Online Conflict In Gaza & Ukraine

As the geopolitical landscape changes, the Israeli-Palestinian conflict in Gaza has extended from the physical battleground into the digital domain of warfare. Today, the use of cyber warfare techniques has become an integral part of the ongoing tensions, adding a layer of complexity to an already intricate situation. 

Various hacktivist groups have targeted critical infrastructure, government agencies, and organizations in both Israel and Palestine. 

The attacks include Distributed Denial of Service (DDoS) attacks, defacement attacks and data breaches. As other countries take a stand on the war, the conflict has also spread beyond the immediate region, affecting several other countries. These cyber attacks have contributed to the unfolding events, adding another level of complexity to the ongoing chaos brought on by the Hamas invasion in Israel.

While many of the hacktivist groups might appear unsophisticated in carrying out their attacks, there are some involved with well developed skills. The recent situation in Palestine shares some common characteristics with the war in Ukraine where hacktivist groups have quickly chosen sides and entered the conflict conducting cyber attacks against both the primary antagonists, as well government and private sector supporters.  

There estimated to be at least100 active groups participating in the ongoing “cyber warfare” between Israel and Palestine.  About 20 groups are though to align with Israel, while 77 are supporting the Palestinian side. Some of these groups like KillNet have been engaged in the Ukraine war, demonstrating how geopolitical issues lie behind these hacking activities.  

Hacktivists on both sides have taken to social media and other channels like Telegram to support their side of the ideological struggle, recruiting others, and pushing their own narratives.

So far, the majority of these cyber attacks have been delivered in the form of Distributed Denial-of-Service (DDoS), though other forms are quickly emerging as well.  The victims of these attacks have been media, financial organisations, government, and telecommunications, most of which have a role in disseminating information to domestic and international audiences.  

War In Ukraine

In Ukraine, political and ideological motivated hacktivist activity has expanded past the two primary combatants and targeted governments and even private sector companies supporting a side.  Several hacktivist groups have conducted DDoS attacks against countries that have openly supported Israel to include France, India, Ukraine, and the United States.   

Iranian Hackers

Researchers that observed DDoS originating from Iranian IP addresses has decreased since the beginning of the conflict and one logical explanation may be that they are observing the cyber battlefield trying to see how these attacks are being detected and deflected by Israeli defenders, with the aim of applying this knowledge to future campaigns.

To date, the DDoS attacks on both sides have limited tactical or strategic impact, surprising given the importance given to protecting critical infrastructure, an established target for Iranian hackers, who have successfully disrupted water utilities in Israel.

Despite the Red Cross efforts to create a hacktivist code of conduct in cyberspace that adhere to the basic principles of international humanitarian laws when conducting operations in support of a state, many groups like KillNet have refused to comply. While they may not possess the high level capabilities of nation state hackers, they skilled enough to cause disruption to key industries.  At least, they can obtain the tools they need and collaborate with other more capable sympathisers.

 As well as DDoS exploits, there has been at least one notable incident where a pro-Palestinian group gained access to an app used by Israeli civilians to warn them of impending rocket attacks.  Once compromised, the hackers sent fake rocket alerts and even a fake nuclear launch warning.  There have been other forms of disinformation executed by hacktivists, but most of the claims asserted with respect to attacks they had conducted were not confirmed or substantiated, but still suggest value in spreading fake news.  

As the Palestine conflict continues. it becomes more likely that hacktivist groups will try other forms of more damaging attacks other than defacing websites and DDoS attacks.

Indeed, one pro-Palestinian group has been using a Linux-based wiper malware against Israeli targets.  Wipers were not a frequently used type of malware because they don’t provide an opportunity for an attacker to make a profit. Their main purpose is to cause disruption and destruction, making them a more common tool for nation-state actors and hacktivists.

Wipers Used Againts Ukraine

Numerous wipers were used to disrupt the Ukrainian government, critical infrastructure, and business shortly before Russia's military attack in Ukraine. Wiper malware has proven effectively destructive, often employed to cause, destruction of evidence, and cyber warfare, as it can “wipe” data, overwrite data, or corrupt data.  As more wipers are deployed, other punitive cyber attacks can be expected such as ransomware deployment to lock up systems and steal/distribute stolen data, not make money.  

Hacktivists also engage in doxxing high-value persons for the purpose of exposing their sensitive information that can be leveraged for physical and/or digital targeting. The best indicator of future behavior is past behavior, and the current Palestine conflict bears many geopolitical similarities with the war in Ukraine.

While the current  conflict in Gaza has been going on for only a few weeks, it has the potential to escalate quickly, both in terms of the cyber domain of warfare as well as the truly deadly military actions of kinetic warfare. 

Cyfirma:    CheckPoint:     Imperva:    Oodaloop:    HackerNews:   CPO Magazine:    The Record

FalconFeeds:     Cyber Express:     Image: hosnysalah

You Might Also Read: 

The Israeli-Hamas Conflict Shows Cyber Warfare Is The New Normal:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Bletchley Declaration On Artificial Intelligence Gets International Support
Ransomware Attacks Hit A Record High »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

ECSC Group

ECSC Group

ECSC is a full-service information security provider, specialising in 24/7/365 security breach detection and Artificial Intelligence (AI).

NATO Communications and Information Agency (NCIA)

NATO Communications and Information Agency (NCIA)

The NCIA Cyber Security Service Line is responsible for planning and executing all life cycle management activities for cyber security.

National Cyber Security Centre (NCSC) - Netherlands

National Cyber Security Centre (NCSC) - Netherlands

NCSC Netherlands coordinates enhancing the cyber resilience of the Netherlands in the digital domain.

SolutionsPT

SolutionsPT

SolutionsPT enables customers to strengthen their Operational Technology (OT) network to meet the ever increasing demand for performance, availability, connectivity and security.

limes datentechnik

limes datentechnik

limes datentechnik is an authority in the fields of cryptography and data compression. The FLAM product family is an internationally accepted standard for efficient and safe handling of data.

AAROH

AAROH

AAROH helps customers in Government, Law Enforcement, and Enterprises to identify, prevent, detect, resolve and protect from threats, crimes, breaches & fraud.

Renesas Electronics

Renesas Electronics

Renesas Electronics delivers trusted embedded design innovation with solutions that enable billions of connected, intelligent devices to enhance the way people work and live - securely and safely.

MicroEJ

MicroEJ

MicroEJ is a software vendor of cost-driven solutions for embedded and IoT devices.

GoSecure

GoSecure

GoSecure Managed Detection and Response helps all organizations reduce dwell time by preventing breaches before they happen.

Risk Ledger

Risk Ledger

Risk Ledger is improving the security of the global supply chain ecosystem, reducing the number of data breaches experienced through supply chain attacks by companies and consumers alike.

Secure Technology Integration Group (STIGroup)

Secure Technology Integration Group (STIGroup)

Secure Technology Integration Group, Ltd. (STIGroup) is an innovative firm that provides CyberSecurity consulting, secure IT engineering, managed security services, and human capital solutions.

ANSEC IA

ANSEC IA

ANSEC is a consultancy practice providing independent Information Assurance and IT Security focussed services to customers throughout the UK, Ireland and internationally.

Arqit Quantum

Arqit Quantum

Arqit's mission is to use transformational quantum encryption technology to keep safe the data of our governments, enterprises and citizens.

National Cyber Security Center (NCSC) - Vietnam

National Cyber Security Center (NCSC) - Vietnam

National Cyber Security Center of Vietnam has a central monitoring function and is a technical focal point for monitoring and supporting information security for people, businesses and systems.

SeQure

SeQure

SeQure is a cutting-edge startup specializing in the development of advanced security infrastructure for artificial intelligence and blockchain.

Information Security Society of Africa – Nigeria (ISSAN)

Information Security Society of Africa – Nigeria (ISSAN)

The Information Security Society of Africa – Nigeria (ISSAN) is a not-for-profit organization dedicated to the protection of Nigeria’s cyberspace.