ukrainian institutions.

Tech Companies Help Defend Ukraine Against Cyberattacks - The New York Times
Feb 25, 20224y ago

Ukraine warns of new wave of phishing attacks

On 2022-02-25, Ukrainian cyber officials warned that a new wave of phishing attacks was targeting users amid the broader conflict. The alert marked a shift from the earlier disruptive DDoS activity to credential-theft and social-engineering operations affecting Ukrainian networks.

Ukrainian cyber officials warn of new wave of phishing attacks | CyberScoop
Feb 24, 20224y ago

Viasat KA-SAT satellite network disrupted at start of Ukraine invasion

On 2022-02-24, a cyberattack hit Viasat's KA-SAT satellite communications network, disrupting modems in Ukraine and elsewhere in Europe. The incident affected communications used around the opening of Russia's invasion and later became a major example of spillover risk in satellite infrastructure.

Russia’s Viasat Hack Exposed Satellite Industry’s Security Flaws

Wiper malware hits Ukrainian bank and Baltic government contractors

On 2022-02-24, destructive malware attacks reportedly affected a Ukrainian bank and Ukrainian government contractors in Latvia and Lithuania as Russia's invasion began. The activity showed cyber operations accompanying the kinetic assault and extending beyond Ukraine's borders to supporting organizations in neighboring countries.

Russia’s Cyber Threat to Ukraine Is Vast-and Underestimated | WIRED
Feb 18, 20224y ago

UK publicly attributes February Ukraine cyberattacks to Russia's GRU

On 2022-02-18, the UK government said technical analysis by the National Cyber Security Centre assessed that Russia's Main Intelligence Directorate was almost certainly involved in the DDoS attacks against Ukraine on 15 and 16 February. The statement framed the activity as part of continued Russian aggression toward Ukraine.

Feb 16, 20224y ago

Second day of attacks continues against Ukraine's banking sector

Disruptive attacks against Ukraine's banking and financial sector continued on 2022-02-16, extending the impact beyond the initial wave the previous day. The multi-day activity became the basis for later public attribution by the UK government.

Feb 15, 20224y ago

DDoS attacks hit Ukraine's defense ministry and major banks

On 2022-02-15, disruptive cyberattacks knocked offline or degraded the websites of Ukraine's defense ministry, armed forces, and major banks including PrivatBank and Oschadbank. Ukrainian officials said the incidents were large-scale DDoS attacks occurring amid heightened tensions with Russia.

Jan 14, 20224y ago

Hackers disrupt Ukrainian government websites

On 2022-01-14, multiple Ukrainian government websites were taken offline or defaced in a cyberattack. The incident marked an earlier wave of disruptive activity against Ukraine's public sector before the February attacks on banks and defense-related sites.

Hackers Bring Down Government Sites in Ukraine - The New York Times
Feb 24, 20215y ago

Ukraine says hackers breached document portal and planted malicious files

On 2021-02-24, Ukrainian officials said attackers had compromised a government document-management portal and uploaded malicious files disguised as official documents. Ukraine linked the activity to Russia, describing it as part of ongoing cyber operations against state institutions.

Ukraine says Russia hacked its document portal and planted malicious files - Ars Technica
Dec 17, 201610y ago

Ukraine's power grid is hacked again, causing a blackout in Kyiv

A cyberattack disrupted a Ukrainian power transmission station in December 2016, causing a brief blackout in part of Kyiv. Researchers later linked the incident to malware known as Industroyer/CrashOverride, marking another major attack on Ukraine's power grid.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Russian-Linked Cyberattacks Hit Ukraine and Spill Into Wider European Targets | Mallory