CYBER THREATS AND ACTORS
Attacks on Availability: Significant Growth of DDoS Attacks by
Russian Language Hactivists
One of the consequencs of Russian invasion of Ukraine has been the increased risk of
cyberattacks against the states supporting Ukraine. This is something the NÚKIB has repeatedly
warned about over the past year. Although the more serious scenarios of potential threats have
not materialized, the Czech Republic has been the target of a number of cyberattacks that are
almost certainly (90-100 %) related to this conflict. During 2022, several waves of DDoS attacks
took place in the country, claimed by Russian-speaking hacktivists, which targeted public
sector subjects as well as private organizations.
Killnet DDoS Campaign in April 2022
Anonymous Russia DDoS Campaign in
October 2022
In April 2022, the Russian-language hacking
group Killnet carried out two series of
DDoS attacks against the websites of Czech
entities. The first wave took place on April
19-21, affecting thirteen entities, including
the NÚKIB and a number of ministries of
the Czech Republic. The second wave took
place on April 27, targeting nine additional
subjects. The beginning of the attacks
coincided with the announcement regarding
ongoing repairs of Ukrainian heavy military
equipment on the territory of the Czech
Republic. The attackers announced their
attacks on their Telegram account.
On October 2, 2022, the hacker group
Anonymous Russia announced a wave of
attacks against Czech entities on its Telegram
account. Government institutions, media,
banks, and airports were listed as targets.
Nevertheless, the effects of the attacks
were limited and only a fraction of the
declared targets was hit. In the case of this
campaign, efforts to establish a connection
from the group’s statements to any specific
action by the Czech Republic as a pretext
for the attack failed.
Aside for these two specific campaigns, DDoS attacks also occurred during the remainder of
2022. The monthly number of incidents caused by DDoS attacks, resolved by the NÚKIB, can
be seen below (Graph 14). According to the survey, 28% of the questioned organizations
encountered an attempted or successful DDoS attack during the past year. Therefore, the
number of incidents reported to the NÚKIB is almost surely (90-100 %) only a fraction of the
real scope of threat activity in the country.
15
13
10
8
17
5
0
0
2
1
January February March
April
0
0
0
May
June
July
2
2
August September October November December
Graph 14: Monthly Development of DDos Attacks Resolved by the NÚKIB
15
1