Russia’s Cyber Tactics: Lessons Learned 2022″ Flags Its Own Gaps

A Report Filed Under the Wrong Name

Copies of this file that circulate online arrive with a header reading “OCR of the Document,” attached to a National Security Archive web address. That header names neither of the two bodies that actually produced the report, and it says nothing about hacking, phishing, or Ukraine. It is a scanning-and-indexing artifact generated by the hosting site’s own metadata, not a description of what is inside the file. The document itself is titled “Russia’s Cyber Tactics: Lessons Learned 2022,” issued by Ukraine’s State Service of Special Communications and Information Protection (SSSCIP) together with its incident-response team, CERT-UA, with a foreword signed by then-Deputy Chairman Victor Zhora. It is hosted in the Cyber Vault Library of the National Security Archive and dated March 8, 2023. The mismatched header does not point to anything hidden. It points to a filing problem on a document that turns out to be worth reading on its own terms.

What CERT-UA Actually Counted

The report compiles a full calendar year of CERT-UA’s own incident logs. In 2022 the team manually processed 2,194 incidents, of which 1,148 were rated critical or high severity. The document describes a hinge partway through the year. In the first half, the dominant pattern was disruption, aimed mainly at media and telecom organizations. In the second half, the pattern changed: roughly seven in ten operations were spear-phishing campaigns built around data theft and espionage, with the remaining two or three in ten aimed at destruction. Government-sector incidents nearly doubled, from 281 in the first half to 536 in the second. From October 2022 on, the log shows a turn toward the energy sector, which the report ties to the timing of missile strikes on Ukrainian infrastructure. The quarterly totals shift again after that: 505 incidents in the third quarter, 160 of them critical or high severity, against 350 incidents in the fourth quarter, 193 of them critical or high severity. Fewer incidents overall, and more of them serious, including a cluster of multi-stage supply-chain attacks on energy infrastructure recorded in December 2022.

How CERT-UA Explained the Shift

CERT-UA traces the change to two named groups adapting under pressure: Gamaredon, described in the report as FSB-linked, and Sandworm, also tracked as Unit 74455 and as UAC-0082, described as GRU-linked. Both, according to the report, lost access points they had established before the invasion, including compromised systems inside military commissariats and VPN connections running without two-factor authentication. CERT-UA’s conclusion is that the pivot toward espionage was not a single incident or a one-off campaign but a deliberate strategic reorientation, a trade of disruption for sustained data collection once the earlier footholds closed. That is CERT-UA’s own reading of its own data, presented as an operational threat assessment rather than a closed case.

The Lull, and the Guesses Attached to It

One line in the incident logs does more work than the surrounding statistics. The report notes a drop in Gamaredon-linked activity around the middle of 2022 and lists several possible reasons without choosing among them: improved Ukrainian defenses, fatigue on the attackers’ side, a deliberate operational pause. It also floats the idea, again without settling on it, that these groups work to something like a military schedule, vacations included. The report is explicit that none of this is established; it calls the options hypotheses, not findings. As documented evidence for why the numbers dipped, the honest count is zero confirmed causes.

Two Questions the Report Leaves Open

Two limits are stated in the document itself, not filled in from outside it. First, the report does not resolve whether periods of lower incident counts reflect fewer attacks or attackers who got better at hiding them. Second, it notes isolated intrusions described as “affiliated with Iran and China” without confirming that either was state-directed. Both appear as acknowledged limits of what CERT-UA could establish from the data on hand, not as silences the report leaves unmarked.

What Got Added After the Fact

Two lines in the report sit apart from the incident counts, and the report’s own language marks them as something other than data. In his foreword, Zhora writes that Ukraine will win the cyber conflict: a stated aim, not a documented outcome. Elsewhere, the report’s authors characterize Russian operators in language that reads more like an image than a finding, built on the mid-year dip in activity rather than on any confirmed staffing or scheduling record. One is aspiration, the other inference. Neither is presented in the report as fact, and neither should be read as if it were.

Where the File Stops

The report ends where its year ends. There is no year-end tally reconciling the open question about concealment with hard evidence one way or the other. There is no passage that returns to the intrusions flagged as possibly Iranian or Chinese to confirm or rule out state involvement. A follow-up SSSCIP document, covering the first half of 2023, was published on September 25, 2023, but the 2022 report itself does not revisit either open point. It closes with a year of incident data, a set of hardening recommendations that include multifactor authentication and Active Directory hardening, and two questions the report names as its own and leaves unanswered.