Hackfest - Level UP

Three Paths of Hacktivism: Russia, Ukraine and Belarus
Language: English

Exploring the hacktivist landscapes of Russia, Ukraine and Belarus, this talk will look at how the war in Ukraine has shaped the three diverging paths for each country's hacktivist landscape. It will explore novel approaches adopted by hacktivist personas across the three countries, and the differing circumstances for each country that have influenced these choices. The result is a novel framework through which to explore the broader global hacktivist landscape and how real world changes can significantly influence hacktivist activity.

The audience will leave this talk with a deeper understanding of hacktivism within Russia/Ukraine/Belarus, and a framework through which to consider hacktivism in a global context. For attendees, they can then apply this to their individual company threat landscapes and explore how the hacktivist landscape can change to inform leadership as the global environment changes.


In this proposed talk, I will explore the evolution of hacktivism in Russia, Ukraine and Belarus. Looking at activity since 2020, this talk will explain how hacktivism within the three countries have taken diverging paths, each shaped by the experiences of the individual countries and hypothesize how we can understand potential shifts in hacktivism elsewhere in the world.

In the case of Russia, hacktivism is inorganic and state-run. While there almost certainly is some element of the more standard definition of hacktivism, the state, and in particular the intelligence services, have fully co-opted the idea of ideologically motivated personas to offer plausible deniability and a means to publicize their largely performative activity. When exploring Russia, I will also look at a relatively unique trend within their inorganic hacktivism - gamification, particularly from the NoName057(16) group. While the group itself is run by the state, their connection to a Russian government entity specializing in youth online activity enables them to leverage this speciality to better engage online audiences and encourage youth involvement in their activity.

In contrast, hacktivism in Ukraine developed in a grassroots manner, shaped by the Russian invasion. They cooperate with, but are not fully controlled by the state, free to conduct operations targeting Russia. They have also engaged in unique, defensively oriented hacktivism. Exposed Internet of Things (IoT) devices often make up botnets used for attacks, however Ukrainian hacktivists have been utilizing them in a defensive manner.

FInally, Belarusian hacktivism is the result of a stolen election in 2020 that has grown immeasurably in its scope. Initially, the Belarusian Cyber Partisans (BCP) were highly focused on targeting the security services, looking to expose individuals in the country who worked to target pro-democracy protesters. This included hacking and leaking personally identifiable information, emails, phone calls, etc, but all in a highly targeted and triaged manner. Great care was taken to avoid impacting the average Belarusian. As the war began, BCP began shifting its focus, using cyber-enabled means to impact Russia's ability to leverage Belarusian territory to support its invasion, and then as the war progressed, began targeting Russian entities directly. For example, BCP is one of the two groups responsible for the attack against state-owned Aeroflot. The group is unique, in that it is a true hacktivist group. There is no known connection to any country's intelligence services, which includes funding limitations - they serve no one but themselves and have no legal backing like a state-run service would. Despite this, they are a highly sophisticated group.

Through this, there are a few key ideas that we can take away to understand the evolution of hacktivism.
1) The system of government is a clear driver in how hacktivism is employed. Russia is authoritarian, and needs to control the environment. Ukraine is democratic with an active civil society, which lends itself to more grassroots activity and a willingness to engage throughout the country. Belarus, through the BCP, is a pro-Belarus but anti-regime activity. This suggests that as we look globally, the system of governance within any given country will have an influence on the hacktivist landscape.
2) The idea of an existential threat is a key driver to innovate. Hacktivism has largely been low-sophistication, largely annoying, DDoS and web defacement attacks. But in the case of Russia, Ukraine and Belarus, each operates in an environment that shows clear existential threats to the existence of each state. This leads to the hypothesis that an existential threat will lead to an evolution in an individual country's hacktivist landscape.

Iran will be addressed in the talk, but will be adapted as the situation unfolds - an existential threat does not exist. As of submission the war is largely fought in the air, with general wisdom suggesting that one cannot force regime change through air power alone. Until there are boots on the ground, there is not a significant risk of existential threat to Iran. However, we can see some connections to how Russian hacktivism works (Banished Kitten and Stryker), and similarly to Russian operations, is performative.

The audience will leave this talk with a deeper understanding of hacktivism within Russia/Ukraine/Belarus, and a framework through which to consider hacktivism in a global context. For attendees, they can then apply this to their individual threat landscapes and explore how the hacktivist landscape can change to inform their own analysis as the global environment changes.

There are 3 key takeaways that participants will hopefully leave with.

1) A deeper understanding of the Eastern European hacktivist landscape.

Highlights include the different types of threats. For example a Russian hacktivist threat is more akin to a state-nexus threat due to integration with the security services, compared to a Ukrainian hacktivist threat that is more grassroots, aimed at Russia, but patriotically driven, significantly influenced by the situation Ukraine is in.

2) System of governance as a key driver in the dynamic of individual country hacktivist landscapes.

Russia as authoritarian is inorganic, with a highly controlled landscape operating in lockstep with, if not in total control of, the security services. Ukraine with its far more democratic tendencies and robust civil society, has a more grassroots driven and organic hacktivist landscape. Conversely, Belarus is unique in that it is a highly authoritarian state, but the hacktivist landscape is driven by a pro-Belarus but anti-regime group.

3) Existential threats drive innovation in hacktivism.

Russia, Ukraine and Belarus can each be understood as facing existential threats as of submission, though the existential threat to each is unique to each country's situation. Taken outside of Eastern Europe, how can we apply this hypothesis to understanding the hacktivist threat from other countries, particularly as defenders? This can influence how we as defenders assess threats in countries our businesses already operate in or are looking to expand to. Effectively, what triggers exist in any given country that can lead to the creation of an existential threat that can impact local hacktivists?

The speaker's profile picture
Ian Litschko

Ian is a specialist in the Russian intelligence services and Russian cybercriminal underworld. He has spoken extensively on these topics, and his work has been cited by the House of Commons and the Security Service of Ukraine (SBU).