Russia's Hybrid Cyber-Physical War in Europe Heats Up

An outline of Russia with cyber stylings
Source: traffic_analyzer via Getty Images

Russia continues to ramp up hybrid, asymmetric efforts to target its adversaries across Europe in both virtual and physical space, in support of its invasion of Ukraine, which began in February 2022.

That's according to Recorded Future, which found that the activity stops short of a kinetic, boots-on-the-ground invasion, instead involving a number of psychological, cyber, and physical tactics intended to test enemy defenses, degrade critical infrastructure, and foster fear within an enemy's government and population.

Russia's hybrid warfare strategy has been apparent even outside of Recorded Future's reporting. There are the recent water and wastewater attacks targeting Norway and Poland, for example. In June, DomainTools observed that state actors like to target water and wastewater for primarily psychological reasons, as even a brief disruption in service can trigger disproportionate reaction among the affected populace. Attacks against Poland's energy infrastructure at the beginning of the year were also attributed to Russia-aligned actors.

In a new report, Recorded Future's Insikt Group offered several examples of its own. On the influence operations front, Russia has "often involved impersonating national and pan-European media outlets to disseminate Kremlin propaganda," the blog post said. For example, last month Russia's CopyCop disinformation network reportedly impersonated localized news and fact-checking outlets across Europe, particularly in France and Norway, using AI-generated text and voice.

Other operations were to keep NATO members in what the blog described as a reactive, defensive posture. Russian drones have reportedly violated NATO airspace by flying near Estonia's border. And Romanian authorities intercepted and destroyed a Russian drone detected near Romania's Neptun Deep offshore gas project in the Black Sea, according to the report. "Authorities determined the incident was meant to threaten offshore energy infrastructure and test NATO maritime response protocols," Recorded Future researchers wrote.

Further incidents included an alleged attempt on Russia's part to use drones and explosives to damage cargo infrastructure at a German airport, as well as coordinated cyberattacks against Norwegian public infrastructure.

Chelsea Cederbaum, a senior threat intelligence analyst at Recorded Future who authored the blog post, tells Dark Reading that the key metric to evaluate a company's risk of Russian targeting "is its proximity to providing material support to Ukraine's war effort."

As such, "outside of traditional critical infrastructure, logistics and dual-use firms are at high risk," she says. "In addition, companies manufacturing specialized components that could aid in repairing damage from Russian hybrid attacks — such as subsea cable repair equipment, marine navigational systems, or industrial defense systems — are at high risk."

Russia's Attacks on Europe May Get Worse

Russian officials in 2013 used the term "New Generation Warfare" (NGW) to refer to this kind of indirect warfare. John Gallagher, vice president at operational technology and Internet of Things security vendor Viakoo, says that Russia's NGW framework is still in its early stages, and "more a philosophy than a practice at this point, with each component operating independently." However, this might not be the case forever.

"Russia has several components in place that in the future could be highly coordinated to create a more impactful attack (think cyber-physical attacks combined with system takeovers, media, deepfakes, and corrupted data)," Gallagher explains. "Each threat vector still must be addressed and remediated separately, with the focus on rapid remediation to slow the attack process."

The Insikt Group assesses that although much of Russia's hybrid warfare has been opportunistic to date, over the next two years, "Russian President Vladimir Putin is likely to escalate aggression across Europe, potentially coalescing the above-described tactics into a full-scale NGW campaign."

This assessment, the blog post explained, is in part based on the US Presidential elections in 2028, which "could result in a US president more willing to commit US military and political resources to bolstering Europe's defensive capabilities."

Such activity would likely remain in the realm of the disruptive rather than kinetic, researchers found, but would likely "involve more frequent incursions and violations, multiple tactics used concurrently to strain NATO resources, and escalated aggression," Recorded Future said.

In its blog post, the Insikt Group makes recommendations tailored to those more likely to be affected by disinformation campaigns, physical sabotage, and aerospace and territorial water violations. On the cyber-sabotage front, Russian cyber operations have emphasized access through Internet-facing firewalls, VPNs, email services, and Web portals. For this, Recorded Future explicitly recommends phishing-resistant multifactor authentication (MFA).

Dive deeper

Free tools to verify and analyze what this article covers:

source: DarkReading