The US, UK and EU have officially blamed Russia and specifically the Russian government for the February cyberattack on satellite communications provider Viasat, which caused outages in Central and Eastern Europe just hours before Russia launched its invasion of Ukraine.

“The European Union and its member states, together with its international partners, strongly condemn the malicious cyber activity of the Russian Federation against Ukraine, which targeted the KA-SAT, operated by Viasat,” the EU said in the joint statement, attributing the attack to Russia.
While the primary target of the attack is believed to have been the Ukrainian military, which relies heavily on satellite communications, the February 24 attack also affected internet service for thousands of Viasat customers in Ukraine and tens of thousands of customers across Europe. The attack also cut off remote access to around 5,800 wind turbines across Germany, which rely on Viasat routers for remote monitoring and control.
The attack on Viasat's network has not been fully resolved months later. Viasat says the cyberattack damaged tens of thousands of terminals beyond repair and said in its most recent analysis of the incident that it had so far shipped nearly 30,000 routers to customers in an effort to get them back online.
“This unacceptable cyberattack is yet another example of Russia’s continued irresponsible behavior in cyberspace, which has been an integral part of its illegal and unjustified invasion of Ukraine,” the EU continued, adding that the bloc is “considering further measures to deter these malicious behaviors.”
In its statement, the UK 's National Cyber Security Centre said Russia's military intelligence service was "almost certainly" behind the defacements of Ukrainian government websites in January and the deployment of destructive Whispergate malware before the intrusion.

The official attribution of the Viasat cyberattack comes weeks after SentinelOne researchers said the incident was likely the result of a new strain of Russian wiper malware called “AcidRain” designed to remotely wipe vulnerable modems. Viasat confirmed to TechCrunch that the findings were “consistent” with its own analysis of the attack.
SentinelLabs noted similarities between AcidRain and the VPNFilter malware, which the FBI in 2018 attributed to the Russian military intelligence agency known as the “Fancy Bear” hacking group – or APT28. More recently, the US National Security Agency and CISA linked the activity to Sandworm, which has been blamed for a five-year attack spree, including the devastating NotPetya that targeted hundreds of companies and hospitals around the world. Both APT28 and Sandworm have been linked to Russia’s military intelligence agency, the GRU.
Information source: techcrunch.com
