"The largest cyberattack in its history": Norway targeted by pro-Russian hackers paid in crypto
Three days under the deluge. Norway has just endured the largest cyberattack ever directed against its online public services, claimed by the pro-Russian collective Server Killers in retaliation for Oslo's support of Ukraine. The identity portal that opens access to all administrative procedures in the country barely held up.
Behind this type of offensive lies an ecosystem of volunteers recruited on Telegram and paid in cryptocurrencies, which Europol is dismantling transaction by transaction.
Key Points
- The pro-Russian collective Server Killers claims responsibility for the largest DDoS attack ever suffered by Digdir, Norway's digital agency.
- The retaliation follows the announcement by Jonas Gahr Støre of 85 billion crowns (9.2 billion dollars) in aid to Ukraine.
- The DDoSia project by NoName057(16) pays its volunteers in Toncoin according to researchers from Sekoia.
- Europol's Eastwood operation has resulted in two arrests, seven arrest warrants, and more than a hundred servers taken offline.
Three days of saturation on the Norwegian identity portal
Digdir, the public agency responsible for digitizing and simplifying services of the Norwegian state, operates the infrastructure that allows a citizen to connect with a unique identifier to hundreds of administrative counters, from tax declarations to health records.
It is this gateway that has been targeted since Monday, under a flood of requests calibrated to suffocate it.
This is the largest attack against Digdir's solutions that we have ever experienced.
Are Kvistad, spokesperson for the Norwegian Digitalization Agency (Digdir), to the Associated Press
The method of operation has a name: distributed denial of service, or DDoS. It has nothing to do with a classic intrusion. No data is stolen, no server is compromised. The attackers mobilize thousands of machines to drown their target under artificial traffic until it stops responding to legitimate users. Despite the intensity, Digdir claims to have kept its services accessible almost all the time. Norwegian authorities had not responded to the claim at the time of publication.
A cyberwar declared after billions promised to Kiev
On Telegram, **Server Killers claimed the offensive and announced that they had declared cyberwar on Norway after the extension of security cooperation between Oslo and Kiev. The message has been widely reported by the Norwegian press, which links the collective, directly or indirectly, to previous attacks in the country and elsewhere in Europe.
On Sunday, during a visit to Kiev, Prime Minister Jonas Gahr Støre announced 85 billion Norwegian crowns, or about 9.2 billion dollars, included in next year's state budget in favor of Ukraine. This is the third consecutive year. The two countries also agreed to deepen their cooperation on drones and modern warfare technologies.
Norway had already experienced worse than a saturated portal. Hackers had taken control of the system that remotely operated a dam valve and opened it to increase water flow, before broadcasting a three-minute video of the control panel on Telegram, signed by a pro-Russian cybercriminal group. In Denmark, authorities attributed a destructive attack against a water operator to Z-Pentest, and an offensive against Danish sites ahead of local elections to NoName057(16). Two collectives linked to the Russian state, according to Copenhagen.
Volunteers recruited and paid in Toncoin
This is where crypto comes into play, and not in the way one might imagine. NoName057(16), a central figure in the pro-Russian hacktivist galaxy, has been operating a project called DDoSia for years: software that any sympathizer can install to lend the bandwidth of their machine, with rankings, badges, and bonuses at stake. Researchers from Sekoia, who track the group's infrastructure, have documented payments made in Toncoin to the most active contributors. A subcontracting of nuisance, gamified and paid by performance.
This choice has a cost for the attackers. Indeed, each payment leaves a public and definitive footprint on a register that anyone can consult, where cash or an opaque banking circuit would leave nothing exploitable for investigators.
The Eastwood operation, coordinated by Europol and Eurojust, resulted in two arrests, seven arrest warrants, and twenty-four searches in twelve countries, with more than a hundred servers taken offline. The U.S. Treasury has also sanctioned the host Aeza Group, a specialist in bulletproof hosting, these providers who knowingly host illegal content and ignore requests, by specifically identifying a crypto address linked to its activities.
Europol even went so far as to directly notify more than a thousand participants in DDoSia, via the application they were using, to inform them that they were identified and subject to prosecution. Servers change hosts, Telegram channels duplicate, pseudonyms renew. The transactions that paid the volunteers, however, remain readable.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

GTA 6 leaker sells memecoin before gameplay reveal

Encrypted Code Reveals $44 Million Transactions in a 'Cold Wallet' Linked to Cerimedo

Coinbase Opens Real Estate to Millions of Bitcoin Holders

Banking Processing in the New Reality: Digital Ruble and Cryptocurrencies for Foreign Trade

8-12% Promised, 5-6% Received: Expert Discusses Real Estate Returns in Europe

"Wallet Killers" in Your Browser: 40 Malicious Firefox Extensions Stealing Your Private Keys

Crypto Cards Surpass One Billion, Visa Leads the Way
How to Trade NVDA, AAPL, and Gold Without a Brokerage Account

$4 Billion Buyback: Scott Bessent's Trust Under Scrutiny

Current Account Deficit Surprises in July: What Concerns Us

With 34% of ETH Staked: How to Choose Staking in the Era of Native Compound Interest?

Arthur Hayes Claims Political Deficits and Rising Digital Assets

AI Capital Center? NVIDIA's FY 2027 Q2 Earnings Report: Growth Accelerating, AI Supercycle Enters Multi-Track Phase

Fed Study: Cryptocurrency Investors Rely on 'Belief' and Are Influenced by Historical Returns

Trump Administration Considers New Tariffs on Semiconductors, Morgan Stanley Increases Stake in Zhongji Xuchuang to 8.23%

U.S. Bond Buybacks Release Liquidity! Arthur Hayes Bets on 'These 4 Cryptocurrencies' for the Bull Market

Bitcoin vs Zcash: The Quantum Computing and Privacy Competition Begins

AI or financial advisor? An Argentine experiment tests who achieves better returns

Who is vying for SRO status in the cryptocurrency exchange market? Why are they needed?

How GPU Financing Works: The Structure of USD.AI GPU Secured Loans

Sui Co-founder Ventures into "Side Business" as Havenex Targets Institutional Crypto Financial Infrastructure

DGrid AI: Reconstructing Trust Mechanisms in AI Infrastructure with PoQ and Verification Nodes

Bitcoin Asia Recap: CZ Discusses the 'Bitcoin Century' and What Will Happen in the Next 25 Years

DEBIT Airdrop Guide: How to Share 50,000 USDT Rewards on WEEX

Will Token Be the New Dollar for Stripe?

Crypto: Tax Rules Miss the Core of Flow

CZ: AI and Crypto Integration Will Start with Stablecoins, AI Trading Takes Priority Over AI Payments

OpenAI's Tibo Changes Profile Picture, Suggesting a Reset of Quotas

The Witcher 3 to Receive a Free Remaster with Xbox Play Anywhere









