hw_22e0ec8a8dbe4e55
Russia-based hacking group “Anonymous Sudan” poses as Islamic activists to launch DDoS attacks on Swedish airports, hospitals, banks and utilities.
In February 2023, a hacking operation attributed to a Russia-based group calling itself “Anonymous Sudan” was reported to have launched a series of distributed-denial-of-service (DDoS) attacks against multiple Swedish critical-infrastructure targets including airports, hospitals, banks, the state-owned utility Vattenfall and defence company Saab AB. The Swedish cybersecurity firm Truesec analysed the attacks and concluded the perpetrators were not Islamist activists despite their cover story; the timing, targets and sophistication pointed to Russian state-linked capabilities. The targets spanned Sweden’s national infrastructure across civil, economic and defence sectors, underscoring that hybrid threats go beyond military bases or border zones. This incident is large-scale cyber disruption rather than kinetic attack; but it is clearly a hybrid-warfare act because it hits the resilience of Sweden’s systems and forces diversion of resources. The dynamics show how adversaries use cover identities (“Islamic activists”) to obscure origin, strike broadly across sectors, and create operational stress through the ripple-effects of disruption rather than destruction. Swedish authorities treated the episode as part of their elevated hybrid-threat picture, signalling that modern attacks can target civil infrastructure to achieve strategic effect.
E/M/R/S scores
- EExistence0/4 · Not assessed
- MIntent0/4 · Not assessed
- RRussian actor link0/4 · Not assessed
- SRussian state responsibility0/4 · Not assessed
Facts
No facts
Sources
-
- Role
- discovery_lead
- Date
- 2023-01-31T23:00:00Z
In February 2023, a hacking operation attributed to a Russia-based group calling itself “Anonymous Sudan” was reported to have launched a series of distributed-denial-of-service (DDoS) attacks against multiple Swedish critical-infrastructure targets including airports, hospitals, banks, the state-owned utility Vattenfall and defence company Saab AB. The Swedish cybersecurity firm Truesec analysed the attacks and concluded the perpetrators were not Islamist activists despite their cover story; the timing, targets and sophistication pointed to Russian state-linked capabilities. The targets spanned Sweden’s national infrastructure across civil, economic and defence sectors, underscoring that hybrid threats go beyond military bases or border zones. This incident is large-scale cyber disruption rather than kinetic attack; but it is clearly a hybrid-warfare act because it hits the resilience of Sweden’s systems and forces diversion of resources. The dynamics show how adversaries use cover identities (“Islamic activists”) to obscure origin, strike broadly across sectors, and create operational stress through the ripple-effects of disruption rather than destruction. Swedish authorities treated the episode as part of their elevated hybrid-threat picture, signalling that modern attacks can target civil infrastructure to achieve strategic effect.