HOME

TheInfoList



OR:

The Ukrainian Cyber Alliance (UCA, ukr. ''Український кіберальянс'', УКА) is a community of Ukrainian cyber activists from various cities in Ukraine and around the world. The alliance emerged in the spring of 2016 from the merger of two cyber activists, and Trinity, and was later joined by the group and individual cyber activists from the CyberHunta group. The
hacktivist In Internet activism, hacktivism, or hactivism (a portmanteau of '' hack'' and '' activism''), is the use of computer-based techniques such as hacking as a form of civil disobedience to promote a political agenda or social change. With roots in h ...
s united to counter Russian aggression in Ukraine.


Participation in the Russian-Ukrainian cyber war

The
hacktivist In Internet activism, hacktivism, or hactivism (a portmanteau of '' hack'' and '' activism''), is the use of computer-based techniques such as hacking as a form of civil disobedience to promote a political agenda or social change. With roots in h ...
s began to apply their knowledge to protect Ukraine in cyberspace in the spring of 2014. Over time, the hacktivists began to conduct joint operations. Gradually, some hacker groups united in the Ukrainian Cyber Alliance (UCA), in accordance with  17 of the
Constitution of Ukraine The Constitution of Ukraine ( uk, Конституція України, translit=Konstytutsiia Ukrainy) is the fundamental law of Ukraine. The constitution was adopted and ratified at the 5th session of the ''Verkhovna Rada'', the parliament ...
to defend the independence of their country and its territorial integrity, as is the duty of every citizen. The Ukrainian Cyber Alliance exclusively transmits extracted data for analysis, reconnaissance and publication to the international intelligence community
Inform Napalm InformNapalm is a volunteer initiative to inform Ukrainian citizens and the foreign public about the Russo-Ukrainian War and the activities of the Russian special services as well as the militants of DPR, LPR, and Novorossiya. The team members ...
, as well as to the law enforcement agencies of Ukraine.


Notable operations


Operation #opDonbasLeaks

In the spring of 2016, the UCA conducted about one hundred successful hacks of websites and mailboxes of militants, propagandists, their curators, and terrorist organizations operating in the occupied territories. Among the targets was the mailbox of the Russian organization named "Union of Volunteers of Donbass". From this they obtained passport data and photo documents of citizens of Italy, Spain, India and Finland, fighting in the
Prizrak Brigade The Prizrak Brigade (russian: Бригада «Призрак», meaning "Ghost Brigade"), founded by Aleksey Mozgovoy, is an infantry unit of the Luhansk People's Republic (LPR), one of the self-proclaimed breakaway states located in the Donba ...
, for which Russia grants, and, if necessary, extends visas. It was found that Russians who were wounded during the fighting in eastern Ukraine were being treated in military hospitals of the Ministry of Defense. ukraine attacked many company websites and more in 2023. in the middle of the screen there is a photo and text


Hacking of the ANNA News site

On April 29, 2016, the
Inform Napalm InformNapalm is a volunteer initiative to inform Ukrainian citizens and the foreign public about the Russo-Ukrainian War and the activities of the Russian special services as well as the militants of DPR, LPR, and Novorossiya. The team members ...
website, with a call to the UCA, reported on the hacking and interface of the
Abkhazian Network News Agency ANNA News (Analytical Network News Agency) is a Russian pro-Kremlin news agency. The agency's name ANNA used to stand for "Abkhazian Network News Agency"; after the head office moved to Moscow, when registering in Roskomnadzor on September 22, 20 ...
(ANNA News) news agency. As a result of the hacking, the site did not work for more than 5 days. The hacktivists posted their first video message on the site's pages, in which they used the
Lviv Metro Lviv ( uk, Львів) is the largest city in western Ukraine, and the seventh-largest in Ukraine, with a population of . It serves as the administrative centre of Lviv Oblast and Lviv Raion, and is one of the main cultural centres of Ukraine ...
meme. The message stated (translation):


Operation #OpMay9

On May 9, 2016, the UCA conducted operation #OpMay9. Nine sites of
Donetsk People's Republic The Donetsk People's Republic ( rus, Донецкая Народная Республика, Donetskaya Narodnaya Respublika, dɐˈnʲetskəjə nɐˈrodnəjə rʲɪˈspublʲɪkə; abbreviated as DPR or DNR, rus, ДНР) is a Territorial ...
(DNR) terrorists, propagandists, and Russian
private military companies A private military company (PMC) or private military and security company (PMSC) is a private company providing armed combat or security services for financial gain. PMCs refer to their personnel as "security contractors" or "private military ...
(RPMCs) were hacked. The broken sites were left with the hashtags #OpMay9 and #oп9Травня and three short videos about World War II and Ukrainian contributions to the victory over Nazism – what UCA called the "serum of truth". The hacktivists also posted their new video message on the terrorist sites. The video stated:


Operation #opMay18

On May 18, 2016, on the day of remembrance of the
deportation of the Crimean Tatars The deportation of the Crimean Tatars ( crh, Qırımtatar halqınıñ sürgünligi, Cyrillic: Къырымтатар халкъынынъ сюргюнлиги) or the Sürgünlik ('exile') was the ethnic cleansing and cultural genocide of at ...
in 1944, the UCA conducted Operation #opMay18. It targeted the website of the so-called chairman of council of ministers of the
Republic of Crimea The Republic of Crimea, translit. ''Respublika Krym'' ; uk, Республіка Крим, translit. ''Respublika Krym'' ; crh, , is an unrecognized federal subject (republic) of Russia, located in the Crimean Peninsula. Its territory cor ...
,
Sergey Aksyonov Sergey Valeryevich Aksyonov (russian: Сергей Валерьевич Аксёнов, uk, Сергій Валерійович Аксьонов, ro, Serghei Valerievici Aksionov; born 26 November 1972) is a Russian politician serving, since ...
, putting in his voice the fraudulent message:


Channel One hacking

The UCA hacked the website of Pervy Kanal (Channel One Russia), according to hacktivists, as part of a project to force Russia to deoccupy Donbass and fulfill its obligations under the
Minsk agreement The Minsk agreements were a series of international agreements which sought to end the Donbas war fought between armed Russian separatist groups and Armed Forces of Ukraine, with Russian regular forces playing a central part. The first, known ...
s. Details of Pervy Kanal propagandist Serhiy Zenin's cooperation with Russian state-owned propaganda network
Russia Today RT (formerly Russia Today or Rossiya Segodnya (russian: Россия Сегодня) is a Russian state-controlled international news television network funded by the Russian government. It operates pay television and free-to-air channels ...
were also revealed, along with documentation of Zenin's salary and lavish lifestyle. In Zenin's cloud storage were found 25 videos of DNR members shooting in the settlement of Nikishine.


Operation #opDay28

In 2016, on the eve of
Constitution Day Constitution Day is a holiday to honour the constitution of a country. Constitution Day is often celebrated on the anniversary of the signing, promulgation or adoption of the constitution, or in some cases, to commemorate the change to constitut ...
, the UCA conducted operation #opDay28. 17 resources of Russian terrorists were hacked, and the hacked sites played another Lviv Metro video which purported to be from the leader of DNR, O. Zakharchenko:


Hacking of the Russian Ministry of Defense

In July 2016, the UCA hacked the document management server of the Department of the
Ministry of Defense of the Russian Federation The Ministry of Defence of the Russian Federation (russian: Министерство обороны Российской Федерации, Минобороны России, informally abbreviated as МО, МО РФ or Minoboron) is the govern ...
, and made public defense contracts executed during 2015. The success of the operation was largely determined by the negligence of Russian Rear Admiral Vernigora Andrei Petrovich. At the end of November 2016, the UCA broke into the Ministry server a second time and obtained confidential data on the provision of the state defense order of 2015–2016. According to analysts of Inform Napalm, the documents show that Russia is developing a doctrine of air superiority in the event of full-scale hostilities with Ukraine, citing the amount allocated for maintenance, modernization and creation of new aircraft.


Operation #op256thDay

Before Programmer's Day, UCA conducted operation #op256thDay, in which more than 30 sites of Russian foreign aggression were destroyed. On many propaganda resources, the hacktivists embedded an
Inform Napalm InformNapalm is a volunteer initiative to inform Ukrainian citizens and the foreign public about the Russo-Ukrainian War and the activities of the Russian special services as well as the militants of DPR, LPR, and Novorossiya. The team members ...
video demonstrating evidence of Russia's military aggression against Ukraine.


Operation #OpKomendant

The activists gained access to the postal addresses of 13 regional branches of the "military commandant's office" of the DNR in operation #OpKomendant. For six months, the data from the boxes was passed for analysis by Inform Napalm volunteers, employees of the Peacemaker Center, the
Security Service of Ukraine The Security Service of Ukraine ( uk, Служба безпеки України, translit=Sluzhba bezpeky Ukrainy}) or SBU ( uk, СБУ, link=no) is the law enforcement authority and main intelligence and security agency of the Ukrainian ...
and the Special Operations Forces of Ukraine.


Hacking of Aleksey Mozgovoy

In October 2016, UCA obtained 240 pages of e-mail correspondence of the leader of Prizrak Brigade,
Aleksey Mozgovoy Aleksey Borisovich Mozgovoy or Mozgovoi (russian: Алексе́й Бори́сович Мозгово́й, uk, Олексі́й Бори́сович Мозгови́й, translit=Oleksii Borysovych Mozghovyi'';'' 3 April 1975 – 23 May 2015) wa ...
. Judging by the correspondence, Mozghovyi was completely under the control of an unknown agent with the codename "Diva".


Hacking of Arsen Pavlov

The UCA obtained data from the gadgets of Arsen "Motorola" Pavlov, leader of the
Sparta Battalion The Sparta Battalion (russian: батальон «Спарта») is a Russian separatist military unit of the breakaway Donetsk People's Republic (DPR) in eastern Ukraine. It has been fighting against the Armed Forces of Ukraine in the Donba ...
, and his wife Olena Pavlova (Kolienkina). In the weeks leading up to his death, Pavlov was alarmed by the conflict with Russian curators.


SurkovLeaks operation

In October 2016, the UCA accessed the mailboxes of
Vladislav Surkov Vladislav Yuryevich Surkov (russian: Владислав Юрьевич Сурков; born 21 September 1962 or 1964) is a Russian politician and businessman. He was First Deputy Chief of the Russian Presidential Administration from 1999 to 201 ...
, Vladimir Putin's political adviser on relations with Ukraine. Acquired emails were published by Inform Napalm in late October and early November (SurkovLeaks). The emails revealed plans to destabilize and federalize Ukraine, and with other materials demonstrated high-level Russian involvement from the start of the war in eastern Ukraine. A US official told NBC News that the emails corroborated information that the US had previously provided. The authenticity of the emails was confirmed by
Atlantic Council The Atlantic Council is an American think tank in the field of international affairs, favoring Atlanticism, founded in 1961. It manages sixteen regional centers and functional programs related to international security and global economic prosp ...
and
Bellingcat Bellingcat (stylised as bellngcat) is a Netherlands-based investigative journalism group that specialises in fact-checking and open-source intelligence (OSINT). It was founded by British journalist and former blogger Eliot Higgins in July 2014 ...
, and published by numerous Western news sources. In the aftermath of the leaks, Surkov's chief of staff resigned. Additional emails belonging to people from Surkov's environs were published in early November, detailing Russia's financing of the "soft federalization" of Ukraine, recruiting in the Odesa region, and evidence of funding election campaigns in the Kharkiv region. The emails stated that Yuriy Rabotin, the head of the Odesa branch of the Union of Journalists of Ukraine, received payment from the Kremlin for his anti-Ukrainian activities. On April 19, 2018, the British newspaper ''The Times'' published an article stating that the SurkovLeaks documents exposed Russia's use of misinformation about the downing of
Malaysia Airlines Flight 17 Malaysia Airlines Flight 17 (MH17/MAS17) was a scheduled passenger flight from Amsterdam to Kuala Lumpur that was shot down by Russian forces on 17 July 2014, while flying over eastern Ukraine. All 283 passengers and 15 crew were killed. Cont ...
in order to accuse Ukraine.


Hacking of the DNR Ministry of Coal and Energy

In November 2016, the UCA obtained emails from the DNR's "Ministry of Coal and Energy", including a certificate prepared by the
Ministry of Energy A Ministry of Energy or Department of Energy is a government department in some countries that typically oversees the production of fuel and electricity; in the United States, however, it manages nuclear weapons development and conducts energy-relat ...
of the Russian Federation in January 2016, which detail the plans of the occupiers for the Donbass coal industry.


FrolovLeaks

Operation FrolovLeaks was conducted in December 2016, and produced correspondence of Kyrylo Frolov, the Deputy Director of the CIS Institute (
Commonwealth of Independent States The Commonwealth of Independent States (CIS) is a regional intergovernmental organization in Eurasia. It was formed following the dissolution of the Soviet Union in 1991. It covers an area of and has an estimated population of 239,796,010. ...
) and Press Secretary of the Union of Orthodox Citizens, for the period 1997–2016. The correspondence contains evidence of Russia's preparation for aggression against Ukraine (long before 2014). It also revealed Frolov's close ties with
Sergey Glazyev Sergey Yurievich Glazyev (russian: Серге́й Юрьевич Глазьев) (born January 1, 1961, in Zaporozhye, Ukrainian SSR, USSR) is a Russian politician and economist, member of the National Financial Council of the Bank of Russia, ...
, the Russian president's adviser on regional economic integration, Moscow Patriarch Vladimir Gundyaev, and
Konstantin Zatulin Konstantin Fyodorovich Zatulin (russian: Константин Фёдорович Затулин, born on 7 September 1958, in Batumi, Adjarian ASSR, Georgian SSR, Soviet Union) is a Russian politician, first deputy chairman of the committee of th ...
, a member of the Foreign and Defense Policy Council, an illegitimate member of the Russian State Duma and director of the CIS Institute. The letters mention hundreds of others connected with the subversive activities of Russia's
fifth column A fifth column is any group of people who undermine a larger group or nation from within, usually in favor of an enemy group or another nation. According to Harris Mylonas and Scott Radnitz, "fifth columns" are “domestic actors who work to un ...
organizations in Ukraine.


Hacking of Luhansk intelligence chief

For some time, UCA activists monitored the computer of the Chief of Intelligence 2 AK (Luhansk, Ukraine) of the Russian Armed Forces. This officer sent reports with intelligence obtained with the help of regular Russian
unmanned aerial vehicle An unmanned aerial vehicle (UAV), commonly known as a drone, is an aircraft without any human pilot, crew, or passengers on board. UAVs are a component of an unmanned aircraft system (UAS), which includes adding a ground-based controller ...
s (UAVs) – Orlan,
Forpost The IAI Searcher (also known by the Hebrew name מרומית ''Meyromit'' - "Marsh tern", or officially in Israel as the חוגלה ''Hugla'' - "Alectoris") is a reconnaissance UAV developed in Israel in the 1980s. In the following decade, it re ...
and Takhion – which were also used to adjust fire artillery. Documents have also been published proving the existence of the Russian ground reconnaissance station PSNR-8 "Credo-M1" (1L120) in the occupied territory. In July 2017, on the basis of the obtained data, additional reconnaissance was conducted on social networks and the service of the Russian UAV Takhion (servicemen of the 138th OMSBR of the RF Armed Forces Private Laptev Denis Alexandrovich and Corporal Angalev Artem Ivanovich). The surveillance provided evidence of troop movements to the Ukraine border in August 2014. A list of these soldiers, their personal numbers, ranks, exact job titles, and information on awards for military service in peacetime were published. The operation also determined the timeline of the invasion of the Russian artillery unit of the 136th OMSBR in the summer of 2014, from the moment of loading equipment to fortifying in the occupied territory of Ukraine in Novosvitlivka, Samsonivka, and Sorokine (formerly Krasnodon).


Hacking of Oleksandr Usovskyi

In February and March 2017, the UCA exposed the correspondence of Belarus citizen Alexander Usovsky, a publicist whose articles were often published on the website of
Ukrainian Choice Ukrainian Choice, officially since 2016Viktor Medvedchuk Viktor Volodymyrovych Medvedchuk ( uk, Віктор Володимирович Медведчук, ; born 7 August 1954) is a Ukrainian lawyer, business oligarch, and politician who is since September 2022 living in exile after being handed over ...
. Inform Napalm analysts conducted a study of the emails and published two articles on how the Kremlin financed anti-Ukrainian actions in Poland and other Eastern European countries. The published materials caused outrage in Poland, the Czech Republic and Ukraine. In an interview with Fronda.pl, Polish General Roman Polko, the founder of the Polish Special Operations Forces, stated his conviction that the anti-Ukrainian actions in Poland and the desecration of Polish monuments in Ukraine were inspired by the Kremlin. Polko said that the information war posed a threat to the whole of Europe, and that the Polish radicals were useful idiots manipulated by Russia.


Hacking of CIS Institute

An analysis of hacked emails from CIS Institute (
Commonwealth of Independent States The Commonwealth of Independent States (CIS) is a regional intergovernmental organization in Eurasia. It was formed following the dissolution of the Soviet Union in 1991. It covers an area of and has an estimated population of 239,796,010. ...
) revealed that the NGO is financed by the Russian state company
Gazprom PJSC Gazprom ( rus, Газпром, , ɡɐzˈprom) is a Russian majority state-owned multinational energy corporation headquartered in the Lakhta Center in Saint Petersburg. As of 2019, with sales over $120 billion, it was ranked as the larges ...
. Gazprom allocated $2 million annually to finance the anti-Ukrainian activities of the CIS Institute. The head of the institute, State Duma deputy
Konstantin Zatulin Konstantin Fyodorovich Zatulin (russian: Константин Фёдорович Затулин, born on 7 September 1958, in Batumi, Adjarian ASSR, Georgian SSR, Soviet Union) is a Russian politician, first deputy chairman of the committee of th ...
, helped terrorists and former Berkut members who fled to Russia to obtain Russian passports.


Hacking of Russian Foundation for Public Diplomacy

Access to the mail of O. M. Gorchakovan, an employee of the Russian Foundation for Public Diplomacy, provided insight to the forms of Russia's foreign policy strategy. On the eve of the war, funding for a six-month propaganda plan in Ukraine reached a quarter of a million dollars. Under the guise of humanitarian projects, subversive activities were carried out in Ukraine, Serbia, Bosnia and Herzegovina, Bulgaria, Moldova, and the Baltic States.


Hacking of Oleksandr Aksinenko

UCA activists gained access to the mailbox of telephone miner Oleksandr Aksineko, a citizen of Russia and Israel. The correspondence indicates that Aksinenko's terrorist activities are supported by the Russian
Federal Security Service The Federal Security Service of the Russian Federation (FSB) RF; rus, Федеральная служба безопасности Российской Федерации (ФСБ России), Federal'naya sluzhba bezopasnosti Rossiyskoy Feder ...
(FSB), which advised him to "work in the same spirit". Aksinenko also sent anonymous letters to the
Security Service of Ukraine The Security Service of Ukraine ( uk, Служба безпеки України, translit=Sluzhba bezpeky Ukrainy}) or SBU ( uk, СБУ, link=no) is the law enforcement authority and main intelligence and security agency of the Ukrainian ...
(SBU) and other structures in Ukraine.


#FuckResponsibleDisclosure flashmob

At the end of 2017, the UCA and other IT specialists held a two-month action to assess the level of protection of Ukrainian public resources, to check whether officials were responsible with information security. Many vulnerabilities were uncovered in the information systems of government agencies. The activists identified reported these vulnerabilities openly to those who could influence the situation. The activists noted the effectiveness in publicly shaming government agencies. For example, it was found that the computer of the Main Directorate of the
National Police National Police may refer to the national police forces of several countries: *Afghanistan: Afghan National Police *Haiti: Haitian National Police *Colombia: National Police of Colombia *Cuba: Cuban National Police *East Timor: National Police of ...
in Kyiv region could be accessed without a password and found on a network drive 150 GB of information, including passwords, plans, protocols, and personal data of police officers. It was also found that the
Bila Tserkva Bila Tserkva ( uk, Бі́ла Це́рква ; ) is a city in the center of Ukraine, the largest city in Kyiv Oblast (after Kyiv, which is the administrative center, but not part of the oblast), and part of the Right Bank. It serves as the admi ...
police website had been hacked for a long time, and only after the volunteers noticed did the situation improve. SCFM had not updated servers for 10 years. Activists also found that the website of the Judiciary of Ukraine kept reports of the courts in the public domain. The Kherson Regional Council has opened access to the joint disk. The CERT-UA website (Ukraine's
computer emergency response team A computer emergency response team (CERT) is an expert group that handles computer security incidents. Alternative names for such groups include computer emergency readiness team and computer security incident response team (CSIRT). A more modern ...
) posted a password from one of their email accounts. One of the capital's taxi services was found to keep open information about clients, including dates, phone numbers, and departure and destination addresses. Vulnerabilities were also revealed in Kropyvnytskyi's Vodokanal, Energoatom, Kyivenerhoremont, NAPC, Kropyvnytskyi Employment Center, Nikopol Pension Fund, and the Ministry of Internal Affairs (declarations of employees, including special units, were made public). The police opened a criminal case against "Dmitry Orlov", the pseudonym of the activist who publicized the vulnerabilities in a flash mob. They also allegedly tried to hack the Orlov website, leaving a message which threatened physical violence if he continued his activities. The activist deleted the website as it had fulfilled its function.


List-1097

UCA activists obtained records of orders to provide food for servicemen of 18 separate motorized rifle brigades of the Russian Armed Forces, who were sent on combat missions during the Russian occupation of Crimea. Inform Napalm volunteers searched open sources of information for the social network profiles of servicemen named in the orders, and discovered photo evidence of their participation in the occupation of Crimea. Records also revealed how troops had been transferred to the Crimea, at Voinka. On January 31, 2017, the central German state TV channel ARD aired a story about the cyber war between Ukraine and Russia. The story documented the repeated cyber attacks by Russian hackers on the civilian infrastructure of Ukraine and efforts to counter Russian aggression in cyberspace, in particular the Surkov leaks. Representatives of the UCA were portrayed as the heroes of the story. Former State Duma deputy Denis Voronenkov (who received Ukrainian citizenship) made statements that Surkov was categorically against the annexation of Crimea. In response, the UCA released photos and audio recordings of the congress of the Union of Donbas Volunteers, from May 2016 in annexed Crimea and November 2016 in Moscow, at which Surkov was the guest of honor. Volunteers of the Inform Napalm community created a film about UCA's activities called ''Cyberwar: a review of successful operations of the Ukrainian Cyber Alliance in 2016''.{{Cite web, date=2017-02-02, title=Кібервійна: огляд найуспішніших публічних операцій Українського Кіберальянсу в 2016 році, url=https://informnapalm.org/ua/cyberwar-2016/, access-date=2020-03-08, website=InformNapalm.org (Українська), language=uk


References

Information technology organizations based in Ukraine Hacker groups 2016 establishments in Ukraine Internet properties established in 2016