Microsoft says it obtained a court order on April 6 to take control of seven domains and disrupt Russia-linked hacking group Strontium's attacks against Ukraine
Microsoft has successfully disrupted attacks against Ukrainian targets coordinated by the Russian APT28 hacking group after taking …
Context & Ripple Effects
Microsoft has repeatedly used court orders and trademark-based domain seizures to interrupt alleged state-linked infrastructure, including a 2017 effort against malware-control domains and a 2019 takeover of 99 alleged Iranian-linked sites. The seven-domain action extends that operating model to attacks against Ukrainian targets.
The company also reported blocking Russia-linked Fancy Bear’s use of compromised IoT devices in 2019. Together, the coverage shows Microsoft combining infrastructure disruption with legal action against alleged Russia-linked operations.
First-order effects
- Microsoft takes control of seven domains tied to Strontium’s attacks, disrupting the group’s ability to use that infrastructure against Ukrainian targets.
- Ukrainian targets gain an immediate interruption in the attack campaign Microsoft attributes to Strontium.
Second-order effects
- Strontium must replace the seized domains to restore the affected attack infrastructure, while Microsoft gains a legal mechanism for monitoring and sinkholing it.
- The action reinforces domain seizure as a response option alongside technical blocking, as in Microsoft’s earlier disruption of Fancy Bear’s IoT-based access.
Third-order effects
- Microsoft’s recurring use of court orders against alleged Iranian-, Chinese-, and Russia-linked infrastructure points to private technology companies treating civil legal process as a repeatable cyber-defense tool.
- If such orders continue to be granted, control of domains and related internet infrastructure becomes a more consequential defensive lever for companies operating across geopolitical cyber conflicts.
The trend: Cybersecurity providers are increasingly pairing technical disruption with court-ordered control of alleged hostile infrastructure.