Listen to this episode

Ukranian Hacker Group

0:0014:46

Recorded March 2022. Regulations, deadlines, requirements and products discussed in this episode reflect that date and may have changed since. For where things stand today, see our current compliance guidance or ask us.

The episode in brief

What this episode covers

In this March 2022 episode, the Petronella Technology Group team runs through cybersecurity headlines dominated by the Russian invasion of Ukraine. Craig describes a Guardian report on the IT Army of Ukraine, a volunteer force of around 300,000 hackers recruited through Telegram, and cites claims that Kremlin and Duma websites, state media, banks, and Gazprom have faced disruption.

The panel also discusses Apple's release of 39 security patches across iOS, iPadOS, macOS and other operating systems, which Blake says addressed memory corruption flaws that could enable remote code execution. Craig argues listeners should update their devices, noting it was Patch Tuesday at the time of recording. The team covers banks bracing for Russian cyber retaliation after seven Russian lenders were removed from SWIFT, warnings that Russian capabilities have been well tested on US targets such as SolarWinds and Colonial Pipeline, and a fake antivirus update spreading Cobalt Strike malware. Craig urges never clicking links and verifying senders amid rising phishing. BJ adds thoughts on cloud security, Azure Quantum, and converging world crises.

Worth remembering

Key takeaways

  1. Craig highlights a Guardian report that 300,000 volunteer hackers signed up through Telegram as the IT Army of Ukraine to support Ukraine against Russia.
    “300,000 volunteer hackers come together to fight Russia.”
  2. Craig notes the group has already disrupted Russian web services, with Kremlin and Duma websites intermittent since the invasion started, according to NetBlocks.
    “the availability of websites of the Kremlin and Duma Russia's lower house of parliament have been intermittent since the invasion started”
  3. Blake describes Apple releasing 39 documented vulnerability fixes across iOS, iPadOS, macOS and other systems, which he says could expose users to remote code execution attacks.
    “If an iPhone user opens a malicious PDF file or views malicious web content.”
  4. Craig urges listeners to keep updating all endpoints and devices, noting at the time of recording it was Patch Tuesday with Microsoft patches also expected.
    “definitely want to make sure that you're updating all of your end points and devices, especially at this time with all the stuff going on”
  5. Craig advises never clicking links and going directly to manufacturers instead, saying he has noticed a large increase in phishing emails across many companies.
    “never click on a link. Always go direct to the manufacturer.”
  6. BJ cautions that updates should be verified as official, pointing to a fake antivirus update that launched Cobalt Strike malware in Ukraine.
    “make sure that the updates you're doing are verified official”
  7. Craig argues Russian cyber capabilities have been well tested on US targets, citing SolarWinds and Colonial Pipeline, and says everyone should be on high alert.
    “Russian based cyber attacks against us targets have been well tested.”

The summary and takeaways were drafted with AI from the transcript below. Each takeaway is shown with the passage it comes from.

From the show notes

About this episode

In this episode, we discuss the White-Hat Hacker group that has formed to help Ukraine fend off Russia.

Guests : Blake, Erin, & BJ

Full text

Episode transcript

Select any timestamp to play from that moment. This transcript was generated automatically from the audio and may contain errors, including in speaker names. The audio is the record.

Encrypted Ambition

Never miss an episode

New conversations on cybersecurity, compliance and AI for business leaders. Follow the show, or talk to Petronella Technology Group about what you heard.