There has been substantial commentary on the role of cyberattacks, hacktivists, and the cybercrime underground in the Russia-Ukraine conflict. Drawing on a range of data sources, we argue that the widely-held narrative of a cyberwar fought by committed 'hacktivists' linked to cybercrime groups is misleading. We collected 281K web defacement attacks, 1.7M reflected DDoS attacks, and 441 announcements (with 58K replies) of a volunteer hacking discussion group for two months before and four months after the invasion. To enrich our quantitative analysis, we conducted interviews with website defacers who were active in attacking sites in Russia and Ukraine during the period. Our findings indicate that the conflict briefly but significantly caught the attention of the low-level cybercrime community, with notable shifts in the geographical distribution of both defacement and DDoS attacks. However, the role of these players in so-called cyberwarfare is minor, and they do not resemble the 'hacktivists' imagined in popular criminological accounts. Initial waves of interest led to more defacers participating in attack campaigns, but rather than targeting critical infrastructure, there were mass attacks against random websites within '.ru' and '.ua'. We can find no evidence of high-profile actions of the kind hypothesised by the prevalent narrative. The much-vaunted role of the 'IT Army of Ukraine' co-ordination group is mixed; the targets they promoted were seldom defaced although they were often subjected to DDoS attacks. Our main finding is that there was a clear loss of interest in carrying out defacements and DDoS attacks after just a few weeks. Contrary to some expert predictions, the cybercrime underground's involvement in the conflict appears to have been minor and short-lived; it is unlikely to escalate further.
翻译:对俄罗斯-乌克兰冲突网络攻击、黑客主义和网络犯罪在地下的作用进行了大量评论。根据一系列数据来源,我们争辩说,由“黑客主义者”与网络犯罪集团有关联的网络战争的广泛叙述具有误导性。我们收集了281K网络诽谤攻击,1.7M反映DDoS攻击,以及441个志愿者黑客讨论小组在入侵前两个月和入侵后四个月的公告(有58K份答复)。为了丰富我们的定量分析,我们采访了活跃于俄罗斯和乌克兰袭击网站的败类网站。我们的调查结果表明,这场冲突只是短暂但相当显著地吸引了低层次网络犯罪界的注意,而污脸和DDoS攻击的地理分布也发生了显著的变化。然而,这些参与者在所谓的网络战争中所起的作用并不大,而且他们与大众犯罪学中想象的“黑客主义者”不同。最初的兴趣波浪使更多的低面人物参加了攻击运动,而不是针对关键基础设施。我们的调查显示,“黑客”的大规模攻击行动在俄罗斯内部似乎没有多少次出现。