cybersecurity

Who Is Attacking Ukraine: Verified Actors, Motives, and Methods

Who is attacking Ukraine addresses a core question at the intersection of warfare, technology, and international security: which actors are carrying out destructive operations a...

Mara Ellison
Who Is Attacking Ukraine: Verified Actors, Motives, and Methods

Why this question matters and how we answer it

Who is attacking Ukraine addresses a core question at the intersection of warfare, technology, and international security: which actors are carrying out destructive operations against Ukrainian institutions and infrastructure, what do they hope to achieve, and how do observers know this. This evergreen explainer separates verified evidence from speculation, outlines the primary threat actors—state and non-state—and describes common tactics, objectives, and indicators. The aim is a durable reference that reflects current understanding and remains useful as tactics and command relationships evolve.

Attribution in cyberspace and conflict: what it means and why it is hard

Attribution is the process of determining who carried out a specific action with confidence grounded in evidence. In cyberspace and hybrid conflict, it is rarely instantaneous and can involve technical analysis, intelligence sharing, and geopolitical judgment. Reliable attribution typically rests on multiple, overlapping indicators such as digital fingerprints, infrastructure reuse, operational patterns, and human intelligence. This section explains how analysts reach conclusions rather than asserting unproven claims.

How analysts reach conclusions

  • Technical indicators: IP addresses, malware signatures, command-and-control patterns, and toolchains are examined for links to known actors.
  • Operizational patterns: timing, targets, and messaging are compared to historical behavior.
  • Intelligence and corroboration: allied intelligence, intercepted communications, and leaks can support or challenge technical findings.
  • Public声明 and admissions: claims of responsibility are evaluated for consistency with capability, motive, and evidence.

State actors confirmed or assessed by defenders and analysts

Defenders and researchers routinely attribute significant operations to specific states based on technical and intelligence evidence. These assessments inform responses and public reporting. Below is a compact overview of the most frequently cited actors in current public reporting.

Russian Federation

Russian state-directed actors are consistently assessed to be conducting cyber and information operations against Ukraine. Activities span government missions, contracted actors, and proxies. Objectives include undermining trust, disrupting critical services, and degrading command, control, and communications. Methods observed include destructive wipers, ransomware, and influence operations. Public reports from governments and researchers regularly document infrastructure and tactics linked to Russian services and units.

Belarus

Belarusian authorities have enabled Russian operations from their territory and participated in regional coercion and espionage. Cyber operations often transit or originate from Belarusian infrastructure, leveraging shared networks and lax oversight. The state is assessed to support information operations and technical reconnaissance that benefit Russian aims.

Iran

Iran is assessed to conduct cyber operations against Ukraine, primarily to project regional influence and test capabilities. Reported activities include destructive wiper campaigns and data theft aligned with geopolitical interests. Some services act as contractors, offering technical support to state priorities. Motives combine regional rivalry, financial goals, and strategic positioning.

China

Chinese actors are assessed to target Ukrainian infrastructure for intelligence collection and potential future disruption, reflecting broader global patterns. Priorities typically center on espionage and preparation for possible contingency operations, rather than direct kinetic support. Attribution often relies on characteristic malware families, infrastructure, and targeting profiles.

North Korea

North Korean actors are assessed to engage in financially motivated cybercrime against Ukraine to fund state programs. Operations are often routed through intermediaries and focus on cryptocurrency theft and laundering. While primarily profit-driven, these activities can indirectly support wider objectives and reduce pressure on state resources.

Russia-linked non-state and proxy actors

Organized criminal groups and ideological volunteers linked to Russian objectives are assessed to conduct ransomware, data theft, and disruption for profit or political messaging. While not formal military units, their actions align with state interests and are frequently laundered through criminal payment channels. The boundary between criminal and political activity can be fluid in hybrid conflicts.

Non-state and proxy actors operating in or affecting Ukraine

Non-state actors amplify the impact of state operations, offering deniability, specialized skills, or ideological commitment. Their role is often to supplement state capabilities, test new techniques, or monetize access to compromised systems. Below are the most relevant categories for Ukraine in current assessments.

Cybercrime syndicates

Groups focused on ransomware, data theft, and banking fraud routinely target Ukrainian organizations. They exploit vulnerabilities in remote access, exposed services, and weak patching. Their campaigns can cause widespread disruption, especially when double extortion or third-party supply chain compromises are used.

Hacker collectives and ideologically motivated volunteers

Hacker groups and volunteers may support one side or conduct independent operations for reputation, ideology, or profit. Some align loosely with state narratives without direct coordination; others engage in overt offensive actions. Their impact varies widely based on skill, access, and target hygiene.

Common tactics, techniques, and procedures observed in attacks on Ukraine

Across actors, recurring patterns help defenders detect and respond. Recognizing these TTPs makes it easier to link incidents, identify campaigns, and prioritize hardening. Below is an overview of the most frequently observed methods.

Initial access and foothold

  • Spear-phishing with tailored lures and weaponized attachments.
  • Exploitation of public-facing vulnerabilities in VPNs, email gateways, and collaboration tools.
  • Compromised credentials obtained via credential stuffing or theft.
  • Third-party and software supply chain compromises affecting managed services and SaaS.

Lateral movement and persistence

  • Pass-the-hash, remote services abuse, and legitimate credential misuse.
  • Scheduled tasks, registry modifications, and image file tampering for persistence.
  • Use of legitimate administrative tools (living-off-the-land binaries) to blend in.

Impact and objectives

  • Destructive wipers designed to corrupt or destroy data and boot records.
  • Ransomware and double extortion to monetize access and pressure victims.
  • Data theft and system reconnaissance to support future operations or espionage.
  • Information operations and content manipulation to influence perceptions.

Verified incident pattern summary

The table below synthesizes public reporting on notable attributes tied to attacks on Ukrainian targets. This summary is based on consensus assessments from governments and researchers and reflects understanding as of the latest reporting cycles.

Attribute Verified Detail Source Type
Primary state actor Russian Federation Multi-vendor threat intelligence and government reports
Secondary supporting actors Belarus, Iran, North Korea, Russian proxies Joint statements, indictments, and incident reports
Typical destructive capability Wipers and ransomware causing large-scale disruption Public incident disclosures and forensic analyses
Common initial access Phishing, exploited public-facing infrastructure, compromised credentials Campaign reports and advisories
Persistence methods Scheduled tasks, living-off-the-land binaries, registry changes Malware analyses and detection advisories
Motivations by actor Disruption, espionage, profit, influence, coercion Analyst assessments and court documents

Defenders use layered protections and explicit assumptions that hostile actors may target them because of affiliation, sector, or perceived value. Practical measures focus on reducing the attack surface, improving detection, and rehearsing responses.

Immediate, practical steps

  • Enforce phishing-resistant multi-factor authentication on all remote and administrative access.
  • Prioritize patching for internet-facing systems and disable unnecessary services.
  • Implement robust identity and access management, including least-privilege and conditional access.
  • Segment critical networks to limit lateral movement and protect sensitive data stores.
  • Back up critical data offline and test restorability regularly.

Detection and response practices

  • Monitor for signs of compromise across endpoints, identities, and cloud workloads.
  • Use threat intelligence relevant to Ukraine-related campaigns to tune alerts.
  • Exercise incident response plans, including communication, containment, and evidence preservation.
  • Establish relationships with trusted partners, CERTs, and national reporting centers.

Staying informed responsibly

Information about attacks on Ukraine circulates quickly and can include unverified claims. Prefer official advisories from national cybersecurity agencies, multi-vendor threat intelligence, and reputable security research organizations. Clearly distinguish between observed facts, inferred activity, and unconfirmed speculation when sharing or acting on reports. Responsible communication reduces confusion and supports coherent defensive decisions.

Key takeaways

  • Attacks on Ukrainian targets are attributed mainly to Russian state actors, with support from Belarus, Iran, North Korea, and various non-state actors.
  • Common objectives include disruption, espionage, financial gain, and influence, delivered through proven tactics like phishing, credential compromise, and destructive wiper malware.
  • Multi-layered defenses, strong identity protections, regular backups, and practiced incident response remain the most effective countermeasures.
  • Reliable attribution depends on converging technical and intelligence evidence, not single data points.
  • Staying current with official guidance and verified reporting ensures that responses remain proportionate and effective.

Related Reading

More pages in this topic cluster.

Bristol Airport cyber attack: what happened, impact, and current status

In 2022, Bristol Airport experienced a cyber attack that affected some of its IT systems, including parts of its website and passenger-facing services. This verified explainer o...

Read next
Cyber Deals 2017: A Comprehensive Overview of Major Acquisitions and Trends

2017 was a landmark year for cybersecurity mergers and acquisitions, characterized by record deal volumes and high-value transactions across sectors. This overview examines the...

Read next
Impact Team Hackers: roles, tactics, and measurable outcomes

Impact team hackers are threat actors that explicitly design operations to achieve measurable business, operational, or reputational effects rather than only stealing access or...

Read next