Ukrainian authorities and private researchers reported a coordinated cyber campaign against Ukraine that combined DDoS attacks, fake SMS alerts, bomb-threat emails, and suspected network manipulation to disrupt government and financial services. On 15 February 2022, attacks struck Ukrainian banks, government entities, and DNS servers for the gov.ua zone, temporarily affecting access to many state websites. CERT-UA said the activity went beyond ordinary cybercrime and included an information-psychological destabilization component, while Unit 42 noted the United States and United Kingdom attributed the initial DDoS wave to Russia’s GRU. CERT-UA also described suspicious BGP activity involving a PrivatBank-related prefix and said more than 30,000 relevant IP addresses tied to DDoS-for-hire infrastructure were shared through MISP.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
A March 7 update cited by Zscaler said DanaBot affiliate ID 5 stopped targeting the Ukrainian Ministry of Defense webmail server and began DDoSing IP address 138.68.177.158, which passive DNS linked to invaders-rf[.]com.
Zscaler reported that DanaBot affiliate ID 5 used the malware's download-and-execute capability to deploy a Delphi-based HTTP flood tool against the Ukrainian Ministry of Defense's webmail server.
Ukrainian authorities reported that a massive DDoS attack on 2022-02-23 targeted multiple government and banking websites, causing some systems to become unavailable or operate intermittently. The State Service of Special Communications and other national cybersecurity bodies said they were countering the attack, rerouting traffic to reduce damage, and coordinating incident reporting through CERT-UA.
Unit 42 reported that both the United States and the United Kingdom publicly attributed the initial February 15 DDoS attacks against Ukraine to Russia's Main Intelligence Directorate, the GRU.
360Netlab said attacks against Ukrainian .gov.ua sites increased in volume and intensity and peaked on this date, with botnet commands observed against targets including www.szru.gov.ua, bank.gov.ua, www.president.gov.ua, mova-ombudsman.gov.ua, fisu.gov.ua, and od.tax.gov.ua.
CERT-UA investigated a series of incidents on this date including fake ATM-outage SMS messages, bomb-threat emails to financial institutions, DDoS attacks on banks and government entities, DNS-targeting attacks affecting gov.ua, and a suspicious BGP announcement involving a PrivatBank-related route. Unit 42 also described this as the start of a DDoS wave affecting Ukrainian government organizations and banks.
360Netlab observed DDoS attacks against Ukrainian government websites beginning on this date, marking the start of a broader campaign that later intensified.
360Netlab reported that the Mirai command-and-control server 5.182.211.5 became active on this date and was later used exclusively to target Oschadbank-related infrastructure.
360Netlab reported that DDoS attacks against Russian .ru government and military websites started on this date and were more numerous than those against Ukrainian targets.
Unit 42 reported that on this date a phishing page impersonating a cloud file storage service targeted a Ukrainian state administration employee and pre-populated the victim's gov.ua email address.
Unit 42 observed a second round of website defacements against Ukrainian government organizations on this date. The defacements linked to a 'Free Civilian' onion site advertising alleged databases of Ukrainian citizens' personal data.
Unit 42 reported that a HermeticWiper sample named conhosts._exe was uploaded to a public malware repository from an organization in Kyiv, Ukraine. Early reporting indicated the wiper had been deployed against a Ukrainian financial institution and contractors in Latvia and Lithuania serving the Ukrainian government.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cert.gov.ua
Open sourcezscaler.com
Open sourceblog.netlab.360.com
Open sourcecip.gov.ua
Open sourceunit42.paloaltonetworks.com
Open sourcecert.gov.ua
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.