
A New Era of Cyberwar and the Hunters Down the Enemy's Most Dangerous Hackers
Andy Greenberg · 2019 · Technology
Original summary · AI-drafted, human-published · added by Library
Andy Greenberg traces a single Russian military hacking unit, later named Sandworm, from a minor botnet controller in 2014 to the group responsible for the first confirmed blackouts caused by malicious code and for NotPetya, the costliest cyberattack in history. The book argues that Ukraine became a live-fire testing range for cyberwarfare, and that the world's economies are now entangled in a conflict with no agreed rules, no reliable deterrent, and almost no legal recourse when digital weapons escape their intended target.
Pick a finish date and Genius lays out the days — the plan shows today's target and keeps you honest.
Start a circle and share the code — everyone sees everyone's honest place in the book. Accountability, not leaderboards.
- Security professionals who want the definitive narrative behind NotPetya and the Ukrainian grid attacks - General readers curious how a regional war can produce global economic damage through a computer worm - Policymakers and executives who need to understand critical infrastructure risk in concrete, not abstract, terms
State-sponsored hacking units often operate for years inside industrial control systems before the outside world notices they exist.
The December 2015 Ukrainian blackout proved for the first time that a purely digital intrusion could reach through a computer network and physically shut off electricity to hundreds of thousands of people.
The second Ukrainian grid attack, in December 2016, shows that Sandworm was not improvising but methodically rehearsing an automated, reusable weapon for attacking power grids anywhere.
NotPetya shows that a cyberweapon aimed at a single country's businesses can be engineered for near-total propagation once it escapes its intended boundary.
NotPetya demonstrates that the economic cost of a cyberweapon can fall overwhelmingly on parties who were never the intended target, undermining the idea that cyberattacks can be precisely controlled.
Definitive attribution of a cyberattack to a specific state and unit is possible, but it requires years of accumulated evidence and is often overtaken by political considerations rather than technical proof.
Russia treated Ukraine's power grid, businesses, and infrastructure as a proving ground for cyberweapons it might later deploy against other adversaries, using the ongoing Donbas conflict as cover.
Human resilience and manual expertise, not automated cyberdefense, were what actually kept Ukraine's grid and economy functioning through repeated attacks.
The world lacks any workable legal or normative framework for cyberattacks that cross the line between espionage and acts of war, leaving critical infrastructure everywhere vulnerable to weapons designed and tested elsewhere.
Andy Greenberg is a senior writer at WIRED specializing in cybersecurity, hacking, and information freedom. He previously covered technology and security at Forbes, has reported on Stuxnet, the dark web, and WikiLeaks, and spent years embedded with the researchers who tracked Sandworm across multiple continents.