In a February report on the cyber threats in Ukraine, Alphabet Inc.’s Google said that cyber campaigns by Sandworm, which it calls FrozenBarents, “seem designed to advance Russian strategic objectives and respond to changes in Russian intelligence requirements throughout the conflict.”
The attack was “testing the international community’s ability to attribute espionage operations to Moscow” or the reaction of Ukraine’s allies to a targeted destructive attack outside Ukraine by deploying ransomware on Poland’s transport system, Microsoft said.
The ransomware attack on Polish and Ukrainian transport services in October, attributed to Sandworm, may have been “a trial balloon” for further attacks, the report said. Russian hackers have been accused of bombarding Ukrainian institutions with “wiper malware” and DDoS attacks, a campaign that began even before President Vladimir Putin ordered troops to invade more than a year ago.