Mapping the Shadow War From Estonia to Ukraine

Evgueni Erchov (Senior Director of Research and Threat Intelligence · Cipher)

Recon Village @ DEF CON 33 · Day 1 · Recon Village

Overview

In this insightful Recon Village talk, Evgueni Erchov, Senior Director of Research and Threat Intelligence at Cipher, delves into the intricate and evolving landscape of Russia's cyber operations, meticulously tracing their integration with kinetic military actions from the 2007 Estonia attacks to the full-scale invasion of Ukraine in 2022. Erchov's presentation provides a critical analysis of how Russia has continuously refined its hybrid warfare playbook, learning from each engagement to develop more sophisticated and impactful cyber capabilities. The talk is particularly relevant for understanding the strategic intent and operational methodologies of a major state-sponsored threat actor, offering valuable lessons for national security, critical infrastructure protection, and the broader cybersecurity community.

Watch on YouTube

Visual summary for Mapping the Shadow War From Estonia to Ukraine by Evgueni Erchov
Visual summary for Mapping the Shadow War From Estonia to Ukraine by Evgueni Erchov

Key moments

  1. 0:00 Introduction to speaker and talk on shadow war
  2. 1:30 Talk goal: Evolution of Russian cyber-military operations
  3. 2:40 Estonia 2007: First Russian crowdsourced cyber operation
  4. 4:20 Georgia 2008: Adding kinetic attacks and BGP hijack
  5. 6:00 Significance of BGP hijacks through Russian infrastructure
  6. 7:50 SORM platform: Russian state surveillance and data retention

Mapping the Shadow War From Estonia to Ukraine

Speakers: Evgueni Erchov, Senior Director of Research and Threat Intelligence, Cipher

Conference: Recon Village

YouTube: https://www.youtube.com/watch?v=y-1_nKM8DRQ

Overview

In this insightful Recon Village talk, Evgueni Erchov, Senior Director of Research and Threat Intelligence at Cipher, delves into the intricate and evolving landscape of Russia's cyber operations, meticulously tracing their integration with kinetic military actions from the 2007 Estonia attacks to the full-scale invasion of Ukraine in 2022. Erchov's presentation provides a critical analysis of how Russia has continuously refined its hybrid warfare playbook, learning from each engagement to develop more sophisticated and impactful cyber capabilities. The talk is particularly relevant for understanding the strategic intent and operational methodologies of a major state-sponsored threat actor, offering valuable lessons for national security, critical infrastructure protection, and the broader cybersecurity community.

Erchov, drawing from his extensive background as a US Army cyber threat intelligence officer and federal agent, illuminates the incremental yet significant advancements in Russia's cyber warfare doctrine. He highlights how initial, relatively unsophisticated Distributed Denial of Service (DDoS) campaigns evolved into complex operations involving BGP hijacks, electronic warfare, and the strategic exploitation of civilian communications infrastructure. The talk underscores the importance of recognizing these patterns of evolution to anticipate future threats, especially as Russia continues to adapt its tactics in an increasingly digital and interconnected global environment.

A key theme throughout the presentation is Russia's methodical approach to integrating information warfare, cyberattacks, and physical aggression to achieve strategic objectives. Erchov also touches upon contemporary developments, such as the use of deepfake technology and novel methods of satellite communication compromise, alongside a fascinating discussion on the "Great Migration of Hackers" spurred by the conflict. This comprehensive overview is crucial for anyone seeking to understand the historical context, current state, and potential future trajectory of state-sponsored cyber conflict.

Background

▶ Watch: Introduction to speaker and talk on shadow war (0:00)

Evgueni Erchov initiates his talk by sharing his unique professional background, which includes serving as a US Army cyber threat intelligence officer and a federal agent, experiences that have deeply informed his analytical perspective on nation-state cyber activities. His current role as Senior Director of Research and Threat Intelligence at Cipher involves extensive work on cyber investigations, including ransomware and business email compromise cases, providing him with a broad view of the threat landscape. The core objective of his presentation is to dissect the evolution of Russia's cyber operations in conjunction with military actions, offering insights into their past strategies and predictions for future engagements.

Erchov sets the historical stage with the 2007 Estonia cyberattacks, which he identifies as Russia's inaugural significant cyber operation. This event was triggered by the planned removal of a Soviet-era statue, which Russia leveraged to incite public sentiment and orchestrate a misinformation campaign aimed at its own populace. Crucially, this operation marked the first instance where Russia successfully crowdsourced cybercriminals to participate in state-sponsored activities, distributing various DDoS tools for public use. The attacks were so severe that they effectively "unplugged" Estonia from the internet for several days, causing widespread disruption to banking services, news dissemination, and international communications, demonstrating the profound downstream impact of cyber warfare.

Building on the Estonian experience, Russia refined its tactics during the 2008 Georgia conflict. While continuing to employ misinformation and crowdsourced cybercriminals, this operation introduced two significant escalations: kinetic attacks on communication towers to physically disrupt internet access, and the malicious use of BGP hijacks. Erchov explains that BGP hijacks allowed Russia to reroute all Georgian internet traffic through Russian infrastructure, granting them full control over communications. He emphasizes the critical implications of such hijacks, noting that under Russian law (specifically the Yarovaya Law), all encryption/decryption keys must be provided to the FSB (Federal Security Service), and all internet service providers (ISPs) and telecom providers must retain metadata for six months, accessible by the FSB without court orders. This comprehensive surveillance capability is further amplified by the SORM platform, a mandatory system for all Russian telecom and ISP licensees, designed for intercepting phone calls, text messages, and internet communications across three phases of deployment.

The 2014 annexation of Crimea marked another significant escalation. Beyond replicating previous tactics, Russia deployed a covert unit to attack Ukrainian telecom providers within Crimea. Simultaneously, Russian ISPs in Crimea were already SORM 3 compliant, having been prepared for the Sochi Olympic Games, further solidifying Russian control over communications. During this operation, Russia also deployed electronic warfare (EW) units, effectively jamming Ukrainian military radio communications and satellite phones, cutting off Ukrainian forces from their command. This multi-faceted approach, combining cyber, kinetic, and EW capabilities, ultimately led to the withdrawal of most Ukrainian units. Erchov notes a peculiar pattern: many of these major Russian military operations (Georgia, Crimea, Ukraine 2022) coincided with the tail end of Olympic Games, particularly those held in China or Russia, an observation he attributes to coincidence but highlights as a recurring temporal marker.

Key Findings

▶ Watch: Estonia 2007: First Russian crowdsourced cyber operation (2:40)

Erchov's analysis reveals several critical findings regarding Russia's evolving cyber warfare strategy and its implications:

  1. Continuous Operational Evolution: A central tenet of Russia's approach is continuous learning and adaptation. With each successive conflict—Estonia (2007), Georgia (2008), Crimea (2014), and Ukraine (2022)—Russia has refined its cyber tactics, integrating new technologies and methodologies to enhance effectiveness. This iterative development makes their operations increasingly sophisticated and harder to counter.
  2. Integrated Hybrid Warfare: Russia consistently merges cyber operations with kinetic military actions and information warfare. From the earliest DDoS attacks in Estonia to the advanced electronic warfare in Ukraine, cyber capabilities are not standalone but integral components of a broader military and geopolitical strategy designed to disrupt, control, and influence.
  3. Strategic Use of Infrastructure Control: The talk highlights Russia's deep control over its own and, when possible, adversary communication infrastructure. The use of BGP hijacks to reroute traffic through Russian networks, combined with domestic surveillance platforms like SORM and laws like the Yarovaya Law, provides the FSB with pervasive access to communications, including decryption keys and metadata, effectively enabling real-time intelligence gathering and control.
  4. Advanced Electronic Warfare Capabilities: Russia has demonstrated increasingly sophisticated electronic warfare capabilities. In Crimea, this involved jamming radio and satellite communications. In Ukraine (2022), these capabilities extended to compromising sophisticated satellite terminals like Viasat and Starlink, showcasing an advanced ability to disrupt modern communication systems crucial for military and civilian operations.
  5. Sophisticated Information Operations: The use of deepfake technology in Ukraine, such as the fabricated video of President Zelenskyy, marks a significant advancement in Russia's information operations (IO). This signifies a move towards more convincing and potentially damaging disinformation campaigns, leveraging AI to create highly deceptive content.
  6. Novel Satellite Terminal Compromise: The method used to compromise Starlink terminals in Ukraine was particularly ingenious. Russian forces reportedly planted malware on captured Ukrainian Android devices, leaving them behind for Ukrainian troops to recover. When these devices were subsequently used to control Starlink terminals, the malware facilitated their compromise, demonstrating a clever exploitation of both physical access and software vulnerabilities.
  7. The "Great Migration of Hackers": Erchov identifies a significant demographic shift in the cybercriminal landscape, dubbed the "Great Migration of Hackers." The war in Ukraine and Russia's partial mobilization have driven an estimated 12 million Ukrainians and 5 million Russians (mostly males under 55) from their home countries. This exodus, occurring in distinct waves, has seen cybercriminals initially relocate to nearby, visa-lenient countries (Georgia, Thailand, Mongolia, Vietnam, Turkey). However, increased scrutiny and changing regulations in these initial host countries, coupled with unprecedented Russian law enforcement actions against cybercriminal groups (even those not targeting Russia), are now pushing these groups towards South America, where visa requirements are lax and money laundering regulations are less stringent. This migration could reshape the global cybercriminal ecosystem and potentially lead to new collaborations, such as with organized crime cartels.

Technical Deep Dive

▶ Watch: Georgia 2008: Adding kinetic attacks and BGP hijack (4:20)

Russia's cyber strategy, as detailed by Erchov, is characterized by a persistent technical evolution, building on lessons learned from each conflict.

DDoS Attacks (Estonia, 2007): The initial foray into cyber warfare involved Distributed Denial of Service (DDoS) attacks. These were largely unsophisticated, relying on overwhelming Estonian internet infrastructure with a flood of traffic. The success stemmed from the sheer volume of attacks, which Estonian defenses could not handle, forcing the country to effectively disconnect itself from the global internet. This demonstrated the power of resource exhaustion as a cyber weapon, capable of isolating a nation and disrupting critical services like banking and news dissemination. The crowdsourcing aspect meant that a distributed, amateur army could be leveraged for significant impact.

BGP Hijacks and Infrastructure Control (Georgia, 2008): In Georgia, Russia introduced BGP (Border Gateway Protocol) hijacks. BGP is the routing protocol that makes the internet work, allowing networks to exchange routing information. A BGP hijack involves an attacker illicitly announcing ownership of IP address ranges they do not control, thereby redirecting internet traffic intended for legitimate destinations through their own network. In Georgia, Russia used this to route all Georgian internet traffic through Russian infrastructure. This technical maneuver had profound implications:

  • Interception and Surveillance: By funneling traffic through Russian-controlled networks, Russia gained the ability to intercept all communications.
  • FSB Access: This capability is buttressed by Russian laws. The Yarovaya Law mandates that all internet service providers and telecom companies in Russia must provide the FSB with all encryption/decryption keys and retain metadata for six months, accessible without court orders. This effectively means any traffic routed through Russia is subject to state-level surveillance.
  • SORM Platform: The System for Operative-Investigative Measures (SORM) is a mandatory surveillance system that all licensed telecom and ISP providers in Russia must install. Erchov details its three phases:
  • Phase 1: Covered phone calls and text message interception and metadata collection.
  • Phase 2: Expanded to cover all internet communications.
  • Phase 3: Encompassed all landline and cellular communications within Russia.

This platform provides the FSB with comprehensive, real-time access to all communications traversing Russian networks, making BGP hijacks a potent tool for intelligence gathering and control.

Electronic Warfare (Crimea, 2014 & Ukraine, 2022): Russia significantly escalated its electronic warfare (EW) capabilities. In Crimea, this involved deploying EW units to jam Ukrainian military radio communications and satellite phones. This physically disrupted command and control, isolating Ukrainian units.

In the 2022 invasion of Ukraine, EW capabilities were even more advanced, extending to the compromise of sophisticated satellite communication systems:

  • Viasat Compromise: While specific technical details of the Viasat compromise are not extensively covered in the transcript, it was a significant event that disrupted satellite internet services across Ukraine and parts of Europe at the start of the invasion.
  • Starlink Terminal Compromise: The method for compromising Starlink terminals was particularly innovative and technically astute. Russian forces reportedly captured Ukrainian Android devices used to control Starlink terminals. They then planted malware on these devices and left them behind. When Ukrainian troops recovered and subsequently used these compromised devices to operate their Starlink terminals, the malware facilitated the compromise of the terminals themselves. This demonstrates a sophisticated understanding of both the hardware-software interface and the operational security practices of their adversaries, leveraging physical access to achieve a persistent cyber foothold.

Deepfake Technology (Ukraine, 2022): Russia's information operations evolved to include deepfake technology. The creation of a fake video allegedly showing President Zelenskyy surrendering is a prime example. This technology leverages artificial intelligence (AI) and machine learning to generate highly realistic but fabricated video or audio content, making it difficult for the average person to distinguish from genuine media. This represents a significant leap in disinformation capabilities, capable of sowing widespread confusion and undermining morale.

Weaponized Certificates (Future Prediction): Erchov references an article by Andy Greenberg which suggested that a Russian APT group, Tula, might use Russian infrastructure to update certificates on machines. This technical prediction aligns with Russia's established control over communications infrastructure (SORM, BGP hijacks). By controlling certificate issuance or updates, Russia could potentially facilitate man-in-the-middle attacks, making decryption of communications even easier for themselves, further solidifying their surveillance capabilities by undermining trust in digital identities.

Demo / Proof of Concept

▶ Watch: Significance of BGP hijacks through Russian infrastructure (6:00)

The talk delivered by Evgueni Erchov was an analytical presentation focused on the historical evolution and strategic implications of Russia's cyber operations. It did not include a live demonstration or a proof of concept of any specific exploit or technique. The content was primarily observational, drawing on past events and intelligence analysis to illustrate the discussed concepts.

Defensive Implications

▶ Watch: SORM platform: Russian state surveillance and data retention (7:50)

The evolving nature of Russia's cyber warfare, as meticulously detailed by Evgueni Erchov, presents critical defensive implications for governments, organizations, and individuals worldwide. Understanding these patterns is paramount for developing robust and adaptive cybersecurity strategies.

  1. Vigilant BGP Monitoring: Given Russia's demonstrated willingness to employ BGP hijacks for surveillance and control, organizations, particularly those operating in geopolitically sensitive regions or dealing with critical infrastructure, must implement advanced BGP monitoring solutions. It is crucial to detect anomalous route announcements, especially those routing traffic through Russian Autonomous System Numbers (ASNs), and have a rapid response plan to mitigate potential interception or disruption.
  2. Assumption of Compromise in High-Risk Environments: For individuals and organizations operating within or transiting through Russia, or dealing with Russian-controlled infrastructure, the default assumption should be that all communications are compromised. This is due to laws like the Yarovaya Law and pervasive surveillance systems like SORM, which grant the FSB unfettered access to communications data, including potentially encryption keys. Implementing end-to-end encryption and using trusted VPNs (though even these may be compromised if routed through Russian infrastructure) is essential, but the ultimate recommendation is to minimize reliance on local networks.
  3. Deepfake Awareness and Verification: The emergence of deepfake technology in information operations necessitates a strong focus on media literacy and verification. Defenders must educate employees and the public on how to identify deepfakes, promote critical thinking regarding online content, and implement technical solutions for detecting synthetic media. This includes leveraging AI-driven tools for deepfake detection and establishing rapid response protocols for debunking disinformation campaigns.
  4. Enhanced Biometric Data Security: Erchov specifically warns that companies dealing with biometric data (face scans, fingerprints, iris scans) are at higher risk. Unlike passwords, biometric identifiers cannot be changed. Therefore, organizations handling such sensitive data must invest in the most robust security measures, including advanced encryption, secure storage, and stringent access controls, to prevent compromise that could have irreversible consequences for individuals.
  5. Supply Chain and Device Security: The sophisticated compromise of Starlink terminals via malware planted on captured Android devices highlights the critical importance of supply chain security and device hygiene. Organizations must implement rigorous vetting processes for all hardware and software, secure device management policies, and educate users about the risks associated with found or compromised devices. This includes ensuring devices are wiped or securely provisioned before deployment and maintaining strong physical security protocols.
  6. Anticipating Adversary Evolution: Russia's history of continuously learning and adapting its tactics means defenders cannot rely on static defenses. Threat intelligence must be dynamic, constantly monitoring for new tools, techniques, and procedures (TTPs). This includes tracking developments in AI, electronic warfare, and novel exploitation methods, and proactively integrating these insights into defensive strategies.
  7. Impact of Hacker Migration and New Threat Hubs: The "Great Migration of Hackers" presents a complex, evolving challenge. The potential for cybercriminals to establish new hubs in regions with lax regulations, such as South America, could lead to new forms of cybercriminal collaboration, potentially with organized crime syndicates like cartels. This shift could result in more sophisticated money laundering schemes, new attack vectors, and a broader range of targets. Defenders should monitor intelligence for emerging threat clusters in these regions and anticipate changes in the types and scale of cybercriminal operations. The off-topic mention of cartels controlling 90% of Mexican avocado farms, while seemingly unrelated, serves as a stark reminder of the financial sophistication of such organizations, making them attractive partners for cybercriminals seeking to launder illicit gains.

Key Takeaways

  • Russia's Cyber Tactics Continuously Evolve: From basic DDoS in Estonia to sophisticated satellite compromises and deepfakes in Ukraine, Russia consistently refines its cyber warfare playbook, learning from each engagement to achieve increasingly complex objectives.
  • Integrated Hybrid Warfare is the Norm: Russian operations seamlessly blend cyberattacks, kinetic military actions, and information warfare to achieve strategic goals, underscoring the need for a holistic defense strategy.
  • Infrastructure Control is Key to Surveillance: Russia leverages BGP hijacks and domestic surveillance platforms like SORM (mandated for all ISPs/telecoms) alongside laws like the Yarovaya Law to gain comprehensive access to communications, including encryption keys and metadata.
  • Advanced EW and Novel Compromise Methods: The ability to jam military radios, disrupt satellite communications, and ingeniously compromise Starlink terminals via malware on captured Android devices highlights Russia's advanced electronic warfare and exploitation capabilities.
  • Deepfakes Elevate Information Warfare Risks: The use of deepfake technology for disinformation campaigns (e.g., fake Zelenskyy video) signifies a new era of highly deceptive information operations, demanding enhanced media literacy and technical detection methods.
  • The "Great Migration of Hackers" Reshapes the Threat Landscape: Geopolitical pressures are driving cybercriminals to new havens, potentially leading to new hubs in regions like South America and increased collaboration with organized crime, which could alter the global threat matrix.

About the Speaker(s)

Evgueni Erchov is the Senior Director of Research and Threat Intelligence at Cipher, a firm specializing in cyber investigations, particularly in cases involving ransomware and business email compromise. Prior to his role at Cipher, Erchov served for several years as a US Army cyber threat intelligence officer, gaining significant experience in analyzing and countering state-sponsored cyber threats. He also spent a few years as a federal agent, further broadening his expertise in law enforcement and intelligence operations. Erchov's diverse background provides him with a unique and comprehensive perspective on the intersection of cyber warfare, intelligence, and national security.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent chronological walkthrough of Russian hybrid warfare doctrine from Estonia to Ukraine, delivered by someone with credible government-side intel experience. The narrative holds together and the 'Great Migration of Hackers' angle adds a wrinkle you don't hear in every Russia-APT retrospective, but the core material is well-trodden ground for anyone who's followed Sandworm, the Viasat incident, or the Grugq's writing on info ops.

Heather Calloway (CISO) — WEAK

Erchov clearly knows this material and the historical arc from Estonia to Ukraine is competently assembled. But this is a briefing document dressed up as strategic insight — it catalogs what happened without producing a defensible thesis about what institutions should do differently or who is accountable for the gaps it identifies.

→ Top-rated talks at Recon Village @ DEF CON 33

All talks from Recon Village @ DEF CON 33