2022 DDoS attacks on Romania
Beginning 29 April 2022, at 04:05 EEST, a series of multiple DDoS attacks were launched against several Romanian government, military, bank and mass media websites. Behind the attacks was the pro-Kremlin hacking group Killnet, who resorted to this in response to a declaration made by Florin Cîțu, the then-President of the Senate of Romania, that Romania would provide Ukraine with military aid. The Russian Federation, who invaded the latter, publicly spoke against Western military support for Ukraine, stating that it would result in "lightning-fast retaliatory strikes". The DDoS attacks continued until 1 May.
Background
On 26 April 2022, the President of the Chamber of Deputies of Romania Marcel Ciolacu, Prime Minister Nicolae Ciucă and Minister of Foreign Affairs Bogdan Aurescu visited Kyiv, Ukraine, to meet with Ukrainian President Volodymyr Zelenskyy, Ukrainian Prime Minister Denys Shmyhal, and with the president of the Verkhovna Rada, Ruslan Stefanchuk. In the meeting, Romania reiterated its support for Ukraine and its European integration aspirations, as well as committing to active involvement in the reconstruction of the country.[1]
The meeting was planned since as early as 13 April, with the Romanian delegation initially consisting of the President of the Senate Florin Cîțu and the President of the Chamber of Deputies Marcel Ciolacu, both visiting Kyiv on 27 April at the invitation of Stefanchuk.[2] Prime Minister Ciucă justified the absence of Cîțu around the fact that there were two state visits separately planned, under condition by the safety measures imposed in Kyiv due to the 2022 Russian invasion of Ukraine.[3] Nevertheless, Florin Cîțu visited Kyiv by himself on 27 April 2022,[4] after which he stated that Romania should do more for Ukraine, supporting them with military equipment.[5]
Russia claimed that Western military support for Ukraine are "posing a threat to European security". Russian President Vladimir Putin stated that "if someone intends to intervene in the ongoing events [Russian invasion of Ukraine] from the outside, and create strategic threats for Russia that are unacceptable to us, they should know that our retaliatory strikes will be lightning-fast".[6]
Cyberattack
On 29 April 2022, at 04:05 EEST, the websites of the Ministry of National Defence (MApN), the Romanian Border Police, the Government of Romania, and of CFR Călători were taken down by a DDoS attack. According to the MApN, the cyberattack did not compromise the functioning of its website, but rather prevented user access to it. The government stated that IT specialists at the structures at governmental level are collaborating with experts from specialized institutions to restore access and identify the causes. In the meantime, CFR Călători issued alternative means of purchasing train tickets digitally.[7]
The Romanian Intelligence Service (SRI) stated that the hackers behind the cyberattack used network equipment from outside Romania.[8] The pro-Kremlin hacking group Killnet claimed the attacks through Telegram, stating that "the president of the Romanian Senate, Marcel Ciolacu issued a statement promising the Ukrainian authorities "maximum assistance" in supplying lethal weapons to Kyiv". Furthermore, they revealed a list of websites that it took down through the DDoS attack, where the website of OTP Bank (the Romanian division) was also listed.[9] The Directorate for Investigating Organized Crime and Terrorism (DIICOT) was notified in the case, and access to the websites was restored.[7][10]
At 19:30 EEST, another DDoS attack was launched, this time on the website of the Ciolacu-led Social Democratic Party (PSD), taking it down in a similar manner. In response, the party's IT department quickly took action and restored access to the website within 15 minutes.[10]
In retaliation, Romania's National Cybersecurity Directorate (DNSC) published a list of 266 IP addresses involved in the 29 April DDoS attacks to its official website. On 30 April, at approximatively 2:30 EEST, this website had also been taken down through a further DDoS attack by the pro-Kremlin hacking group, with user access restored by 8:30 EEST.[11] Later the same day, a further DDoS attack took down the website of the Romanian Police.[12]
The pro-Kremlin hacking group threatened to take down another 300 Romanian websites in a similar manner, including websites of stores, military, government, mass-media, banks, hospitals, educational institutions, political parties, etc. Some websites using Moldovan (.md) domains were also included in the list.[13]
On 1 May 2022, Killnet took down the websites of seven Romanian airports (including those located in Bucharest, Cluj-Napoca, etc.), as well as of the TAROM airline and several news media websites, including Digi24, among others.[14]
It has been suspected that a Romanian resident in the United Kingdom helped Killnet take down Romanian websites, translating content in Romanian language to Russian language. They were put in custody.[15] In retaliation, Killnet threatened to "destroy Romania, the United Kingdom and Moldova" if they are not released in 48 hours.[16]
Public reactions
Romania's Minister of Defence, Vasile Dîncu described the cyberattacks as "symbolic attacks".[17] The President of the Chamber of Deputies of Romania Marcel Ciolacu called his nominalization as "Senate president" by Killnet a mistake (as the presidency of the Senate was held by Florin Cîțu),[18] and stated that "if needed, Romania is ready both legally and morally to take this step [to supply Ukraine with military equipment]. At this moment [at the time of the first attacks], there is no decision".[19] In the meantime, the Romanian hacking group "Anonymous Romania" stated that it launched a counterattack against a Russian governmental website.[20]
Florin Cîțu, the president of the Senate, reacted as well: "First of all, I do not know what kind of hackers are those who do not know who the president of the Senate or the president of the Chamber of Deputies is [...]. Secondly, if we look at that [Killnet's] statement it is bizarre to have the picture of the President of the Chamber of Deputies, to have the correct name, but to mistake his position [...]. A simple search on Wikipedia and you would have found out who the president of the Senate is".[21]
References
- "Imagini cu Marcel Ciolacu și Nicolae Ciucă la Kiev, cu Volodimir Zelenski. Vizita ar fi trebuit să aibă loc mâine, împreună cu Florin Cîțu". www.antena3.ro (in Romanian). Retrieved 2022-04-29.
- "Marcel Ciolacu și Florin Cîțu merg la Kiev pe 27 aprilie". www.digi24.ro (in Romanian). Retrieved 2022-04-29.
- "De ce nu a fost Florin Cîțu în Ucraina alături de Ciucă și Ciolacu. Explicația premierului". www.antena3.ro (in Romanian). Retrieved 2022-04-29.
- "Primele imagini cu Florin Cîțu în Ucraina: "Ceea ce am văzut deschide ochii lumii asupra acțiunilor Rusiei"". www.antena3.ro (in Romanian). Retrieved 2022-04-29.
- "Marcel Ciolacu, despre trimiterea de arme în Ucraina: "Dacă este nevoie, România este pregătită să facă acest pas"". www.antena3.ro (in Romanian). Retrieved 2022-04-29.
- "Russia says pumping Ukraine with weapons is threat to European security". Reuters. 2022-04-28. Retrieved 2022-04-29.
- "Val de atacuri cibernetice în România. Vizate mai multe instituții, între care Guvernul și Ministerul Apărării / Atacurile, revendicate de hackerii pro-ruși de la Killnet". economie.hotnews.ro (in Romanian). Retrieved 2022-04-29.
- "Atacurile cibernetice care au vizat Guvernul și MApN. SRI: Hackerii au folosit echipamente de rețea din afara României, profitând de vulnerabilități ale site-urilor". www.hotnews.ro (in Romanian). Retrieved 2022-04-29.
- "Cine este gruparea de hackeri Killnet care a atacat site-urile Guvernului și Armatei României". economie.hotnews.ro (in Romanian). Retrieved 2022-04-29.
- "Site-ul PSD inactiv după ce a fost atacat de hakerii ruși de la Killnet". www.antena3.ro (in Romanian). Retrieved 2022-04-29.
- "Continuă seria de atacuri de tip DDoS asupra site-urilor românești". www.antena3.ro (in Romanian). Retrieved 2022-04-30.
- "UPDATE Site-ul Poliției Române a fost atacat cibernetic "într-un mod similar ca celelalte instituții" (surse)/ Problema a fost remediată în aproximativ o oră de la anunțul Poliției/ Hackerii pro-ruși Killnet au amenințat că vor ataca peste 300 de entități din România". G4 Media (in Romanian). 2022-04-30. Retrieved 2022-04-30.
- "Gruparea Killnet amenință că va ataca cibernetic alte aproape 300 de site-uri din România". economie.hotnews.ro (in Romanian). Retrieved 2022-05-01.
- "Site-urile marilor aeroporturi din România nu funcționează. Hackerii ruși de la Killnet revendică atacul". www.digi24.ro (in Romanian). Retrieved 2022-05-01.
- "BREAKING Un român din Marea Britanie, suspectat că a ajutat gruparea de hackeri ruși Killnet pentru a ataca site-uri din România. Bode: "Cetăţeanul este în custodia autorităţilor şi este audiat"". G4 Media (in Romanian). 2022-05-03. Retrieved 2022-05-04.
- "Killnet confirmă sprijinul românului Ioan Feher și amenință că va "distruge România, Marea Britanie și Moldova" dacă nu va fi eliberat: "Dacă susține Rusia, nu înseamnă că e un criminal"/ Este vizat Ministerul Sănătății". G4 Media (in Romanian). 2022-05-03. Retrieved 2022-05-04.
- "Reacția lui Vasile Dîncu după ce grupul pro-rus Killnet a atacat cibernetic România: "Este un atac simbolic"". Stirileprotv.ro (in Romanian). Retrieved 2022-04-30.
- "Ciolacu spune că hackerii ruși l-au confundat cu Cîțu: E o greșeală acolo, sunt și eu". www.digi24.ro (in Romanian). Retrieved 2022-04-30.
- "Ce spune Marcel Ciolacu, președintele Camerei Deputaților, despre motivele invocate de hackerii Killnet: E o greșeală acolo". ZF.ro (in Romanian). Retrieved 2022-04-30.
- "Grupul de hackeri Anonymous România susține că a atacat un site guvernamental din Rusia ca răspuns la acțiunile grupării ruse Killnet". G4 Media (in Romanian). 2022-04-29. Retrieved 2022-04-30.
- "Cîțu, deranjat că a fost confundat cu Ciolacu: Ce hackeri sunt ăia care nu știu cine e șeful Senatului? Dădeai search pe Wikipedia". www.digi24.ro (in Romanian). Retrieved 2022-05-02.