{"id":1112,"date":"2022-01-27T18:50:40","date_gmt":"2022-01-28T01:50:40","guid":{"rendered":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/?p=1112"},"modified":"2022-01-27T18:50:43","modified_gmt":"2022-01-28T01:50:43","slug":"the-belarus-railway-hack","status":"publish","type":"post","link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/01\/27\/the-belarus-railway-hack\/","title":{"rendered":"The Belarus Railway Hack"},"content":{"rendered":"\n<p class=\"has-text-align-left\">On Monday, January 24<sup>th<\/sup>, a group of hackers claimed to have launched a successful ransomware attack against Belarusian Railways, the state-run national train system of Belarus. In their <a href=\"https:\/\/twitter.com\/cpartisans\/status\/1486090490655252481?s=20\" data-type=\"URL\" data-id=\"https:\/\/twitter.com\/cpartisans\/status\/1486090490655252481?s=20\">posted screenshots<\/a>, the group appears to have gotten access to the backend systems of the railway and has claimed to have encrypted the system with malware<sup>[1]<\/sup>. One of their initial statements can be seen in the screenshot below:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" data-src=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/01\/image-16-1024x668.png\" alt=\"\" class=\"wp-image-1117 lazyload\" width=\"593\" height=\"385\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 593px; --smush-placeholder-aspect-ratio: 593\/385;\" \/><figcaption>Photo Source: https:\/\/twitter.com\/cpartisans\/status\/1485615555017117700<\/figcaption><\/figure>\n\n\n\n<h2 class=\"has-huge-font-size wp-block-heading\" id=\"who-are-they\" style=\"text-transform:capitalize\">Who are they?<\/h2>\n\n\n\n<p>Known as the \u201cBelarusian Cyber-Partisans\u201d, they are a group of politically minded, cyber-activists out of Belarus<sup>[2]<\/sup>. The group staunchly opposes the Belarusian president and dictator, Alexander Lukashenko, who won office after reportedly rigging the election in 2020. The Cyber-Partisans have launched several successful hacks against the government, since their first appearance after a number of anti-Lukashenko protests during that time<sup>[3]<\/sup>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-do-they-want\" style=\"text-transform:capitalize\">What do they want?<\/h2>\n\n\n\n<p>The decryption keys to return the train network to normal, according to the Cyber-Partisans, will only be provided if the Belarus government meets a list of demands<sup>[1]<\/sup>. The group has called for the release of 50 political prisoners in need of medical care, who were detained along with over 900 others during the country\u2019s protests against the president<sup>[3]<\/sup>. In addition, they want a commitment that Belarusian Railways will not transport Russian troops, preventing their presence in the country<sup>[1]<\/sup>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" data-src=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/01\/image-17-1024x821.png\" alt=\"\" class=\"wp-image-1121 lazyload\" width=\"596\" height=\"478\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/01\/image-17-1024x821.png 1024w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/01\/image-17-300x241.png 300w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/01\/image-17-768x616.png 768w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/01\/image-17-1536x1232.png 1536w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/01\/image-17-1568x1258.png 1568w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/01\/image-17.png 1728w\" data-sizes=\"(max-width: 596px) 100vw, 596px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 596px; --smush-placeholder-aspect-ratio: 596\/478;\" \/><figcaption>Photo Source: https:\/\/twitter.com\/cpartisans\/status\/1485618881557315588<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why\">Why?<\/h2>\n\n\n\n<p>Belarus is a country in eastern Europe, that borders both Ukraine and Russia. One main factor in the protests that arose after the election of Lukashenko was opposition to plans of greater economic and political integration of Russia and Belarus into a \u201cunion state\u201d<sup>[3]<\/sup>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img decoding=\"async\" data-src=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/01\/image-18-1024x741.png\" alt=\"\" class=\"wp-image-1126 lazyload\" width=\"572\" height=\"414\" data-srcset=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/01\/image-18-1024x741.png 1024w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/01\/image-18-300x217.png 300w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/01\/image-18-768x556.png 768w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/01\/image-18-1536x1112.png 1536w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/01\/image-18-2048x1483.png 2048w, https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-content\/uploads\/sites\/115\/2022\/01\/image-18-1568x1135.png 1568w\" data-sizes=\"(max-width: 572px) 100vw, 572px\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 572px; --smush-placeholder-aspect-ratio: 572\/414;\" \/><figcaption>Photo Source: https:\/\/www.geographicguide.com\/europe-maps\/europe-east.htm<\/figcaption><\/figure>\n\n\n\n<p>Meanwhile, tensions between Russia and Ukraine have only been intensifying over the last month as Russia has amassed thousands of troops near their shared border. If Russia is able to attack from both Russia and Belarus, Ukrainian forces would be forced to spread thin across both borders<sup>[2]<\/sup>.<\/p>\n\n\n\n<p>The attack by the Cyber-Partisans appears to be a bid at disrupting Russian troop movements and attempting to halt the buildup of Russian troops and military weaponry in Belarus<sup>[2]<\/sup>.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cWe don\u2019t want Russian soldiers in Belarus since it compromises the sovereignty of the country and puts it in danger of occupation. It also pulls Belarus into a war with Ukraine. And probably Belarusian soldiers would have to participate in it and die for this meaningless war.\u201d<sup>[3]<\/sup><\/p><cite>&#8211; A member of the Cyber-Partisans, told the Guardian<\/cite><\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-does-this-mean-for-cybersecurity\" style=\"text-transform:capitalize\">What does this mean for cybersecurity?<\/h2>\n\n\n\n<p>According to Brett Carlow, a ransomware-focused researcher at security firm Emsisoft, the Cyber-Partisans&#8217; method of using reversible encryption rather than merely wiping targeted machines would represent a new evolution in hacktivist tactics. Going on to say \u201cThis is the first time I can recall non-state actors having deployed ransomware purely for political objectives.\u201d<sup>[1]<\/sup><\/p>\n\n\n\n<p>Cybersecurity experts have said that it is too early to know whether this attack will be fully successful or not, however, this attack does mark a possible new evolution for both cyber-activism and cyber-terrorism. Juan Andres Guerrero-Saade, a researcher at security firm SentinelOne, says that this tactic could soon bleed out to other groups who see the power of ransomware to achieve political coercion, for good and for ill.<sup>[1]<\/sup><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>\u201cThe looming horror of ransomware is precisely just how many systems are out there about whose criticality we don&#8217;t understand until they&#8217;re unavailable. So, if this is a continued tactic of theirs, I think we&#8217;ll definitely see a ratcheting up of the pressure on both sides.\u201d<sup>[1]<\/sup><\/p><cite>&#8211; Juan Andres Guerrero-Saade<\/cite><\/blockquote>\n\n\n\n<p>Sources:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Greenberg, Andy. \u201cWhy the Belarus Railways Hack Marks a First for Ransomware.\u201d <em>Wired<\/em>, Conde Nast, 25 Jan. 2022, https:\/\/www.wired.com\/story\/belarus-railways-ransomware-hack-cyber-partisans\/.<\/li><li>Muncaster, Phil. \u201cBelarus Activists Fire Ransomware at State Railway.\u201d <em>Infosecurity Magazine<\/em>, 25 Jan. 2022, https:\/\/www.infosecurity-magazine.com\/news\/belarus-activists-fire-ransomware\/.<\/li><li>Roth, Andrew. \u201c&#8217;Cyberpartisans&#8217; Hack Belarusian Railway to Disrupt Russian Buildup.\u201d <em>The Guardian<\/em>, Guardian News and Media, 25 Jan. 2022, https:\/\/www.theguardian.com\/world\/2022\/jan\/25\/cyberpartisans-hack-belarusian-railway-to-disrupt-russian-buildup.<\/li><li>Pietsch, Bryan. \u201cHacking Group Claims Control of Belarusian Railroads in Move to &#8216;Disrupt&#8217; Russian Troops Heading near Ukraine.\u201d <em>The Washington Post<\/em>, WP Company, 25 Jan. 2022, https:\/\/www.washingtonpost.com\/world\/2022\/01\/25\/belarus-railway-hacktivist-russia-ukraine-cyberattack\/.<\/li><\/ol>\n","protected":false},"excerpt":{"rendered":"<p>On Monday, January 24th, a group of hackers claimed to have launched a successful ransomware attack against Belarusian Railways, the state-run national train system of Belarus. In their posted screenshots, the group appears to have gotten access to the backend systems of the railway and has claimed to have encrypted the system with malware[1]. One &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/2022\/01\/27\/the-belarus-railway-hack\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;The Belarus Railway Hack&#8221;<\/span><\/a><\/p>\n","protected":false},"author":376,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[15],"tags":[],"class_list":["post-1112","post","type-post","status-publish","format-standard","hentry","category-cpsc-329-602-w22","entry"],"featured_image_src":null,"featured_image_src_square":null,"author_info":{"display_name":"Camille Paton","author_link":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/author\/camille-paton\/"},"_links":{"self":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/1112","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/users\/376"}],"replies":[{"embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/comments?post=1112"}],"version-history":[{"count":3,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/1112\/revisions"}],"predecessor-version":[{"id":1129,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/posts\/1112\/revisions\/1129"}],"wp:attachment":[{"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/media?parent=1112"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/categories?post=1112"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpsites.ucalgary.ca\/isec-601-f21\/wp-json\/wp\/v2\/tags?post=1112"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}