Description

Meduza, an independent Russian news website, has been targeted by repeated attempts to disrupt its digital infrastructure, researchers have revealed. In March 2024, Meduza reported facing the most intense cyber campaign in its history, just before the Russian presidential election. The distributed denial-of-service (DDoS) incident, which flooded the website with traffic, was attributed to the Russian authorities. Despite the election granting Vladimir Putin another six-year term, the onslaught against Meduza's website has continued and intensified, according to a recent report by the Sweden-based digital forensics organization Qurium. Meduza, known as one of the few Russian media outlets independent of Kremlin control, relocated to Latvia in 2014. Currently, access to its website from Russia requires the use of a VPN. In 2023, the Russian government designated Meduza as an “undesirable organization,” subjecting it to heavy fines and potential prison sentences for employees. In April 2024, Meduza faced two large-scale DDoS attacks, prompting it to seek Qurium's assistance to investigate. The first attack, lasting 48 hours from April 15, saw Meduza's website flooded with 2 billion fake user requests — hundreds of times more than usual. Qurium detected nearly 6,300 IP addresses involved in this attack. The second attack, starting on April 18, lasted only one hour but employed 10 times more IP addresses than the first. The botnet behind these attacks likely operated from compromised routers or malware in desktop computers outside Europe. Qurium's analysis identified three proxy providers facilitating the attacks: Plain Proxies, Min Proxy, and RapidSeedBox. Plain Proxies and Min Proxy were also linked to attacks against Hungarian media critical of the current political regime. Meduza, while not certain of the attackers' identity, believes the Kremlin is behind the attacks. They stated, "We know that this is a very expensive attack, and its purpose is not just to disrupt the operation of our website and mobile application, but to make our resources stop working. Only Russian authorities can have such a goal, and they will continue trying to achieve it."