Ukraine Suspects Belarus Intelligence-Linked UNC1151 Group Over Cyberattack

The cyberattack splashed websites with a warning to "be afraid and expect the worst".

Advertisement
By Reuters | Updated: 17 January 2022 13:17 IST
Highlights
  • Russia has dismissed such fears as "unfounded"
  • Demedyuk suggested the hackers had used Google Translate
  • Russia was probably involved but gave no details

Messages left on Ukrainian websites on Friday were in three languages: Ukrainian, Russian, and Polish

Kyiv believes a hacker group linked to Belarusian intelligence carried out a cyberattack that hit Ukrainian government websites this week and used malware similar to that used by a group tied to Russian intelligence, a senior Ukrainian security official said.

Serhiy Demedyuk, deputy secretary of the national security and defence council, told Reuters that Ukraine blamed Friday's attack - which defaced government websites with threatening messages - on a group known as UNC1151 and that it was cover for more destructive actions behind the scenes.

"We believe preliminarily that the group UNC1151 may be involved in this attack," he said.

Advertisement

His comments offer the first detailed analysis by Kyiv on the suspected culprits behind the cyberattack on dozens of websites. Officials on Friday said Russia was probably involved but gave no details. Belarus is a close ally of Russia.

The cyberattack splashed websites with a warning to "be afraid and expect the worst" at a time when Russia has massed troops near Ukraine's borders, and Kyiv and Washington fear Moscow is planning a new military assault on Ukraine.

Russia has dismissed such fears as "unfounded".

The office of Belarusian President Alexander Lukashenko did not immediately respond to a request for comment about Demedyuk's remarks.

Advertisement

Russia's foreign ministry also did not immediately respond to a request for comment on his remarks. It has previously denied involvement in cyberattacks, including against Ukraine.

"The defacement of the sites was just a cover for more destructive actions that were taking place behind the scenes and the consequences of which we will feel in the near future," Demedyuk said in written comments.

Advertisement

In a reference to UNC1151, he said: "This is a cyber-espionage group affiliated with the special services of the Republic of Belarus."

'Track record'

Demedyuk, who used to be the head of Ukraine's cyber police, said the group had a track record of targeting Lithuania, Latvia, Poland and Ukraine and had spread narratives decrying the NATO alliance's presence in Europe.

Advertisement

"The malicious software used to encrypt some government servers is very similar in its characteristics to that used by the ATP-29 group," he said, referring to a group suspected of involvement in hacking the Democratic National Committee before the 2016 US presidential election.

"The group specialises in cyber espionage, which is associated with the Russian special services (Foreign Intelligence Service of the Russian Federation) and which, for its attacks, resorts to recruiting or undercover work of its insiders in the right company," Demedyuk said.

The messages left on the Ukrainian websites on Friday were in three languages: Ukrainian, Russian, and Polish. They referred to Volhynia and Eastern Galicia, where mass killings were carried out in Nazi German-occupied Poland by the Ukrainian Insurgent Army (UPA). The episode remains a point of contention between Poland and Ukraine.

Demedyuk suggested the hackers had used Google Translate for the Polish translation.

"It is obvious that they did not succeed in misleading anyone with this primitive method, but still this is evidence that the attackers 'played' on the Polish-Ukrainian relations (which are only getting stronger every day)," he said.

© Thomson Reuters 2022


Why are Galaxy S21 FE and OnePlus 9RT launching now? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Further reading: Cyberattack
Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo X200T With Zeiss Cameras to Launch in India on This Date
  2. Here's When the Realme P4 Power 5G Will Launch in India
  3. Oppo A6 5G Launched in India With 7,000mAh Battery at This Price
  4. Motorola Edge 70 Fusion Leak Reveals Full Specifications Ahead of Launch
  5. Google Pixel 10a Leak Suggests No Price Hike Over Pixel 9a
  6. Amazon's New Echo Show 11 Debuts in India With These Features
  7. iQOO 15R Will Be Launched in India Soon, Company Confirms
  8. Samsung Galaxy A57 Spotted on Certification Site With These Key Features
  9. OpenAI Offer: ChatGPT Plus Is Now Free for One Month
  10. Red Magic 11 Air Launched With Snapdragon 8 Elite, 7,000mAh Battery
  1. SpaceX Adds 29 More Starlink Satellites in Rapid Falcon 9 Launch From Florida
  2. Sony to Cede Control of Bravia TVs to China’s TCL Electronics
  3. Adobe Premiere Integrated With AI-Powered Firefly Platform; New After Effects Features Rolling Out
  4. Samsung Upgrades Bixby With Perplexity-Powered AI Features, Takes Page Out of Apple’s Playbook
  5. Google Reportedly Working On New Live Features and Agentic Mode for Gemini Assistant
  6. Redmi Note 15 Pro+, Redmi Note 15 Pro RAM and Storage Options, Key Specifications Leaked Ahead of India Launch
  7. Eddington Arrives on OTT: What You Need to Know About Joaquin Phoenix and Pedro Pascal Starrer Thriller
  8. Red Magic 11 Air Launched With Snapdragon 8 Elite, RedCore R4 Gaming Chip and 7,000mAh Battery
  9. Nikosh Chhaya Season 2 OTT Release Date Revealed: Know When and Where to Watch This Bengali Horror Series
  10. Oppo A6 5G Launched in India With 7,000mAh Battery, 50-Megapixel Camera: Price, Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.