Lyce · Hybrid Watch

hw_1eceddfbe1d6cc32

Campagna DDoS contro diversi settori canadesi.

Il Canadian Centre for Cyber Security (Cyber Centre) ha emesso l’allerta AL23-014 il 15 settembre 2023, affermando che dal 13 settembre si sono verificate diverse campagne di distributed denial-of-service (DDoS) contro sistemi del governo federale canadese, nonché contro i settori finanziario e dei trasporti. L’allerta evidenzia che resoconti da fonti aperte collegano questa attività ad attori di minacce informatiche sponsorizzati dallo Stato russo, le cui tattiche, tecniche e procedure sono state documentate in precedenza. Le campagne sembrano mirare a interrompere l’accesso ai servizi online, ad esempio degradando le prestazioni dei siti web e rendendo difficile per gli utenti raggiungere i servizi, minando così la fiducia nelle infrastrutture critiche. Il Cyber Centre ha sottolineato che, sebbene molti di questi attacchi possano essere gestiti con una mitigazione DDoS standard, il targeting strategico di settori economici e infrastrutturali chiave suggerisce un intento più ampio della mera molestia. Nel suo avviso, il Cyber Centre ha raccomandato alle organizzazioni di rivedere le difese perimetrali, isolare le applicazioni esposte al web e consolidare i gateway per mitigare tali minacce.

Evento
2023-09-13
Pubblicazione
2023-09-12T22:00:00Z
Prima osservazione
2026-09-24T06:09:10.079Z
Stato revisione
Non valutato
Paesi
CA
Aggiornato
2026-09-27T23:56:59.668Z

Punteggi E/M/R/S

  • EEsistenza0/4 · Non valutato
  • MIntento0/4 · Non valutato
  • RLegame con attore russo0/4 · Non valutato
  • SResponsabilità dello Stato russo0/4 · Non valutato

Fatti

Nessun fatto

Fonti

  1. Ruolo
    discovery_lead
    Data
    2023-09-12T22:00:00Z

    The Canadian Centre for Cyber Security (Cyber Centre) issued Alert AL23-014 on 15 September 2023, stating that since 13 September there have been several distributed denial-of-service (DDoS) campaigns targeting Canadian federal government systems as well as the financial and transportation sectors. The alert points out that open-source reporting links this activity to Russian state-sponsored cyber threat actors, whose tactics, techniques and procedures have been documented previously. The campaigns appear to aim at disrupting access to online services — for example, degrading website performance, making it difficult for users to reach services, thereby undermining confidence in critical infrastructure. The Cyber Centre emphasised that while many of these attacks may be managed by standard DDoS mitigation, the strategic targeting of key economic and infrastructural sectors suggests a broader intent beyond mere nuisance. In its advisory, the Cyber Centre recommended organizations review perimeter defences, isolate web-facing applications and consolidate gateways to mitigate such threats.