data
Image: Unsplash+/Getty

Russian network monitoring firm confirms cyberattack claimed by pro-Ukraine hackers

Russian software developer Microolap confirmed that hackers had compromised some of its systems but denied claims that they gained access to its network monitoring platform or stole data belonging to major Russian companies.

Microolap, which develops software for intercepting and analyzing network traffic, said Thursday that it had detected an attempted breach of several non-critical systems but found no evidence that hackers accessed its core infrastructure, customer data or other sensitive information.

"We urge people not to treat the attackers' claims as fact," Microolap CEO Andrey Smirnov said. "Our cybersecurity systems worked as intended: We detected the incident and kept critical data secure."

The statement came a day after a hacking group calling itself Black Spark claimed it had spent more than a month inside Microolap’s network and gained access to its internal systems, including EtherSensor, the company's network traffic analysis platform.

The hackers claimed they extracted and deleted data belonging to several Microolap customers, including Russian Railways, state banknote and document producer Goznak, VTB Bank and its leasing subsidiary, and Russian IT company NEK.TECH.

The group published several screenshots that it said showed compromised systems and data obtained during the intrusion. The authenticity of the images could not be independently verified.

Microolap acknowledged that some of its systems had been compromised but rejected the hackers’ account of the scope of the attack.

The company said its investigation found that the hackers accessed several rarely used development systems hosted by another Russian provider, an outdated version of its website and an old Bitrix24 customer management system containing a limited amount of data.

The affected systems were isolated from Microolap's core infrastructure, and their compromise did not give the attackers access to EtherSensor or data belonging to customers and partners, the company added.

Microolap said none of its production systems or components critical to EtherSensor were affected. The platform continued to operate normally, and the incident had no impact on its performance, data integrity or availability, it added.

Microolap said it had taken its outdated website offline, introduced additional security measures and was investigating the incident with the help of "one of Russia's largest cybersecurity companies," which it did not name.

Black Spark describes itself as an "underground movement in Russia." In a manifesto published on Telegram, the group said its members had remained in Russia and chosen what it called "armed resistance."

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.