Ukraine, 2015–2026: Campaigning Under Fire
Follow a decade of power disruption, destructive malware, satellite effects, espionage, influence, adaptation, and resilience.
In this lesson, you will learn to:
- Construct a campaign timeline linking at least eight cyber operations to military, political, and defensive developments.
- Explain why tactical technical success may coexist with limited strategic effect and significant civilian harm.
Ukraine, 2015–2026: Campaigning Under Fire
Ukraine provides the richest public record of cyber operations across competition and armed conflict. This lesson rejects a search for one decisive cyber weapon and instead studies persistence, combined effects, operational learning, civilian exposure, and defender adaptation.
From grid disruption to global spillover
In December 2015, attackers disrupted electricity distribution for roughly 225,000 Ukrainian customers. The operation combined months of preparation, stolen access, remote interaction with control interfaces, denial of operator control, destructive components, and disruption of customer communications. Restoration through manual operations limited duration. The lesson is not “malware turned off the grid.” Coordinated human action, knowledge of the distribution environment, and attacks on recovery processes created the effect; practiced manual capability helped contain it. CISA’s Russian state-sponsored threat summary also links the 2016 transmission event with CrashOverride/Industroyer.
NotPetya in June 2017 used a compromised Ukrainian software-update mechanism and worm-like movement to produce destruction disguised as ransomware. It escaped the intended geographic and organizational context, disrupting shipping, medicine, logistics, and other firms worldwide. The US Department of Justice indictment attributes the operation to GRU officers and describes nearly one billion dollars in losses among three named victims alone. NotPetya remains a warning about tightly coupled supply chains: operational reach can exceed target intent, and global civilian consequences can overwhelm any claim of technical precision.
Full-scale invasion revealed integration and limits
Before and during the February 2022 invasion, Ukrainian organizations faced defacement, false ransomware, multiple wipers, espionage, and communications disruption. Microsoft reported at least six Russia-aligned state actors conducting destructive or espionage activity and later documented operations against dozens of agencies and enterprises. The EU stated that the KA-SAT attack occurred about one hour before the invasion and facilitated military aggression while causing cross-border outages.
These events show integration in several forms: timing around military action, collection against diplomatic and defence targets, disruption of government and communications, cyber-enabled influence, and targeting of organizations supporting the war effort. Integration does not mean cyber effects replaced missiles or maneuver. Many services were restored, migrated, or rerouted. Cloud relocation, vendor support, threat-intelligence sharing, backups, distributed administration, and rapid incident response reduced persistence.
Mandiant’s 2024 APT44 assessment argues that Sandworm became more integrated with conventional forces while shifting relative emphasis toward intelligence collection as the war continued. That shift is strategically important. When durable disruption is hard or expensive, access may serve targeting, situational awareness, influence, and preparation. Analysts should therefore track mission alignment and collection requirements, not count only wipers and outages.
Measure warfighting value and human cost together
A balanced assessment asks two questions at once: what military or political advantage did the operation create, and what harm or risk did it impose on civilians and shared infrastructure? Cyber operations may produce localized, temporary advantage while still causing broad humanitarian or economic consequences. Conversely, loud disruption may consume adversary resources without materially changing battlefield decisions.
Build an effects ledger with intended target, direct effect, duration, affected mission, civilian dependencies, cross-border propagation, recovery pathway, intelligence lost, adversary adaptation, and evidence confidence. Revisit it after hours, days, and weeks. A service outage restored in six hours may create a decisive window—or no meaningful operational advantage at all.
The enduring lesson from Ukraine is resilience as combat power. Manual operation, segmentation, distributed backups, cloud and partner capacity, practiced incident command, trusted communications, and public credibility deny the attacker persistence and amplification. The defender is also campaigning. Every recovery teaches the adversary, so defenders must decide what to reveal, what to preserve for intelligence, and when to force eviction.
Resources
- DOJ Indictment Summary for GRU Destructive Operations — Official allegations covering the Ukrainian grid attacks, NotPetya, Olympic Destroyer, and related operations, with specific limits as an indictment rather than a conviction.
- Microsoft Special Report on Ukraine — First-party observations of destructive, espionage, and defensive activity around the 2022 invasion.
- Unearthing APT44 — Mandiant’s 2024 campaign-level assessment of Sandworm’s sabotage, espionage, influence, and wartime integration.