Ukrainian hackers destroyed the IT infrastructure of Russian drone manufacturer
prm.ua
prm.ua
One day I decided to change my main disk and used the opportunity to rebuild everything from scratch and from backups. I was up in about an hour.
And then I spent a week fixing this and that, ah yes I changed that too and, crap, I cannot remember why this thingie is set up this way. And some more.
This is a one-man lab, with simple services, all on docker. I also work in IT.
Recovering from scratch a whole infrastructure managed by many people over the years is a titanic task.
I helped to recover my nearby hospital as a volunteer when it was ransomwared. The poor two IT guys over there has no idea how to recover and the official help was pityful.
I also helped with a ransomware attack on a large company. The effort people had to do to remember why something was that way, or just remember whatever was colossal. Sure a lot of things were "documented" and "tested" but reality hit hard.
However, because in a previous life I'd been responsible for backups and involved in disaster recovery planning I was already kind of prepared with:
- a mirrored on site copy of backups (that they either didn't find or chose to leave behind)
- older hardware that had once been performing the duties of the existing seized gear (I'm a bit of a hoarder, I like repurposing or keeping for just such an occasion)
- multiple off site backups
- pretty good documentation of my setup
I was back up and running within a day or two and had lost maybe a couple of days of data. And it's a home lab, so nothing super important anyway, but a (not really) nice resilience test.
It also gave me the experience to work out a few structural changes to further limit the impact of an event that takes out a bunch of processing and storage.
(After 8 months they told me to pick up all my gear, they found nothing, but thanks for traumatising my kids)
Possibly the worst thing to be raided for: distribution of CSAM.
Apparently based purely on the 'evidence' of my IP address being on some list - that's the only explanation I ever got.
Funny thing is, they did so little background research they didn't even know to expect kids in the house when they raided at 6:30am.
It still triggers me. This was in August 2022. I wrote pages and pages of my memories and thoughts about it, and it still makes me angry for about ten different reasons.
The long version I haven't written yet and probably never will. I don't want to dwell on it, I want to get on with my life and have an even worse drama to deal with at the moment: https://news.ycombinator.com/item?id=44533637
I know I'm alive, that's for sure. I'm trying to make lemonade by the goddamn bucket load.
P.S. I have written prior HN comments referring to the raid if you care enough to go back that far.
As someone who was arrested in his PJs at 4am due to a false accusation that the police did not investigate and for which they did not have probable cause, I feel this in my bones.
$15k in legal fees, a day in jail, and three months later, the charges were dropped because, as per the DA, “we cannot in good conscience pursue this case”.
No consequences for the person who made the false accusation, or the officer that enacted an arrest without probable cause.
My heart still skips a beat whenever I think I hear a knock at the door or noises in the middle of the night. I’ll wake up from a dead sleep in a panic. In theory I could pursue a lawsuit against both the accuser and officer, but that feels overwhelming — I’ve just tried to move on.
It completely changed the way I see the police and the criminal justice system. The process is, in of itself, punishment.
I was fortunate enough to be able to afford good legal representation, and I now have a great deal of empathy for those who are railroaded by the system because they cannot.
My home was searched by the police for something much less serious (buying lab equipment, completely legally), and the experience left me having panic attacks every time there was a knock at the door.
I don't like that it can be interpreted that way, but I also refuse to stop using it since that's someone else's reading.
The only factor I use to treat one human different from another is whether they're a jerk or not, and I have to know them well enough to work that out. I've come across a few jerks in my time, and they take many and varied forms.
A few months from now, I'd love to have written down decisions for my current project:
- Why did I decided to use Kysely over Drizzle, Knex, Prisma, TypeORM or other ORM/SQL tool?
- How am I going to do migrations?
- Why am I using one of Deno/Bun over sticking to nodejs?
- Why did I structure the project as a directory per feature over controllers/models/services directories?
- Why did I fork this library and what are the steps to keep this thing updated? Do I plan to upstream my changes? Is there a GitHub issue or PR about it?
- Why am I hosting in one of AWS/GCP/Azure? Why not lambda functions? Why docker?
- Why did I pick this specific distribution of kubernetes over the other also lightweight alternatives?
- Why did I even start this project and what do I aim to accomplish with it?
So I created a # Decisions section in README.md
This way I don't keep doubting my own decisions and wasting time opening 20 documentation tabs to compare solutions yet again.
Of course, you have a relatively high profile, so could probably avoid it/get it reversed.
I've also tried a mechanism where I have GitHub Actions write them out as JSON files in the repo itself, then I can git clone them in one go: https://gist.github.com/simonw/0f906759afd17af7ba39a0979027a... and https://github.com/simonw/fetch-github-issues
Technical decisions used to be in the daily-notes.org file, but keeping in a separate file makes it more accessible to LLMs. I actually started that practice before LLMs were in common use, I struggle to remember why.
Should that "why" be in technical-decisions.org or daily-notes.org?
Lots of things can keep going with pen and paper or some cloud software.
At the very least, you have to communicate with your clients.
Everything is quickly strapped together due to teams being understaffed. Preparing infrastructure in a way such that it can easily be recreated is easily twice the effort as “just” setting it up the usual way.
Either that bites you sooner or later, or you're lucky and grow; suddenly, you're a larger organisation, and there are way too many moving parts to start from scratch. So you do a half-hearted attempt of creating a backup strategy held together by duct-tape and hope, that kinda-sorta should work in the worst case, write some LLM-assisted documentation that nobody ever reads, and carry on. You're understaffed and overworked anyway, people are engaging in shadow IT, your actual responsibilities demand attention, so that's the best you can do.
And then you've grown even bigger, you're a reputable company now, and then the consultants and auditors and customers with certification requirements come in. So that's when you actually have to put in the work, and it's going to be a long, gruesome, exhausting, and expensive project. Given, of course, that nobody fucks up in the mean time.
I can go back to code I wrote months or years ago, and assuming I architectured and documented it idiomatically, I takes me only a bit of time to start being able to reason about it effectively.
With infrastructure is it a whole different story. Within weeks of not touching it (which happens if it just works) I start to have trouble retaining a good mental model of it. if I have to dig into it, I'll have to spend a lot of time getting re-acquainted with how it all fits together again.
Turns out some of the software running on it had some weird licensing checks tied to the hardware so it refused to start on the new server.
It turns out that the company that made this important piece of software doesn't even exist anymore.
This is around the time when you call that one guy on your team that can reverse engineer and patch out the license check.
This is why I like docker, if you keep the sources, you recover no matter what (at least until the "no matter what" holds water)
my understanding is that docker would not have helped in that scenario
This all got stored in the cloud, but also locally in our office, and also written onto a DVD-R, all automatically, all verified each time.
Our absolute worst case scenario would be less than an hour of downtime, less than an hour of data loss.
Similarly our dev environments were a watered down version of the live environment, and so if they were somehow lost, they could be restored in the same manner - and again, frequently tested, as any merge into the preprod branch would trigger a new dev environment to automatically spin up with that codebase.
It takes up-front engineering effort to get in place, but it ended up saving our bacon twice, and made our entire pipeline much easier and faster to manage.
I think this is an outdated view. In modern enterprises DR is often one of the most crucial (and difficult) steps in building the whole infra. You select what is crucial for you, you allocate the budget, you test it, and you plan the date of the next test.
However, I'd say it's very rare to do DR of everything. It's terribly expensive and problematic. You need to choose what's really important to you based on defined budgets.
"No, Restore is" I would say to stunned faces...
most companies started rebooting the mainframe every six months to ensure they could restart it.
It went surprisingly well despite having stayed 15 years in the old DC without rebooting. They were super scared of exactly the case you described but except for some minor issues (and a lot of cussing) it was OK.
This is why I reboot my server from time to time after having applied patches or made more significant changes, despite the fact that "it should not change anything". This is a good moment to realize that it did change something and you have the opportunity to fix the issue while it I sfresh in your mind, and possibly with more time.
I'm curious about how you got in the door here. Very cool, but isn't healthcare IT notoriously cagey about access? I've had to do PHI training and background checks before getting into the system at my (admittedly only 2) PHI-centered jobs.
Granted, if it was such an emergency, I could see them rushing you through a lite version of the HR onboarding process. Did you have a connection in the hospital through whom you offered your services?
I volunteered to help because I knew that even broadly planning the recovery, evidence preservation etc. would be completely beyond the capabilities of the two IT folks (they were extremely nice and helpful, and glad that there was someone to help).
I was there to draw things on the board and ask the questions that will help to recover. I would not have (nor want, not have the need) to access patient information. This is something I warned them about early in the process, as the chaos was growing.
You need to imagine a large hospital completely blocked, with patients during an operation being stabilized and driven away.
I am used to crisis situations and having someone who will anticipate things you do not think about (how to communicate, how to reach prople having planned procedures, who does what and who talks with whom) is a useful person to have before the authorities kick in.
My wife had a planned operation that morning and I was on site when the ransomware hit, it is just this. Nothing James Bond like, just sheer luck to have been around.
The hospital made a recovery but it took about a year IIRC
Even the sequencing (recover and secure the network, then the AD, then some Tier-2 apps etc.) was something they were not ready for. I cannot blame them - the way these things are managed is really messy, with no clear responsibilities beyond the everyday operations.
My hope is that the continuous attacks on the national infrastructure (such as hospitals) will build a more coordinated and homogenous approach. This would be a great lesson learned.
Half of the work is to know what you need, the other half is to know how you do it, while the third half is to cope with all the undocumented tinkering which happened along the way. So in that regard, starting from scratch can be acceptable, as long you are not starting from zero, and can build up on the knowledge and experience of the previous run(s). I mean, there is a whole gaming-genre about this, which is quite popular. And usually you have the benefit that you might be able to fix some fundamental failures which you had to ignore because nobody wanted to take the risk.
Now it's simply become part of my engineering hygiene - as natural and effortless as brushing my teeth.
Actually drilling your DR is also crucial. If you never put it to the test, your documentation isn't worth the paper it's printed on.
In fact the last few years I've been thinking about ways for these systems to rebuild themselves on a continuous basis. Eg. I'd love a smartphone that competely restores itself from backup every night, even to brand new identical hardware, including secure element artifacts (either via private keys I securely control or reregistering everything in an automated fashion), with no user-noticeable impact.
Imo, nix is more finnicky but more of a complete solution than ansible.
Um, sorry but what do you mean ?
The problem is environments like hospitals, who'll "cost center" their IT department to death, where even the most seasoned pro has no chance to ever do the right thing. There should be liability at the board level. There never will.
- daily backup locale + remote (blackbaze with 60 readonly retention strategy, separated bucket by service)
- monthly offline backup
- a preprod server where my users can restore entiere environment for testing purpose (CI)
in case of full house fire, i can be back online in an working day.
PS: i have only some TBs of data so quite easy to do.
How did they prevent threat actors presenting themselves as volunteers, were you vetted?
A far bigger risk is accepting incompetent volunteers if anything.
TBH your mistake was only running one layer of virtualization. What I do on my home setup is run a docker in a VM in a VM in a docker in a docker in a VM in a docker in a VM in a VM in a docker. This, I feel, ought to be the minimum level of indirection and virtualization in any technical configuration in perpetuity. Anything less is bush league and prone to errors.
Sure it can help, but it's just not a one fix solution people thing. If you want a good test of your IAC, just provisioning a brand new environment first time using only your iac.
The second rule of IAC club is that you do not hand modify your infrastructure.
Huh? This is a strange assumption to make. Is your premise that IAC can't ever be truly reproducible?
If you are modifying things manually then you're not doing IAC.
What I meant I that I do not have the kind of setup a lot of people show: a DC-grade self, with a U2 switch etc. I have an old server, my ISP box, a UPS, a switch and maybe something else I forgot. But since the server runs both Home Assistant and Pi-hole, it is critically important.
OTOH this criticality allows me not to invest too much in monitoring: I have family and friends yelling immediately when something is down :)
DeMars launched, and procurement basically stopped for a year. Only the items my friend was in charge of remained in stock, through out the launch/roll-out process.
Switching to a new system; even when it is for the better, is a painful, expensive process.
The company that I worked for, did a successful transition to SAP, but it took about two years, and a lot of butthurt.
From what I've been told, this is actually supposed to be a selling point of SAP: They have built tools to fit the processes of the industry leaders, so by buying into SAP, you're buying into the winning way of doing business.
I am not endorsing this opinion or making a claim regarding its veracity, just stating that that is what I have heard.
It's a bit surprising that we don't have that feature as a requirement for most IT infrastructure. It would make it so much more usable.
"Understandable and fixable" depends more on the complexity of the application rather than the fact it's in Excel.
Most of the projects we did in consultancy dev, was turning that one critical excel sheet nobody but 'the excel guy' understands into a simple to use web application, so that everybody could use it and the business won't explode when mr. excel would leave the shop.
Saved to someone's desktop, or some random directory no one knows about.
Probably also depends on the complexity of the orders and workflows.
As an old software engineer, I can say with certainty that software engineering is a very, VERY wasteful practice. We could all be running Windows 3 right now, DOS, or some old Unix. The overhead involved in making actual advancements shows our slow progress as a species, and that we’re in a thread discussing a drone manufacturing facility being blown up in a war and how much that matters.
I think the natives had it right to live off of the land peacefully, and if anything to devote full time on science to determining what we do to help life survive in the universe.
I can't agree with you. People have got their human mind as a result of ever increasing and self-inflicted costs driven by a competition among males. They developed minds to play politics and they came to a point when 20% of metabolism of human body was devoted to its brain.
The result of such a wasteful way to spend their energy resources? Humans colonized all the Earth, drove to the extinction almost all big animals, and now there are as much humans on the Earth as mosquitos. Looks like a win, doesn't it?
These things go off the rails sometimes. Just today I've found a new example to it:
highlanders who had practiced brutal initiation ceremonies “in which they were forced to drink only partly slaked lime that blistered their mouths and throats, were beaten with stinging nettles, were denied water, had barbed grass pushed up their urethras to cause bleeding, were compelled to swallow bent lengths of cane until vomiting was induced, and were required to fellate older men, who also had anal intercourse with them” gave them up after only minimal contact with outside disapproval. Some later told anthropologists they felt “deeply shamed” by their treatment of their own sons and were relieved to stop.[1]
The waste of resources into useless things doesn't lead to good outcomes each time, but I believe that software engineering will lead to something. I'm not Jesus, I can't predict exactly what the beneficial results will be, but at least I can point to a growing ability of engineers of handling complexity. It lags behind their ability to create complexity, but still it grows.
[1] https://www.astralcodexten.com/p/book-review-arguments-about...
I swear this is SAPs main business model
Just endless consulting bills to set it up then fix it when it's delivered in a broken state.
Even accounting systems are able to usually run fairly independently.
It’s not that IT and business and manufacturing support software engineers don’t help, but they aren’t necessary, especially if they’re just making the same thing over and over.
I visited Russia a few years ago. Commercially, they have all the same technology we have (for me, in the UK). Like us, they outsource most of their manufacturing to China, but internally they produce software equivalent to (or to be honest greater than) what we produce. The difference seems to be that a lot of Russian software, websites and apps are more local, which gives the illusion that it's not as good. Google is multinational, whereas the equivalence Yandex sticks to Russian and Slavic language countries. I was actually quite surprised to see in some areas they are ahead in digitising things (government services, payments). I expected the opposite.
Whatever software you can think of originating from the US, UK, or wherever, Russia has an equivalent. The major difference isn't the technical ability, but the commercial and cultural reach of that technology. Most of the world is happy to use Facebook, except Russia (and some others) who uses VK. We don't use VK, because it's Russian and we already use Facebook. Google, Facebook, Twitter, Uber (all artificially high value commercial products) have Russian equivalents. Sometimes they are even combined into one (Yandex has an Uber-like service within it). And when it comes to hardware, none of us are particularly strong with that. We all designate that to China, who sells it to all of us equally.
Whenever we hear about cyberwarfare, cybercrime and exploits, we usually pin it on Russian/Chinese speaking hackers. Russia seems to have better primary, secondary and tertiary education in computing, and, like the rest of Eastern Europe, produces many of the better programmers (something you can see in open source communities). From discussions with Russians, the level of maths, science and computing education is higher at a younger age than it was for me in the UK. Quite a lot of what would be A-level (18) Maths in my country was taught at Russian secondary school level (16).
In warfare, Russia has made fools of themselves in Ukraine, but on the other hand war is (sadly) the greatest contributor to military evolution. We see that with the introduction and evolution of drone warfare. Our UK Challenger tanks have been disabled and destroyed by far lower cost drones. All the technology associated with that (comms, jamming, avoiding jamming, self-targeting) is being rapidly developed by both Ukraine and Russia on the battlefield right now.
Where exactly would a decade back put them, technologically speaking?
Western support to Ukraine has been a real joke - https://carnegieendowment.org/europe/strategic-europe/2025/0...
So the support from Western countries is enormous, considering all these aspects.
[1]: https://fr.wikipedia.org/wiki/Logiciel_unique_%C3%A0_vocatio...
You could also be making surgical parts that help save lives.
Overall though, I think I’d rather be making nice practical furniture that hopefully people would never throw away. While I support people that want to protect, war is horrible.
I was acquired by a company that was working on Sales Force integration for 3 years, I left before it was fully functional.
They had 4 full time devs working on Sales Force, meanwhile we had built the entire company in a year with 4 devs.
Is this sarcasm?
Drones have revolutionized reconnaissance, sabotage, and munitions interception. Relative to their material cost, they can be terrifically destructive, and with the advances in image recognition in the past decade some are able to operate even when affected by electronic signal jamming. This is some very cyberpunk shit going on right now.
This was obviously a very high-value target, and Ukraine has shown themselves again to be masters of asymmetric warfare: taking out a sizable chunk of Russia's long range bombers using drones smuggled across Russia, and now impacting one of the centers of Russia's drone manufacturing. It is difficult to see how the war will end, but it is clear that Ukraine is not about to stop fighting.
War didn't end the first time man invented the longer spear; defenses adapt.
They could be using version control for their software with every developer having all of the software they have developed for their products git-cloned to their development machines. Assuming a modest development team working with version control (who doesn't), then you do have to wonder if they have lost the crown jewels. I suspect not.
It is going to be a similar situation with everything else such as CAD files. People will have local copies because it is quicker to work that way.
As for the company emails and general office files, sure they might have lost lots of that, but that isn't going to be the end of the world.
The website is also part of the company and you would expect the elite hackers to have taken that down but no they have not, that works just fine.
Then there is the product itself. If you have been following the war closely then you will know what drones are in use at a given time. We might not get to know all of the drones as well as the heavy hitters, however, the name of this company is not something that the keenest watcher of the SMO will be familiar with. It is not as if they have shut down Geranium 2 production, is it?
As for yourself, and how you write, is that ChatGPT speaking?
The reason I ask is that we all know about things such as version control so I wonder if there is common sense or ChatGPT going on with your comment.
With the hacks that Snowden, Assange and their ilk participated in, we had stuff uploaded somewhere for the world to see. In this way it was self evident that stuff had been exfiltrated.
In this instance we can assume the drone company are going to deny everything. However, if we had some of their trade secrets uploaded somewhere then a data breach could be considered plausible. Or a recorded screen cast of the hack.
However, the intended audience for this story doesn't care about hard evidence, they just need a morale boost, and belief trumps reason on these situations.
My school history teacher taught me how to look at evidence and it is not rocket science. Hence why Ukraine is like an intelligence test nobody thought they needed. If people can't do critical thinking about some war that has been on the news for more than three years, how are they supposed to do science or anything else that needs critical thinking?
Not even that. The new hotness are the fiber optic cable ones that don't even use radio signals, that's some scary stuff.
It is possible that FPV drones are showing up as so important because Russia is committed to a disgusting meat sluice of fodder to achieve its marginal territory gains.
Most countries don’t have the appetite for those kind of losses. Most countries, frankly, don’t have the audacity to set these kinds of war aims.
I predict they won’t matter too much to the war meta. At least not so much as cheap long range jet drones which are also becoming significant here.
The question is how useful would these things be if your opponent wasn’t blindly rushing forward?
The role of this tech is effectively a dynamic minefield more or less
Of course, that was said purposefully, and may not reflect the truth at all.
But still, the thought that that is security for some (and I am sure it is for someone, somewhere) is kind of an extension of security by obscurity that is scary.
If you never bootstrap from zero (nor simulate this) then your systems probably have cycles in their deployment dependencies. Your config pusher is deployed from Jenkins/Puppet/Ansible but 2 years ago someone made Jenkins dependent on the config pusher for its own config. Now you cannot just deploy these systems in order, you have to replay the history before that change.
Bootstrapping from zero will never be easy and will always take some time. I don't think you can prepare your way out of this, short of preparing a fully redundant, fully separate secondary infrastructure.
Testing this reliably is difficult, though, and often these procedures and their documentation is outdated.
What you can do is to have a sandbox environment where you periodically do a full setup exercise from a prepper disk. Conceptually it's not that different from testing backup recovery (ok, most companies neglect this too, so maybe you have a point :) ).
Which gives me an idea for an "Ask HN"... Edit: submitted https://news.ycombinator.com/item?id=44582994
Other way is to build a stripped down version of rustc only capable of compiling latest rustc, e.g. using https://github.com/dtolnay/bootstrap
Great post on bootstrapping and its problems: https://bootstrappable.org/
Actual project capable of bootstrapping Linux system from scratch: https://github.com/fosslinux/live-bootstrap
Construction industry have products with typical lifetime of 50+, in some cases multiple hundreds. Computing and digitalization are hot topic now and for the past several decades with various buzzwords (probably 'digital twins' is the newest one) however when I am unable to open construction design files made in the beginning of my career less than 30 years ago due to obsolescence for various reasons then all those efforts seem for nothing eventually beyond immediate needs. Good old outdated 2D drawings seen as unfeasible practice might save the day in the future (... perhaps, assuming that current pdf files could still be opened some decades down the line, as that is a common 'digital paper' approach nowadays, actual physical world paper are used less and less).
Deliberately blocking the supposed enemy from hearing you does strike me as irrational, though. The mere fact they're doing Russian censors' job should probably make them recheck if they got anything wrong in their decision process, just in case.
>that clearly doesn't change the situation in Russia
Giving up is the easiest thing to do. Last time some people did, it was blamed on stereotypes like their "learned helplessness" and "fatalism".
Some non-Ukrainian do as well, seemingly with no rhyme or reason, I run into this so routinely that I have an entire thread: https://mastodon.social/@grishka/111934602844613193
Somebody saved it four hours ago.
The people who put together the doctrine on 4th Generation Warfare talked about the blurring of civilian and military. Rules of engagement gets fuzzier.
Same do Ukrainians, don't they? More over, long before they killed civilians and defenders in Iraq and Afghanistan on Americans invitation. Then left without even saying 'sorry'. Since 2014 they were shelling Donetsk just for fun, killing people at random. So, it's more complicated than you'll find in western mass media. Especially in EU where full picture is illegal.
Russia consistently and deliberately targets civilians. There is no "both sides" here.
There news on Russian side daily of Ukrainians doing exactly this, deliberately targeting civilians. Also usually their own non-combatants who are trying to surrender. This is war crime.
There are dirty tactics in this war which western public will learn about later. For now it's given a rosy optimistic picture approved by Zelinsky office. That's how 'Support Ukraine' is pushed on them. In fact it's 'support the war', as Ukrainians are dying in big numbers. By the way, official number of civilians killed 3 years is lower that in Gaza in 3 months.
The article might be a collage of several other articles, and they didn't check for consistency.
I would love some other term for the aligned side people in cyberwarfare, sort of "cybersoldier" or "networkmilitia", not already somehow cliched in some film. "Cyberactivists" sounds like online protesters (in facebook and such)
The people who illegally obtained classified information to leak to WikiLeaks have made a political impact: https://www.washingtonpost.com/technology/2024/06/26/wikilea... as well as reprisals in the form of arrests and prosecutions.
We also call Greenpeace "activists", but they also employed violent direct-action in their efforts against whaling.
Carl Icahn calls himself a shareholder activist, and many people still consider him a vulture capitalist.
depends who's side you are on
It just says "Хакеры" (hackery, hackers)
On the other hand (and I'm not defending a drone company), anyone that has a business should know by now that ransomware (with our without deletion) is a real thing, and it's not an 'if' question, it's a 'when' question.
I have never worked with/for a Russian company, so it would be interesting to hear/read from someone who has, how 'well organized' are they? GRC-wise. Assuming that someone would run the COBIT framework on them (Russian companies), would the 'average' be 'ok' or it's a big mess (kinda like working for an EU company in early 00's)?
This is not a real reason. This explanation hides the real reason: Russia is a valuable geopolitical partner for USA. Regarless who are in power in USA - all presidents tried to make deals/contacts with Russia.
There is no value for USA in getting Russia loose this war, have internal instability or split in 20-ish national states.
USA wins more from russia being as it is today with all it blood, suffering and hundreds of thousands of deaths caused by the regime thrive for survival.
Actually USA are afraid to push too much to cause internal issues in Russia. And russian ruling class knows that.
There are ticket sales systems for people being transported, but much is freight trains, and if there was an easy way to disrupt that, you can be sure that Ukraine would've done it by now, because the Russian military heavily depends on rail-based supplies.
So the foreign intelligence services gave them a button push so it's not a direct cyber war on Russia.
meanwhile, russian intelligence services have already directly attacked nato countries, with barely any real deniability.
Or lets start talk like adults and talk about current situation and how nations behave now. russia is the definition of evil of these days. I know US government focuses heavily on china for whatever reasons (I guess because its obvious they are #2 and moving up, russia is barely in top 10 in actual capabilities if we ignore nukes and and since they threatened to use them at least 100x in past few years we can safely ignore them for usual conflicts).
Don't hate the messenger, this is how they behave and have painted themselves consistently, heck they are even proud of it in typical russian redneck style if you follow their media a bit.
> Wars aren't, and really never have been, won by blowing stuff up.
That's a huge simplification. Blowing stuff up in a strategic way can certainly help win a war.
https://de.wikipedia.org/wiki/Hackerangriffe_auf_den_Deutsch...
Bulgaria: https://www.theguardian.com/world/2022/aug/01/arms-dealer-10...
Poland: https://www.theguardian.com/world/2025/may/12/poland-to-clos...
And UK.
Plus a million cyberattacks against all sorts of infrastructure.
So I don't see why it would be the case that Ukraine could not have done this by themselves. They have done previous attacks by themselves. I don't see why that would be the case.
It would kind of be like saying, "Oh, if Russia does a cyberattack, it can't have been them acting alone. It must have been China that gave them the stuff to just press a button."
It's not speculation that Ukraine is being assisted to a huge degree.
One angle of that assistance: https://www.nytimes.com/2024/02/25/world/europe/cia-ukraine-...
The Russian regime (and apparently a lot of Russians) deem Ukrainians as an inferior ethnic group - they call them "little Russians".
Ukrainian authorship would mean:
- Ukrainians are competent people with agency (which they are of course, for lots of reasons) - this plays into ethnophobia;
- their government, military, etc, is competent, functional with agency - this plays into government legitimacy;
- Overall, in a lot of instances, the Russian government is incompetent, even more incompetent than the guys their propaganda has been trying to paint as corrupt, incompetent people who are being manipulated.
That's why a lot of time Russian propaganda trys to spin Ukrainian wins as "NATO/CIA/MI6/external agent did this".
For example, they tried really hard to bend reality to remove the credit for the Ukrainian drone operation that destroyed a lot of bomber jets, saying it was planned and executed by CIA, MI6, Israel, etc [0].
This is what we're dealing with here: massive ethnophobia and propaganda.
So in their propaganda, Ukraine can't be competent and stand on its merit, because that would mean they're not inferior people and that they have agency.
You should always be wary of someone making these claims without any evidence.
[0]https://uacrisis.org/en/rospropaganda-zaplutalas-v-pavutyni
I think Ukrainians (and Russians as well) aren't tech illiterate. They are (both) more than capable in this matter.
What foreign intelligence services ? Also if you think there isn't a constant barrage of attacks coming from everyone, you're not ready for the real world.
That position sounds very weird.
I think the most likely explanation is it's the Ukrainians defending Ukraine against Russia's unjustified invasion.
This is a silly expression for written text, since I always read both tomatoes as 'tomato', before realising the intention. :)
Fun fact, I was internal auditor in a bank (I will not specify the year(s) for safety/privacy). We did the due diligence and ended up buying a Ukrainian bank. Part of the 'collections' was really to smash people's faces. Believe it or not. But sure.. you know best.
My only qualm with them is their not so great support for gay people, but then during the war ofc the party line is now they love their gay soldiers. Would have been nice to see more action around that beforehand but I get it. Even other first world countries still have plenty of problems as a gay person, especially gay men.
Do you have any evidence that it was foreign intelligence services?
I suppose it could be used sparingly but Ukraine would have no way of knowing when to use it. Perhaps a Bluetooth or whatever else the drone has on board "keep away" beacon for vips.
The real enemy is QA. Don't want it misbehaving during a virtual test flight.
> LLC “Gaskar Integration” (Gaskar Group)—one of the largest UAV manufacturers in Russia—has just been penetrated right down to the tonsils in the course of demilitarization and denazification.
> VO Team, together with the Ukrainian Cyber Alliance (https://t.me/UCAgroup) and another very well‑known organization whose mere mention makes the vatniks’ bottle‑openings burst (https://gur.gov.ua/), carried out large‑scale operations: we seized all of Gaskar Group’s network and server infrastructure, gathered valuable data on their current and prospective UAVs, destroyed that data, and knocked the entire infrastructure offline.
> By the way, from the information we obtained, the PRC is helping Gaskar Group with production and staff training. China transferred technology for the newest UAVs—technology that is now in our hands .
> VO Team focused on wiping out the production complex’s infrastructure. On‑site we erased more than 250 hosts (4 ESXi servers, 46 virtual servers, 200+ workstations) and bricked about 20 MikroTik devices. In total we destroyed 47 TB of valuable data at Gaskar Group—including 10 TB of backups—and disabled all production and auxiliary systems.
> The scum at Gaskar Group have the blood of hundreds of Ukrainian children, women, and elderly on their hands. That’s why we went after this target with special zeal. We now possess the lists of ALL employees, their home addresses, information about their family members, and much more… We’re in your home computers and phones—we’re everywhere . Not a single bastard from Gaskar Group will escape responsibility!
> The sword of Damocles already hangs by a thin thread over your heads. It’s too late to spew excuses like “we’re apolitical” or “we were just making money”….
> The whole world can see that the so‑called Russian Federation has strategically lost everything. Defeat and collapse of that unwashed entity are only a matter of time. VO Team is collecting data on everyone involved in Putin’s criminal war—the deaths of our children, mothers, and all Ukrainians. Retribution is inevitable and is drawing near!
Well, this is quite the interesting tidbit. Thanks for posting the translation.
They should have checked the source codes and added some changes to make drones unpredictably unreliable
"Oh this totally innocent code change? Oh look it makes the gps act weird if longitude is between a certain range how weird"
The main claim for this myth is the sacrifice of Coventry during the Battle of Britain, but as far as I'm aware, historians are in general agreement that Ultra was unable to ascertain that Coventry was the target before the raid took place.
https://en.wikipedia.org/wiki/Coventry_Blitz#Coventry_and_Ul...
Look at successful cyber campaigns like stuxnet or an actual hardware sabotage from Israel. The attacks were dormant until they were ready for maximum effect. Randomly disabling a production site, without a strategic context, is going to be an isolated win, or an operational victory.
I remember reading some articles about the pentagon being a bit upset at some of the strategic decisions of Ukraine's armed forces where they often push for morale boosting moments at big costs(i think 2 years ago they spent lots of resources to get a strategically irrelevant town). And honestly this is also what it looks like: You dont see a coordinated attack but spurious disconnected events. I think when you are gasping for air you hold on to anything you can, but still the goal is to win, not just look like winning.
It's a good idea, I just think if the goal is to stop the drones working, what better way to do that then to destroy the manufacturing capabilities as often as possible?
Even in the case you describe, you're allowing them to have drones and still do some damage.
- know your threats
- assess your risks based on identified threats
- backup 3-2-1 strategy (3 copies of your data on 2 independent storage places with 1 copy offline and offsite)
- "build the world from scratch" plan with the assumption that all infra is completely and irreversibly destroyed.
- assume you have already been hacked but you don't yet know about it. Build your indicators of compromise based on that simple assumption.
Observing how some "groups of people" act in a totally ignorant fashion is amusing.
https://en.wikipedia.org/wiki/Disinformation_in_the_Russian_...
There's also just endless small stuff (shorts/tiktoks/cam footage) on social media (reddit) that really does not pass the sniff test.
I think what Russia is doing is terrible, I am not defending them at all. I am just allergic to bullshit, and there is plenty of smelly things happening on the Ukrainian side, though of course I recognize the Russians are especially bad in this regard.
I was not very clear, but I meant Ukrainian intelligence services claiming operational success where there was none. It's also interesting that this Wikipedia entry appears devoid of UA false propaganda after 2022. I wonder if they realized that this was not a good Wiki entry on which to appear.
what i ultimately care about is manipulation, because manipulation and disinformation erode democracy, and it's overwhelmingly done by the rich and powerful and at the expense of the working class. there are endless billions of dollars getting funneled into the military industrial complex around ukraine, and the more americans align with ukraine, and the more americans can feel invested and interested in the war in happy-feel-good-ways (like having heroes and "fuck russia" moments) the more americans are okay with their tax dollars getting spent this way. whatever machinery is at play here has very successfully captured the support of a massive part of the American left, and the same people you see protesting about the environment are the same people you see waiving ukraine flags and being manipulated into suddenly being pro-war despite being against things like the war in iraq.
billionaires continue to make their billions, people continue to believe what they read on reddit and watch on corporate news, and the narrative is always things that aren't class consciousness.
I'm very dubious that there would be such an amount of “critical” data pretty much anywhere, besides the banking and insurance sector. And particularly not at a drone manufacturer.
If you focus only on data with high-uptime requirements, no probably not 50 TB.
If you include low-uptime requirement but low-replaceability stuff like all the products' mechanical, electrical and software designs, documentation and artifacts? Easily 50 TB.
For all of this to have meaning it has to have a fall of USSR kind of impact at some point, otherwise we just strengthened one of the world's most dangerous state.
Authoritarian governments always fail, because they get used to achieving everything by simply ordering it to be achieved, while the laws of physics don't obey orders.
Meanwhile they're murdering how many of their own soldiers per day?
Definitely one of the companies that everyone has heard of before. No need to mention any of their brand or product names, they're that famous.
$3 million revenue in 2024.
I'm sure we'll hear more about the epic defeat of this major military supplier in the future.