The Montenegrin government has stated that their country is being hit with sophisticated and persistent cyberattacks that threaten their essential infrastructure.
Infrastructure hit so far includes electricity and water supplies, transportation services, and state service online portals.
Several power stations have also been hit, and have had to revert to manual operations. State-managed IT infrastructure has been taken offline in an attempt to contain the effects of the attacks.
The official government website of Montenegro is still offline at the time of writing.
The cybercriminal group behind the attack have demanded a ransom of $10 million.
Montenegro’s Minister of Public Administration, Marash Dukaj, posted this statement on the 26th of August to warn about a new wave of organised cyberattacks:
English translation:
“Although certain services are currently temporarily disabled for security reasons, the security of the accounts of citizens and business entities and their data is not in any way endangered”
The country’s Defense Minister, Rasko Knojevic, has attributed these attacks to Russian threat actors, stating on local media that there is enough evidence to suspect the attack is “directed by several Russian services“.
Both the UK and US governments have released statements warning all citizens about the risks posed by these cyberattacks, and have urged that all tourists either return or seek aid at their respective embassies.
The Political Situation
Montenegro, a small Balkan country with a population of just over 620,000 people is currently undergoing a severe political crisis. The country is split between two political ideas, one to join the European Union, and the other that support reunification with Russia.
This polarizing issue is also being fuelled by the current government’s decision to support sanctions on Russia, causing an outcry from those who support reunification.
Montenegro is currently enjoying the help of its NATO allies to help prevent cyber attacks. France’s efforts are notable, with the country having dispatched an ANSSI (French Agency for Information Systems Security) team to help defend critical systems and restore compromised networks.
Russian Cyber Attacks
While the Montenegrin Defence Minister may have stated that he has evidence linking the attack to Russian threat actors, a Cuban ransomware group has claimed responsibility for the attacks. It has supported this claim by providing critical files containing financial documents and source code from the government.
The legitimacy of these files cannot be verified, due to the download link having since become broken.
If the group are responsible, it is highly likely that they were sponsored by Russia, either through financial backing or by providing state-of-the-art malware.
Another Baltic country, Albania, was also targeted by ransomware in mid-July. This attack came from the Iranian threat actor group “HomeLand Justice“, and was believed to also be politically motivated.
The ransomware note used in the attack (shown above) was designed to encourage the Albanian government to believe the attack originated in their own country and was launched by Albanians.
Cyber attacks of this nature are becoming increasingly common. This is due in part to political motives, but also due to the substantial increase in funding being granted to cybercriminal groups by Russia and China, in order to cause disruption to countries that they perceive to be their enemies.
The UK is certainly familiar with attacks of this nature, with both the NHS and South Staffordshire Water being disrupted by cyber-attacks over the summer.









