1 Comment
User's avatar
User's avatar
Comment removed
Jan 12
Comment removed
Denis Stetskov's avatar

Thanks! The Kyivstar dwell time was the detail that stuck with me most. 7 months of access, and they waited for maximum impact. Same pattern with Mikord — sitting and waiting. The patience is what makes state-level actors different from typical ransomware crews.

The IT/OT convergence point is underexplored — most security frameworks still treat them as separate domains. Ukraine learned the hard way they're not.