#5292: Ukraine's Cyber War: Hacking, Deception, and the IT Army

How Ukraine built a formidable cyber capability from almost nothing — and turned phone calls and phishing into artillery coordinates.

Featuring
Listen
0:00
0:00
Episode Details
Episode ID
MWP-5474
Published
Duration
22:55
Audio
Direct link
Pipeline
V5.2
TTS Engine
chatterbox-regular
Script Writing Agent
deepseek-v4-pro

AI-Generated Content: This podcast is created using AI personas. Please verify any important information independently.

Before 2014, Ukraine's cyber posture was mostly defensive, underfunded, and porous. Russian GRU and FSB units — Sandworm, APT28, Turla — treated Ukrainian networks as a testing ground, hitting the power grid, unleashing NotPetya, and probing election infrastructure. That decade of being the victim turned out to be the foundation. A generation of Ukrainian engineers spent years doing incident response on their own networks, learning how Russian operators think, move laterally, and prefer their tooling. When the full-scale war began in 2022, that intuition became the seed of an offensive capability.

The government did something no NATO country would have done: it stood up a volunteer cyber army in public, on Telegram, with a target list. The IT Army of Ukraine launched in February 2022 and grew to tens of thousands within days, mostly running DDoS attacks against Russian banks and state media. Western analysts were quietly horrified — the noise burned operational security and complicated attribution. But the volunteer energy also built a recruitment pipeline, and over time the model professionalized, feeding skilled people into more serious operations.

The state track is where the impressive work happened. The GUR hacked a Russian research institute responsible for the Yars, Bulava, Iskander-M, and Oreshnik missile programs, gaining access to production schedules, technical documentation, and testing timelines — targeting intelligence for a country being bombarded by those very missiles. The methods lean on social engineering: phishing tailored to specific engineers, fake personas built over months, and sustained phone calls to Russian soldiers and their families that extract unit locations, equipment, and rotation schedules. The hacking is the delivery mechanism; the deception is the weapon. That intelligence flows into the same targeting pipeline that uses volunteer-sourced tips, which is why the cyber campaign and the kinetic war aren't separate stories.

Downloads

Episode Audio

Download the full episode as an MP3 file

Download MP3
Transcript (TXT)

Plain text transcript file

Transcript (PDF)

Formatted PDF with styling

#5292: Ukraine's Cyber War: Hacking, Deception, and the IT Army

Corn
Daniel's question this week is about a war that most people picture in trenches and drone footage, but which has been running a second, quieter campaign through servers and inboxes and phone calls since the first day. He wants to know how Ukraine built a formidable cyber capability from almost nothing, how it's used APTs and deception and social engineering across years of fighting Russia, and how the cyberwar dimension has actually played out alongside the fighting in the trenches and cities.
Herman
And the thing that makes this worth an episode rather than a news roundup is that those two wars aren't separate. The cyber campaign feeds the kinetic one directly. A hacked server in Moscow produces coordinates for an artillery strike in Donbas. A phone call to a Russian soldier's mother produces a unit location. That convergence is the actual story.
Corn
So let's start with where the capability came from, because it didn't come from the government. Before twenty fourteen, Ukraine's cyber posture was mostly defensive, underfunded, and frankly porous. Russian GRU and FSB units, Sandworm, APT twenty eight, Turla, they treated Ukrainian networks as a testing ground. The power grid attacks, the NotPetya worm, the election infrastructure probing, all of that happened before Ukraine had anything resembling an offensive cyber capability.
Herman
And that's the baseline people miss. When the war started in twenty twenty two, Ukraine wasn't starting from a standing army of government hackers. It was starting from a decade of being the victim, which meant two things. One, a generation of Ukrainian engineers and administrators had spent years watching Russian intrusion techniques up close. They'd been doing incident response on their own networks, learning how the adversary operated. Two, there was a huge diaspora of Ukrainian tech workers outside the country who had skills and wanted to help.
Corn
The incident response point is worth dwelling on, because it's not just about learning techniques. It's about building a mindset. When you've spent five years cleaning Russian malware out of your power grid, you develop an intuition for how Russian operators think. You learn their tooling preferences, their operational rhythms, the way they move laterally through a network after initial access. That's not something you can teach in a classroom.
Herman
Right. It's the difference between reading about an adversary and having them in your network for a decade. The Ukrainian engineers who later built the offensive capability started as defenders who'd been burned repeatedly. They knew the adversary's playbook because they'd been the target of it. That's a very different starting point from, say, a Western cyber command that has to learn about an adversary through intelligence reporting and third party telemetry.
Corn
So the government did something that no NATO country would have done. It stood up a volunteer cyber army in public, on Telegram, with a target list.
Herman
The IT Army of Ukraine launched in February twenty twenty two, and the early phase was chaotic in a way that's hard to overstate. The Ministry of Digital Transformation published a Telegram channel with a list of Russian targets, banks, government portals, state media sites, and said, essentially, have at it. Tens of thousands of people joined within days. The initial operations were mostly distributed denial of service, DDoS, flooding Russian banking and government infrastructure with traffic to knock it offline.
Corn
Which sounds unsophisticated, and in some ways it was. But the coordination problem is the interesting part. You've got a volunteer force with no formal command structure, no vetting, no rules of engagement, and a target list that changes daily. How do you keep that from becoming a free for all that causes more problems than it solves?
Herman
You don't, entirely. Western analysts spent the first year of the war quietly horrified by the IT Army, because a noisy volunteer DDoS campaign against Russian banks does a few things. It burns operational security, it alerts the adversary to your capabilities, it complicates attribution for everyone, and it gives Russia propaganda material about Western-backed cyber aggression. There were serious people arguing that the IT Army was net negative, that it was making Ukraine's actual intelligence operations harder.
Corn
I remember those arguments. There was a stretch in mid twenty twenty two where every cyber policy person I knew was having the same private conversation. Publicly, nobody wanted to criticize Ukraine, but privately, the concern was that the IT Army was a liability. The DDoS attacks were loud and easy to attribute, and they were drawing Russian attention to Ukrainian cyber capabilities at exactly the moment when the state track needed to stay quiet.
Herman
And the counterargument, which I think has been vindicated, is that the volunteer energy had value beyond the operational effects. It gave people something to do. It built a sense of participation. It created a pipeline of people who started with DDoS and then developed more sophisticated skills and got folded into more serious operations. The noise was the cost of the recruitment.
Corn
And yet the model evolved. The IT Army didn't stay a DDoS mob. It professionalized, developed internal coordination tools, moved from volume attacks to more targeted operations, and started feeding intelligence to the state apparatus. The volunteer energy became a recruitment pipeline and a capability reserve rather than just a blunt instrument.
Herman
Which brings us to the state track, because that's where the impressive operations happened. The SBU's cyber department and the GUR, military intelligence, built offensive capabilities that are now on par with some of the best state actors in the world. The documented hack of Russia's missile industry institute is the flagship example.
Corn
Walk through that one, because it's the clearest case of cyber intelligence feeding battlefield outcomes.
Herman
The GUR hacked a Russian research institute responsible for the Yars, Bulava, Iskander M, and Oreshnik missile programs. That's the intercontinental ballistic missile, the submarine launched missile, the short range ballistic missile, and the new intermediate range system. Getting inside that institute meant access to production schedules, technical documentation, supply chain data, and testing timelines. For a country being bombarded by those very missiles, that's not espionage for its own sake. That's targeting intelligence, early warning, and vulnerability assessment all at once.
Corn
And the method matters. This wasn't a brute force intrusion. These operations typically start with social engineering, a phishing email tailored to a specific engineer or administrator, a fake persona built over months, a relationship cultivated until the target trusts you enough to open an attachment or click a link. The hacking is the delivery mechanism. The deception is the weapon.
Herman
That's the part of Ukraine's cyber doctrine that gets underappreciated. It's not just hacking. It's a fusion of intrusion, deception, social engineering, and information operations all pointed at the same target. The phone call operations are the purest expression of this.
Corn
Explain the phone call thing, because it sounds almost absurd until you understand the mechanism.
Herman
Ukrainian operatives, sometimes intelligence officers, sometimes volunteers, sometimes people recruited for exactly this purpose, call Russian soldiers or their families. They pose as someone the target trusts. A woman from a dating site, a fellow soldier from a different unit, a government official, a bank employee. The goal is to extract operational information. Where is your unit deployed? What equipment do you have? When are you rotating? Who's your commanding officer?
Corn
And the soldiers talk. That's the uncomfortable part. They talk because they're lonely, because they're bored, because the person on the other end of the line sounds interested in them, because they want to complain about conditions, because they want to brag about what they've done. The social engineering exploits basic human needs, and it works.
Herman
The mechanism is the same one a scammer uses, but the output is military intelligence. A soldier mentions his unit is near a specific village. That gets cross referenced with satellite imagery. A mother mentions her son's unit number and that he's been moved to a new position. That gets fed into targeting models. None of this requires a zero day exploit. It requires patience, a good script, and a willingness to talk to people for hours.
Corn
The hours part is what people don't grasp. This isn't a quick phone call. These are sustained relationships. The operative is calling every few days, building rapport, remembering details the target mentioned last week, asking about the family, about the weather, about the food. By the time the operational questions come, they don't feel like interrogation. They feel like conversation.
Herman
And that's why it's so hard to defend against. You can train soldiers not to answer direct questions about their unit. You can't train them not to be human. The loneliness, the boredom, the desire to talk to someone who seems to care, those aren't security vulnerabilities you can patch.
Corn
Which is why the APT question is hard here. When we say Ukrainian groups are APTs, advanced persistent threats, what do we actually mean? The state directed operations from the GUR and SBU clearly qualify. But the volunteer collectives blur the line. Some of them coordinate with the state. Some of them operate independently. Some of them are just skilled individuals who decided to help. Calling all of them APTs is analytically sloppy, but calling them civilians is also wrong.
Herman
The attribution problem cuts both ways. Russia can't cleanly attribute Ukrainian volunteer operations to the state, which gives Ukraine plausible deniability. But Ukraine also can't fully control what the volunteers do, which creates operational risk. A volunteer who gets caught running an operation against a Russian target could trigger an escalation that the state didn't authorize.
Corn
And yet the tradeoff has mostly worked in Ukraine's favor. The volunteer energy provided scale and speed that a state bureaucracy couldn't match, and the state track provided discipline and targeting that the volunteers lacked. The professionalization happened by layering the two, not by replacing one with the other.
Herman
The GUR hack of the missile institute is the model. That's a state operation, carefully planned, using social engineering and intrusion techniques that took months to execute. But the intelligence it produced flows into the same targeting system that uses volunteer sourced tips. The two tracks converge at the point of use.
Corn
So that's where the capability came from and how it works. Now let's talk about what it actually does on the battlefield, because the convergence is where this gets strange.
Herman
The trenches and cities dimension. The physical war in Ukraine has been attritional, grinding, artillery dominated fighting in the east, and brutal urban combat in places like Mariupol and Bakhmut. In both contexts, intelligence is the difference between hitting the right target and wasting ammunition. Cyber operations feed that intelligence pipeline directly.
Corn
A hacked Russian logistics server tells you where ammunition is being staged. A social engineering call tells you which building a unit is using as a command post. A compromised email account tells you when a rotation is happening. All of that flows into targeting decisions for artillery, drones, and raids. The cyber campaign isn't a separate war. It's the targeting system for the kinetic war.
Herman
And the deception angle runs in both directions. Ukraine has used fake personas and impersonation not just to extract information, but to inject false information. A Russian unit gets a call from someone claiming to be a local civilian reporting Ukrainian positions. The positions are fake. The Russian unit acts on them, moves into an ambush, or wastes artillery on an empty field.
Corn
That's the part that NATO doctrine doesn't really have a clean category for. It's not cyberwarfare in the sense of breaking into networks. It's not psychological operations in the traditional sense. It's a fusion of social engineering, deception, and kinetic targeting that operates through the same channels as the intelligence collection. The line between collection and deception is just a matter of what you tell the target.
Herman
The Russians have been doing their own version of this. The cyber campaign against Ukraine has been significant. The power grid attacks, the blackouts, the attempts to disrupt communications and banking. But here's the thing that surprised a lot of analysts. Russia's cyber campaign has been less decisive than expected.
Corn
Why is that? Russia has some of the most capable cyber units in the world. Sandworm alone has a track record that includes NotPetya, which caused billions in damage globally. Why hasn't that translated into strategic effect in Ukraine?
Herman
Resilience. Ukraine had a decade of being attacked to build up its defenses. When the war started, Ukrainian engineers knew exactly what Russian intrusion techniques looked like, because they'd been responding to them for years. The power grid operators had procedures for rapid restoration. The telecom providers had redundancy built in. The government had moved critical data to cloud infrastructure outside the country. Russia kept hitting the same targets with the same techniques, and Ukraine kept restoring service faster than the attacks could degrade it.
Corn
There's also the fact that cyber attacks are inherently less destructive than missiles. You can knock out a power grid for a few hours, but a cruise missile knocks it out for months. Once Russia had the option of kinetic strikes, the cyber campaign became a supplement rather than a primary weapon. The blackout attacks continued, but they were never going to win the war.
Herman
That's the lesson that NATO has been studying. Ukraine's model, volunteer energy layered with state discipline, rapid restoration, cloud migration, deception fused with targeting, that's now being taught in Western military academies. The question is whether it's replicable, or whether it's specific to Ukraine's situation.
Corn
The uncomfortable implication is that the civilian hacker army is now a permanent feature of war. Once you've shown that tens of thousands of volunteers can be mobilized through a Telegram channel and pointed at an adversary's infrastructure, you can't unshow it. The next conflict will have a volunteer cyber force from day one, on both sides.
Herman
Which raises legal and ethical questions that have no clean answers. Under the laws of war, civilians who directly participate in hostilities lose their protected status. A volunteer who launches DDoS attacks against a Russian bank is arguably a combatant. But they're sitting in a coffee shop in Warsaw, not on a battlefield. The legal framework wasn't built for this.
Corn
The Russians have made exactly that argument. They've claimed that Ukrainian volunteer hackers are legitimate military targets, which means a Ukrainian civilian in Berlin who participates in the IT Army could theoretically be targeted by Russian intelligence. The line between civilian and combatant doesn't just blur. It disappears entirely.
Herman
The grandmothers are the part that breaks the framework completely.
Corn
The grandmothers?

Hilbert: The scam baiting operations. Ukrainian grandmothers and retirees running phone operations against Russian soldiers, pretending to be lonely women to get troop locations. That was happening before the IT Army existed.
Corn
Say that again.

Hilbert: Before the IT Army. Twenty fifteen, twenty sixteen. There were organized groups of older Ukrainian women who would call Russian soldiers, pose as potential romantic partners, and extract deployment information. They'd been doing it since the first invasion. Everyone credits the IT Army, but the grandmothers were first.
Herman
I hadn't heard that. The organized scam baiting operations, I mean. I knew about individual cases, but not organized groups.

Hilbert: I was doing contract OSINT work for a small firm in D.C. around then. My actual job was reading Ukrainian volunteer battalion Telegram channels and writing summaries that nobody read. The grandmother operations were all over those channels. They had scripts, they had target lists, they had coordination. One of them got a Russian soldier to give up his unit's artillery position by telling him she wanted to send him a care package and needed the address.
Corn
What happened with the information?

Hilbert: I forwarded one of those location tips up the chain in twenty fifteen. The channel had a procedure for it. You flagged it, it went to a coordinator, supposedly it got passed to the Ukrainian military. I never heard anything back. Could have been used, could have been ignored. I'm still mildly bitter about it.
Herman
The mechanism is identical to what the state run operations do now. The only difference is the sophistication of the persona and the targeting. A grandmother pretending to be a lonely woman is doing the same social engineering that a GUR officer does, just with less tradecraft.
Corn
That's the point about the volunteer model. It didn't start in twenty twenty two with a government Telegram channel. It started years earlier, organically, because Ukrainian civilians decided to help with whatever skills they had. The IT Army formalized something that was already happening.

Hilbert: The laptop I used for that contract is still in a box somewhere. The summaries were never read. I checked once, the file server had access logs. Ninety percent of them were never opened.
Herman
That's the other side of the volunteer intelligence problem. Volume without processing capacity. You can collect enormous amounts of information from volunteer sources, but if you can't triage it, verify it, and act on it, it's just noise. The professionalization wasn't just about making the hackers better. It was about building the pipeline that turns raw tips into targeting decisions.
Corn
Which is what the GUR hack represents. That's not a tip from a grandmother. That's a carefully planned operation that produced verified, actionable intelligence about missile production. The volunteer model and the state model produce different kinds of information, and the Ukrainian system has learned to use both.

Hilbert: The grandmothers were better at getting soldiers to talk than the professionals, by the way. A Russian soldier is suspicious of a call from a number he doesn't recognize. But a woman who sounds like his mother's friend, who's been calling for two weeks, who remembers details about his hometown, that's not suspicious. That's just a nice conversation.
Corn
The patience is the weapon. That's what I keep coming back to. A DDoS attack is over in hours. A phishing campaign might run for weeks. But a social engineering operation that cultivates a relationship over months, that's a different kind of warfare entirely. It's not about technical sophistication. It's about understanding what makes a person give up information.
Herman
It scales in a way that technical exploitation doesn't. You need a zero day to break into a hardened military network. You need a phone and a script to call a soldier's mother. The barrier to entry for the second thing is essentially zero, which is why the volunteer model worked so well.

Hilbert: The scripts were passed around on Telegram. I still remember one of them. It had a section on what to do if the soldier gets suspicious. You were supposed to get offended and say something about how you thought he was different from the other men. That usually worked.
Corn
That's the mechanism. That's the actual social engineering. It's not a technical exploit. It's a psychological one, and it works because it's aimed at the thing that makes soldiers talk, which is loneliness and the desire to be seen as a person rather than a target.
Herman
That's why the convergence thesis matters. The cyber war isn't just about breaking into networks. It's about creating a continuous intelligence stream that feeds the kinetic war. The grandmothers, the IT Army, the GUR operations, they're all nodes in the same network. The output is the same thing. Where is the enemy, what are they doing, and how do we hit them.
Corn
The next conflict is going to have all of this from day one, and we don't have norms for it. The laws of war assume a clean line between civilian and combatant. The volunteer hacker army erases that line. The grandmother who extracts a troop location is a civilian by any traditional definition. But she's also directly participating in hostilities. What's her legal status? What's her liability? What happens when the other side decides she's a legitimate target?
Herman
Those questions don't have answers yet. The Ukrainian experience is being studied, but the legal and ethical framework hasn't caught up. The next war will be fought under the same ambiguity, and someone will have to decide whether a volunteer in a coffee shop is a combatant.
Corn
The two wars, the trench and the server, they were always one war. That's the thing to hold onto. The cyber campaign isn't a sideshow. It's the targeting system, the deception apparatus, and the intelligence pipeline for the kinetic fight. And the people running it aren't just soldiers. They're grandmothers and engineers and volunteers who decided to help.
Herman
Thanks to Hilbert Flumingtop for producing. This has been My Weird Prompts, the human AI collaboration podcast. If you found this useful, leave us a review wherever you listen. We'll be back soon.

This episode was generated with AI assistance. Hosts Herman and Corn are AI personalities.