Loading summary
A
Hello, everyone. This is Tom Uren. I'm here with the Gruck for another between two nerds. G', Day, Grac. How are you?
B
Good day, Tom. I'm fine. And yourself?
A
I'm very well. This week's edition is brought to you by island, who make an enterprise browser optimized for corporate use. Find them@island IO. So this week we've decided to talk about cyber resistance, and we're going to revisit a couple of groups we've spoken about before, particularly the Ukraine IT Army. We did a couple of episodes about them way back now, and also the Belarus cyber partisans. So the Ukrainian IT army grew up in a flurry after the initial invasion of Ukraine by Russia. We did a couple of episodes about how could Ukraine possibly make use of this outpouring of goodwill? I guess so. There's an influx of people who just want to help. But we spoke about problems of deconfliction. How do you trust any of them? What do you get them to do? I think your bright idea at one point was to get them to function as an initial access broker. Now, since that time, which was a couple of years ago, the IT army has basically disappeared out of the news. We never hear it about it anymore. So I thought it would be a good time to just revisit. And given the fullness of time, what's our assessment of whether that was good or not? I've recalled that there was a couple of stories at the time about how particular people claimed to be doing all sorts of amazing things for the IT army. I always took those with a grain of salt. In the recent, I guess, couple of years, there's been the odd example of a particular hack that has been attributed to a Ukrainian hacktivist group. Not the IT army, per se.
B
No.
A
And it's always hard to know whether that is a real hacktivist group, a group of independent people operating with no input from the state or a cover for the Ukrainian military. And it's also hard to know, you know, exactly what the impact of those hacks have had.
B
Right.
A
So that's the kind of background for the Ukraine IT Army. I'll talk about the cyber partisans when we. When we bring them up, just. Just to remind people of where they're coming from.
B
So the. The brief potted history of the. The cyber army. Basically, on the day of the invasion, there was, you know, there was this big call for, like, everyone who can help, please help. And I think it was Fedorov who went out and said, you know, we need a cyber army, like, if you can do hacking stuff, do hacking stuff to help. And there was a big sort of upswelling of support by a lot of people. Like Anonymous joined in and these, these telegram groups were sort of like organically set up. And the, the IT Cyber army one, I think, grew to 200, 300, 400,000, something like that. Just a huge number of volunteers. And you would, you would think with 400,000 people, you know, just 250,000 people or whatever the number was, Some number of them had to have some skills on his huge. Like it's.
A
Yeah, yeah. I mean, that's a large enough number that you would think is that as many hackers as China has, I don't know, you would think that you could do something with them. Right, right, right.
B
It turned out that the vast, vast majority of them were just sort of volunteering their resources of like an IP address and some bandwidth to like, do DDoS attacks, which are not particularly effective as military tools. Let's be honest.
A
You're not a game changer.
B
No. And like, it just, it didn't really do very much. But one of the things they did do is they did bring people who could do hacking together and sort of directed them generally at Russia. And so there was this huge amount of just like hacking and leaking going on. There was a lot of places that got wiped. There's a lot of defacements. There was all this DDoS. There was just. There's a froth of activity, some of it under the umbrella for the Cyber army, some of it not. But it was. Even the stuff under the umbrella was clearly not like, you know, it wasn't like 2nd Core Cyber Army, 4th Division, you know, the 3rd Battalion Company, very
A
loosely directed to an ruin range of IP addresses or something. And so I guess the thing we've learned from the last couple of years of war is that sometimes these operations can be effective when they're combined with something else.
B
Yeah, I mean, the way I've come to think of it is that cyber effects need to be converted into advantage. Like, they don't convey advantage just by existing. You have to do something to them. So if you turn out the lights, you can convert that into advantage by kidnapping the leader of another state while the lights are out. But if you turn out the lights and then do nothing, you do not convert that to advantage. It's just. It doesn't produce anything.
A
So the default, the default cyber attack is an inconvenience or an ambuggerance, and then you've got to do Something to make use of it, something else.
B
You have to convert it into advantage. It doesn't convey advantage by existing. It doesn't just make it better for you because it happened like this has to be exploited. It can't just exist on its own. That's my current framing for my PhD work is narrowing it down like this. And one of the huge problems with this, 200,000 people mobile, trying to help in any way they could and every way that they could, including quite a lot that they shouldn't have.
A
Yep.
B
You can't convert that into advantage if you don't know about it.
A
Right. Yeah. So if I remember, we spoke about this in some BTN episode and one takeaway or one thought was what you have to do is direct them away from things that are really important to you, so, so that your own services have the space to operate without getting on, conflicting with each other, stumbling upon each other's operations. And so that became a problem of how do you prioritize things to be like the most impactful things that you don't really care about? I think I remember that was our takeaway and that became quite hard because obviously you don't want to devote time to things you don't really care about, even if it's just figuring out what. Managing a whole lot of other people.
B
Right. And you know, as we said, this was just sort of like. And it was a mob, really, and because there was direction over a large amount of them, but there were also people just acting independently within that group.
A
Right. Yeah. I mean, it would take, if you had 200,000 people turn up, it would take quite some time to figure out a command structure that would organically. Right, that's right.
B
Like you don't even show up at an existing structure where you now, oh, no, we have 200,000 people. How do we expand what we're already doing? You know, there's, I think there's a lot of problems in, in managing them, but like some of the problems that they were causing, like, not just this, you know, the issues of confliction or, or, or they would try and operate on something that you were already on. And because they were so much noisier, they would get detected and then in the rollup of their operation, yours would get found out as well. Right. Sort of as a collateral damage. So there's, that's an issue that exists. But one of the other ones was that the heavy media coverage of like all the cyber activity against Russia caused Russia to become very like, they got more secure, they improved their Security posture because.
A
Right.
B
All of these Russian companies were now seeing in the news all the time. So and so got hacked and leaked. Such and such got defaced. A DDoS going on like.
A
Right. So your contention is that the, the noise and froth of the IT army hacking all over the place.
B
Not just, not just them exclusively in Helm. I'm just going to say like the entire, like Anonymous, all of the, all of the hacktivists that were helping.
A
Yep.
B
Cause this and the IT armies are shorthand in this case for that group. But it's.
A
Yep.
B
Yeah.
A
And. And so the like incident response also even companies that don't get hacked are motivated to improve their security. So.
B
Right. Which then makes it more difficult if they, they were legitimate targets. That's you know, now the, the low hanging fruit is slightly less low hanging. Which is annoying. Right. So you know, particularly at a time when you have few resources and you don't want to, you know, you want to be able to do your job without it being harder than it needs to be. And so seeing this sort of shut down ports, get services upgraded, make people apply patches, that would be sort of very annoying. Apparently though, one of the largest impacts it had was it made. There's a like DDoS protection company. They got rid of their free tier. That was sort of like the number one impact that this had overall. Made this one company very profitable.
A
A Russian company.
B
Yes, it was a Russian company. Yeah.
A
So since then what you've described is a froth of activity that drove domestic Russian security improvements. Just necessity. That activity wasn't particularly directed so it didn't really achieve much. How long did that take?
B
It actually couldn't achieve anything because it was never integrated into the state. So there was no way of converting anything they did into advantage.
A
Right, and so is that the first six months or a year or.
B
That's almost two years I think. Right. So that the like the worst of it in terms of like the most damage done was in the first sort of six months, probably even less when
A
you say damage and by damage to
B
Russia or to Ukrainian interests.
A
Right, okay. And that's just because it's cutting off opportunities. So it's really the opportunity cost that is the damage here.
B
Yes. Right, yeah. So the opportunity cost plus like conviction, which would cause some disruptions and then there'd be delays. Like if, if you're trying to attack a target and it gets ddosed.
A
Right.
B
You can't do that. You just have to wait until they're done, you know, like get it out of the System, sort of work it through. Okay. So it caused delays, which, I mean, that's not such a big deal, like a day here or there. Like, that's not as annoying as having access that you could have had cut off because someone broke in, did a hack and leak, and then the company became very serious about security, and now it's much harder to gain access. Right. So there was like, there's just a lot of things that were going on, and then it sort of consolidated into this DDoS thing that would be directed on a regular basis against specific targets. And that was a lot more manageable because you could say, okay, this week they're doing the Vladivostok shoe factory. We won't do any of our Vladivostok shoe factory hacking this week. And in a way, the positive gains to cyber or from. From the cyber activity, let's be generous. I would say minimal.
A
Right. So just from a narrow cyber perspective, like in terms. And the intelligence gained or Russian capability lost or whatever, you're giving them a not positive.
B
Non zero. A non zero score.
A
But there's some one.
B
Yeah. Out of 10 they got non zero.
A
Right, yep.
B
So, you know, on the ledger, you would say that the cyber benefit was very small, the cost was very high. That's a net loss. Right. And I said, no, it's not.
A
Well, I was going to say, are you talking about no benefit whatsoever, plus net lost, or are you saying there were some things on the side. Yeah, that probably were. Good thing. Good things were annoyances for Russia, the state, but they were offset by the opportunity cost of Ukraine not having freedom. I guess if you're a military person, you would say freedom of maneuver.
B
Yes, very much so.
A
Right.
B
But I would not say it was a loss overall. So I'd say that the political benefits that were accrued to the Ukrainian resistance effort, like the war efforts overall from this very, very public cyber movement of support that far outweighed the losses, like the opportunity cost to cyber operations at that time.
A
So it was a tremendous example of people pitching in, I guess. And it feels like it generated a number of stories about how you could help, I guess that. I don't know. Does it rally outside support?
B
I think it rallies outside support. It provides very positive news coverage of Ukrainian resistance, but all of it, and I think here's the real benefit, is that a lot of it was framed from a local perspective. So it was sort of like local boy helps Ukraine resist Russian aggression, which is a sort of more compelling story than Ukraine resists Russian aggression.
A
Like, so you Mean, like for example, in Germany there might be German hero helps Ukrainian resistance. And in the Netherlands and in France and every country could, someone would find that story out.
B
They could do their local, you know, the local hacker who is doing his part, like doing his bit and who still works at the McDonald's for his shift every day. And I think that that was very positive overall to have that sort of coverage, particularly because it was like it was local, it was linked to like, here is one of us doing something. And it gave at least the impression of successful resistance even when things were not necessarily going great on the actual front. Like the actual war was grinding into this attritional stalemate and Ukraine wasn't necessarily making huge advances or gains or anything. They're pushed back everywhere, but at least they were winning in the minds of people who believed that this cyber war thing was going on. So I think that that was very beneficial. And I also think that just having, if you have 200,000 people who believe that they are personally invested to a degree in supporting Ukraine and they feel very like viscerally this is the thing that I am doing to help, I think that that translates into some sort of political sentiment.
A
Well, it probably translates directly into some sort of funding. I would have thought like you would get people who would chip in a few bucks. You've got, I don't know, maybe 50,000 people chipping in a few bucks every now and then. That, that probably adds up over time.
B
Yeah, yeah, 100,000 here, 100,000 there. Soon enough you're talking about real money. You know, there's, there's that aspect, there's that you've got political involvement. You know, if, if their governments don't support Ukraine actively enough, there's a chance that there will be these, these vocal supporters in the voting public that could help shift political sentiment. I mean, there's just, there's a lot of benefits that you get out of it. So there's a sort of like information war. There's this political angle, the financing, and I think all of those were the real benefit that this gave. And anyone reading it as a cyber thing is confused and misreading it.
A
Too narrow, right? Yeah. So a strategic communication win and a cyber nothing burger bit of a cyber
B
loss, but you know, you can make it up in volume, I guess.
A
So moving on to the another example of a group in a kind of similar but different situation, the Belarus cyber partisans. So I first heard of them maybe 2021 or something like that, where they conducted a very successful hack against The Belarusian government. So the, the government there is pretty authoritarian. They are allied with Russia and Putin and there's a relatively, I believe, small group of technically minded people, very competent people who are regularly hacking the Belarusian government. They've got a public presence, they get representatives that turn up at different cyber related conferences. Yeah. So that's the background. And how do you rate their success?
B
So I'd say that there's a few sharp contrasts with the IT army. One of them is sort of size and purpose. So they're small, they have a very specific goal that they're trying to achieve and they're very purposeful and directed, like they know what they're trying to do. They're all on board with sort of doing this. You don't have 200,000 people sort of showing up with a, you know, what can I do to help? You have, I don't know, 3, 5, 10, 15, 20, whatever it is. Just here's what we're doing.
A
I guess on that dimension, it's the exact opposite. Right. It's not crowdsourced, it's vetted.
B
Very, very much so. And then the next thing that they have that I think is very impressive is that they have an actual strategy. Like they have a theory of victory. They've figured out here's how US doing cyber will achieve regime change in Belarus and they've thought about it and they're executing it. Like they've written it down, they've figured out how it's going to achieve their goals and they are attempting to do that. So it ranges from things like they don't leak all of the information they have at once because then it sort of saturates the market and people get sort of bored by it. So instead they sort of stage things out, they do editorial culling to make sure that the more interesting stuff is at the top. So like, the narratives are there for people. I think that they've put more thought, effort and sort of analytical rigor into their understanding of how cyber can achieve political aims than most countries have ever done. I think that they are far, far ahead of, you know, NATO, for example. Like NATO seems to be sort of looking to do sort of a thing that they could do. Like they don't.
A
Right.
B
You know, whereas these guys are like, here's how we do it, here's what the impact is going to be and here's how it's going to lead to our strategic outcome. Like, here's like, like the means and the ends and like, it's just, it's going to work now.
A
Now, Belarus is still ruled by Lukashenko. Right. The dictator there.
B
Yeah. So I don't think that they're wrong, but I think that the impact that they expect might be. They're hoping for too much, I think, from what it can actually do.
A
Yeah. It seemed to me that if you're relying solely on cyber means, you just have to be at the right place at the right time. And maybe what you do can tip circumstances in a particular direction. Like, you know, but if you're not, if you're at the wrong place at the wrong time, it's kind of.
B
This goes back to what I was saying is like, it needs to be converted into advantage.
A
Right? Yeah.
B
Right. And I think that what they're doing is stuff that makes sense, but there's. There's not someone, there's not a force or a movement or anything that can convert this into an advantage and topple the government. They're not in that position yet. I think they're going to keep going until they are so good for them. But by itself, as I've been saying, cyber just doesn't confer advantage by existing. It has to be used in some way. And I think that that's missing. Hopefully they'll find that opportunity to free their country from a regime that is extremely authoritarian and bad. That said, they have been participating as a supporting force. They've been helping Ukraine as well. I think possibly the biggest cyber attack that had an impact so far by a non state actor was when they used ransomware to stop the Belarusian railways.
A
Right. Yep.
B
Right.
A
And that, that was relatively early on in the war, wasn't it?
B
Yeah, yeah, it was sort of like the first or second month or something. It was very, it was very early on. And they, they caused a delay that made the first of all their ransomware demand was hilarious. Which was, you know, stop supporting Putin and close the borders to Russian troops.
A
Which is. And, and then we'll let the trains go.
B
We'd say, love. But when I. So I think that that's very funny, but what I find annoying actually is in, in the academic literature, they're like. And then they sort of resorted to using ransomware like a common criminal. And it's like, that is not what happened. Like, that is like, how could you read that as ransomware? In the same vein.
A
Right.
B
So that was very funny. And it actually did cause a delay in moving troops through Belarus by like eight hours or something. So, like, that's not nothing. That is, that is a small group of individual civilian hackers who got together and delayed the Russian army for eight hours, which is an incredibly impressive feat. But out of the four years of war that we've had, that eight hours doesn't. Doesn't necessarily amount to. To very much in the long run. But I think it's like, it's great that it happened. Like, it shows that. I mean, to me, what it shows is that even a successful cyber attack is not that successful.
A
Right, right. What I wrote about last week, or this newsletter, was Iranian attacks on American water infrastructure.
B
Right, right.
A
So this is a very different situation. But it seems to me that in all these cases, what you're trying to achieve is like a political outcome. Right, right, yeah.
B
For the Iranians, cyber war as a sort of politics by the means kind of thing, like, it's a. Yeah, yeah, that's right, yeah.
A
And it's. It's not the cyber attack itself or the impact, it's can you get the opponent to change their mind? And to me, it seems clearest in the US case because it's a very unpopular war. And so even though cyber attacks are just encumbrances or a pain, annoyances, like, for the US population, annoyances are actually what you want. Right. I mean, a better attack would be to make the price of petrol go even higher with cyber meetings. But I think it's the same thing. Right. That's one of the reasons the war isn't popular. It's hurting them in the hip pocket. And also, if you have to boil water, ah, what's this stupid war?
B
And.
A
And so it feels like the cyber partisans have the right theory of victory to achieve that political goal. It's just that the circumstances aren't right.
B
So, you know, I think that that's. That's an interesting point in that, you know, we often talk about how one of the problems with the cyber attack is that it's just. It's annoying. Yeah, right. Like, it's not a deadly event, it's an annoying event. It's an inconvenience, it's a hassle to deal with. It could be very expensive as well. But it's sort of. It's just these things that suck, basically. And in the case of Iran, that's sort of perfect for them as a tool because they don't want a deadly attack. Right. Like, that would be very counterproductive. They don't. They don't want something that actually causes a response of like, we have to get these guys for what they did to us.
A
Yeah.
B
You want a response of like, why Is everything more annoying because we are doing this thing? I. Disapproval.
A
You don't want cyber Pearl harbor, whatever
B
we do, cyber stubbed toes. You want to cyber move the furniture around at night so that people, you know, bark their shit in the morning when they're trying to go to the bathroom or something. That's what you're looking for is just making things more annoying and aggravating because that's the sentiment you're looking for to get the political outcome you want to achieve. And so in a way, cyber is perfect for this sort of political warfare, I guess, like this sort of. If that's the goal you're trying to achieve, cyber is good for you. If you're trying to defeat a state by hard power, cyber is probably not very useful.
A
Yeah. And it feels like the cyber partisans are a bit more in that second category where they can be very annoying, but annoying. A state doesn't really help much when the people are not voting. I guess you're right.
B
Yeah. So I think they're in a hard situation because they don't have a mechanism of converting anything that they do into advantage. Like, they do need some sort of hard power at some point. And I know that they're working with other groups and dissident politicians who are sort of outside the country, sort of activate, like working for change and things like that. So I have every hope that they all succeed in the end. But, you know, I think that cyber is not going to be sufficient, which, you know, I'm pretty sure that they accept as well. I don't think this is news. They're not going to be soon. Like, oh, why didn't we think of that?
A
BTN thinks we're screwed.
B
Yeah. Announcing we're disbanding after BTN episode 178.
A
So it seems like we've got the clearest case. Iran. It seems like there's a. I don't know if this is their theory of victory, but mine is you increase annoyance at the ballot box that applies political pressure to President Trump, whether whether it's
B
their intended goal or not. It seems like that's how it could work. If it's going to work.
A
Yep. If. If they've got a. That seems to me to be a sensible theory of victory.
B
Right.
A
And it seems like because his motivations are finely balanced, they've tried to come to a deal many times. It perhaps that could be the straw on the camel's back that gets an enduring deal.
B
Right.
A
That seems plausible to me. So when it comes to the cyber partisans, they have a strategy, I think, which actually the plan, when carried out, does delegitimize, does undermine the Belarusian government. So it's achieving a political goal, but it's. That right now is just not enough.
B
Right. It's insufficient on its own at this point. So.
A
And, And I guess there's the, you know, it's adding to their political aims or whatever. It's. It's taking a step in that direction. That's just the. On balance, the. The situation is not that that step is close enough.
B
Right, Right. It's. You can delegitimize the government, but when the government doesn't rely on legitimacy to stay in power.
A
Right. Yes.
B
It's not necessarily beneficial.
A
And then, yeah, Ukraine, it's not so much a benefit for. But because it attacks Russia or does anything, really, it's more cyber war.
B
Right, Right.
A
So it's still achieving a political goal, though. Yeah, yeah.
B
So, I mean, here we go. The takeaway here is that cyber war is politics by other means of politics.
A
Thanks, scott.
B
Thanks a lot, tom.
Podcast: Risky Bulletin
Host(s): Tom Uren and The Gruck
Date: August 10, 2026
Episode Summary by GPT-4
In this episode, Tom Uren and The Gruck revisit the concept of "cyber resistance" in the context of ongoing global conflicts. Focusing especially on the Ukrainian IT Army and Belarus' Cyber Partisans, they analyze how grassroots hacktivist groups have evolved, their real-world impact on wartime outcomes, and how cyber operations translate (or don't) into tangible strategic advantage. The discourse explores the intersection of cyber tactics, political influence, and psychological warfare, making for an insightful take on modern cyber resistance.
Formation & Hype
Actual Impact
Problems of Scale & Control
Positive: Political and Social Capital
Negative: Opportunity Cost and Hardened Targets
Conclusion on Net Effect
Background
Contrast with Ukraine IT Army
Analytical Rigor and Strategy
Achievements and Limitations
Iranian Attacks on US Infrastructure
Cyber Effect = Annoyance, Not Destruction
Cyber Attacks Often Yield 'Annoyance', not Victory
Political Utility Trumps Operational Gains
The discussion is analytical, wryly humorous, and candid—balancing skepticism about cyber operations' hype with appreciation for their broader political effects. Both hosts offer practical, insider perspectives tempered by real-world outcomes.
Cyber resistance movements like the Ukrainian IT Army and the Belarus Cyber Partisans demonstrate that large-scale, uncoordinated cyber actions rarely deliver decisive operational effect. Their true power lies in shaping narratives, catalyzing solidarity, and—at best—nudging the political landscape. Cyber as a weapon of annoyance is most effective where political pressure matters, and its strategic success depends less on technical wizardry than on the context and movements that convert digital noise into real-world change.