The great cyber attack on Russian state television

Since global media are completely silent on the subject, whereas I raised it in my 22 February essay analyzing Putin’s State of the Nation address, I am obliged to return briefly to this subject for purposes of closure.

Shortly before the live broadcast of Putin’s widely anticipated annual speech was about to begin at noon Moscow time on the 21st http://www.smotrim.ru, the website platform for all of Russia’s state television programs, both live and streaming, went dead.  That is to say, the home page was on the screen but it was a frame without content.  Then a few hours later even that disappeared, most likely by decision of Russia’s communication engineers to shut down and prepare for a reconstruction of the site.

The Kremlin said not a word about this broadcasting disaster, which had to be the result of a cyber attack waged by a state, not a prankster group, given its intensity and success in completely disabling the site.   This leads me to believe that the damage only affected the international broadcasting, meaning that Moscow had no need to make embarrassing explanations to its domestic audience.

Last night, one week after the disaster, www.smotrim.ru was back in operation, as if nothing had happened. However, the configuration for accessing the live programs is not the same as before, indicating that what was done was not merely flicking a switch but the reconstruction of the site from zero.

It is noteworthy that the problem was confined to the state news broadcasters www.smotrim.ru and www.vesti.ru   Other Russian channels, even the far more aggressive Solovyov Live channel, continued operation this past week without any problems.

Surely the Russians know who did it.  One may be certain they will take their revenge at an appropriate time and in an appropriate manner. Given the fragility of the global internet, it is stunning that this brazen attack took place at all. If I may invert the words in the soliloquy of Hermann, the ill-fated hero of Tchaikovsky’s opera Queen of Spades, spoken at the end of his calamitous wagers at cards, ‘today it is me, tomorrow it will be you.’

©Gilbert Doctorow, 2023

Translations below into French (Youri), German (Andreas Mylaeus) and Brazilian Portuguese (Evandro Menezes)

La grande cyberattaque contre la télévision d’État russe

Étant donné que les médias mondiaux sont totalement silencieux sur le sujet, alors que je l’ai soulevé dans mon article du 22 février analysant le discours de Poutine sur l’état de la nation, je suis obligé de revenir brièvement sur ce sujet afin de le clôturer.

Peu avant le début de la diffusion en direct du discours annuel très attendu de Poutine, à midi (heure de Moscou), le 21 https://smotrim.ru/, le site Web de tous les programmes de la télévision d’État russe, en direct et en streaming, s’est éteint. En d’autres termes, la page d’accueil était affichée à l’écran, mais il s’agissait d’un cadre sans contenu. Puis, quelques heures plus tard, même celui-ci a disparu, très probablement sur décision des ingénieurs en communication de Russie, qui ont décidé de fermer le site et de pourvoir à sa reconstruction.

Le Kremlin n’a pas dit un mot sur ce désastre médiatique, qui devait être le résultat d’une cyberattaque menée par un État et non par un groupe de farceurs, compte tenu de son intensité et du fait qu’il a réussi à désactiver complètement le site. Cela m’amène à penser que les dégâts n’ont affecté que la diffusion internationale, ce qui signifie que Moscou n’avait pas besoin de fournir des explications embarrassantes à son public national.

Hier soir, une semaine après la catastrophe, https://smotrim.ru/ était de nouveau opérationnel, comme si de rien n’était. Cependant, la configuration pour accéder aux programmes en direct n’est plus la même qu’avant, ce qui indique que ce qui a été fait n’était pas simplement une interruption mais la reconstruction du site à partir de zéro.

Il convient de noter que le problème s’est limité aux chaînes d’information d’État https://smotrim.ru/et https://www.vesti.ru/. Les autres chaînes russes, même la chaîne Solovyov Live, beaucoup plus agressive, ont continué à fonctionner la semaine dernière sans aucun problème.

Les Russes savent sûrement qui a fait ça. On peut être certain qu’ils prendront leur revanche au moment opportun et de la manière appropriée. Compte tenu de la fragilité de l’internet mondial, il est stupéfiant que cette attaque éhontée ait pu avoir lieu. Si je peux me permettre d’inverser les mots du soliloque d’Hermann, le héros malheureux de l’opéra de Tchaïkovski, La Dame de pique, prononcés à la fin de ses paris calamiteux aux cartes, « aujourd’hui c’est moi, demain ce sera toi ».

Der große Cyberangriff auf das russische Staatsfernsehen

Da sich die Medien weltweit zu diesem Thema ausschweigen, während ich es in meinem Aufsatz vom 22. Februar, in dem ich Putins Rede zur Lage der Nation analysierte, angesprochen habe, muss ich kurz auf dieses Thema zurückkommen, um es abzuschließen.

Kurz vor Beginn der Live-Übertragung der mit Spannung erwarteten Jahresrede Putins am 21. Dezember 2023 um 12 Uhr Moskauer Zeit (http://www.smotrim.ru ) fiel die Website-Plattform für alle Programme des russischen Staatsfernsehens, sowohl für die Live- als auch für die Streaming-Übertragung, aus. Das heißt, die Startseite war zwar auf dem Bildschirm zu sehen, aber es handelte sich um einen Rahmen ohne Inhalt. Ein paar Stunden später war auch diese Seite verschwunden, höchstwahrscheinlich durch die Entscheidung der russischen Kommunikationstechniker, die Seite abzuschalten und einen Wiederaufbau vorzubereiten.

Der Kreml hat sich mit keinem Wort zu dieser Rundfunkkatastrophe geäußert, die das Ergebnis eines Cyberangriffs sein musste, der von einem Staat und nicht von einer Gruppe von Scherzkeksen durchgeführt wurde, da er so intensiv und erfolgreich war, dass die Website vollständig abgeschaltet wurde. Dies lässt mich vermuten, dass der Schaden nur die internationale Ausstrahlung betraf, was bedeutet, dass Moskau seinem heimischen Publikum keine peinlichen Erklärungen zu geben brauchte.

Gestern Abend, eine Woche nach der Katastrophe, war www.smotrim.ru wieder in Betrieb, als ob nichts geschehen wäre. Allerdings ist die Konfiguration für den Zugriff auf die Live-Programme nicht mehr dieselbe wie zuvor, was darauf hindeutet, dass nicht einfach ein Schalter umgelegt wurde, sondern die Website von Grund auf neu aufgebaut wurde.

Es ist bemerkenswert, dass sich das Problem auf die staatlichen Nachrichtensender www.smotrim.ru und www.vesti.ru beschränkte. Andere russische Kanäle, sogar der weitaus aggressivere Solovyov Live-Kanal, setzten ihren Betrieb in der vergangenen Woche ohne Probleme fort.

Sicherlich wissen die Russen, wer es getan hat. Man kann sicher sein, dass sie sich zu gegebener Zeit und auf angemessene Weise rächen werden. Angesichts der Fragilität des globalen Internets ist es erstaunlich, dass dieser dreiste Angriff überhaupt stattgefunden hat. Wenn ich die Worte aus dem Monolog von Hermann, dem unglücklichen Helden aus Tschaikowskis Oper Pique Dame, umkehren darf, die er am Ende seiner verhängnisvollen Wette beim Kartenspiel spricht: “Heute bin ich es, morgen bist du es.”\

O grande ataque cibernético à televisão estatal russa

Uma vez que a mídia global está completamente silenciosa sobre o assunto, enquanto eu o trouxe à tona em meu ensaio de 22 de fevereiro, analisando o discurso do Presidente Vladimir Putin sobre o Estado da Nação, sou obrigado a retornar brevemente a este assunto para a fim de o dar por encerrado.

Pouco antes da transmissão ao vivo do tão esperado discurso anual de Putin começar ao meio-dia, horário de Moscou, no dia 21, smotrim.ru, a plataforma do site para todos os programas da televisão estatal russa, tanto ao vivo quanto gravados, foi desativada . Ou seja, a página inicial estava na tela, mas era um quadro sem conteúdo. Algumas horas depois, até isto desapareceu, provavelmente por decisão dos engenheiros de comunicação da Rússia de fechar e preparar a reconstrução do local.

O Kremlin não disse qualquer palavra sobre esse distúrbio da transmissão, que deve ser o resultado de um ataque cibernético realizado por um estado, não por um grupo de brincalhões, dada a intensidade e o sucesso em desativar completamente o site. Isto me leva a acreditar que o problema afetou apenas a transmissão internacional, o que significa que Moscou não precisou dar explicações embaraçosas ao público local.

Ontem à noite, uma semana após o desastre, smotrim.ru voltou a funcionar, como se nada tivesse acontecido. No entanto, a configuração de acesso aos programas ao vivo não é a mesma de antes, indicando que o que foi feito não foi apenas apertar um botão, mas a reconstrução do site do zero.

Vale ressaltar que o problema estava confinado às emissoras de notícias estatais smotrim.ru e vesti.ru.  Outros canais russos, mesmo o canal “Solovyov ao Vivo”, muito mais agressivo, continuaram operando na semana passada sem problemas.

Certamente os russos sabem quem fez isso. Pode-se ter certeza de que eles se vingarão no momento apropriado e da maneira apropriada. Dada a fragilidade da internet global, é impressionante que esse ataque descarado tenha ocorrido. Se eu puder inverter as palavras no solilóquio de Hermann, o malfadado herói da ópera “Rainha de Espadas”, de Tchaikovsky, falado no final de suas calamitosas apostas nas cartas, ‘hoje sou eu, amanhã será você’.

7 thoughts on “The great cyber attack on Russian state television

  1. I am not sure that that is what happened. I have had connectivity issues accessing several Russian sites from the US for a year. For instance, access to rt.com from my home network is flaky, but not so on the cellular network. Different networks, different internet transit routes. A couple of the largest internet transit backbones, Cogent and Lumen, announced that they canceled the transit services with major Russian backbones, such as Rascom and Rostelecom. The protocol used to inform transit providers about routes is vulnerable to tampering and could have been messed with at the time of the broadcast. The description of the issues are compatible with such an attack. Also, the fact that many Russian sites could not be accessed from outside of Russia for almost a week, but could be accessed from other countries, suggests a possible preventive counter measure against attacks coming from the US. Additionally, if it were a state actor or any sophisticated actor, the attack would have come from many countries, which explains why I could only access them when using a VPN to Russia. BTW, I still cannot get to smotrim.ru from the US.

    Like

    1. PS: this might have been perpetrated by the Russian state itself, in order to avoid disruptions to the speech by the president from abroad. Russia has tested a few times in the last years the whole disconnection of the international transit routes of the internet to verify that it would still stand on its own inside the Russian territory.

      Like

      1. PPS: if the site had to be rebuilt from scratch because it had been hopelessly hacked, then the live transmission would have been disrupted and the Russian audience would have noticed it. It was something else than your thesis suggests. Curiouser, courioser.

        Like

  2. I watched it live (caught the last 30 minutes) on RT on Odyssey. For sure though this will have disrupted a lot of ‘casual’ viewers trying to get access, mind you in the UK without a VPN it can be difficult to view RT but news sites like Vyzglyad, RIA, and TACC are easily enough accessible (as is the risible Moscow Times!) Hard to say what UK/EU policy is, it seems to be piecemeal but mostly centered around ‘banning’ RT and also PressTV these days.

    Like

  3. I watch smotrim.ru in Russia daily and I have not noticed any interruptions, slowdowns or other problems for months. I’m pretty sure it’s just censorship of whatever country you’re residing in or some other country in between that and Russia. If it’s the former (specifically on the level of your ISP), GoodbyeDPI often helps. If it’s the latter, VPN service is the workaround.
    I repeat, smotrim.ru has been fully available in Russia without any interruptions for months.

    Like

Comments are closed.