/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft says it obtained a court order on April 6 to take control of seven domains and disrupt Russia-linked hacking group Strontium's attacks against Ukraine

Microsoft has successfully disrupted attacks against Ukrainian targets coordinated by the Russian APT28 hacking group after taking …

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

Microsoft has repeatedly used court orders and trademark-based domain seizures to interrupt alleged state-linked infrastructure, including a 2017 effort against malware-control domains and a 2019 takeover of 99 alleged Iranian-linked sites. The seven-domain action extends that operating model to attacks against Ukrainian targets.

The company also reported blocking Russia-linked Fancy Bear’s use of compromised IoT devices in 2019. Together, the coverage shows Microsoft combining infrastructure disruption with legal action against alleged Russia-linked operations.

First-order effects

  • Microsoft takes control of seven domains tied to Strontium’s attacks, disrupting the group’s ability to use that infrastructure against Ukrainian targets.
  • Ukrainian targets gain an immediate interruption in the attack campaign Microsoft attributes to Strontium.

Second-order effects

  • Strontium must replace the seized domains to restore the affected attack infrastructure, while Microsoft gains a legal mechanism for monitoring and sinkholing it.
  • The action reinforces domain seizure as a response option alongside technical blocking, as in Microsoft’s earlier disruption of Fancy Bear’s IoT-based access.

Third-order effects

  • Microsoft’s recurring use of court orders against alleged Iranian-, Chinese-, and Russia-linked infrastructure points to private technology companies treating civil legal process as a repeatable cyber-defense tool.
  • If such orders continue to be granted, control of domains and related internet infrastructure becomes a more consequential defensive lever for companies operating across geopolitical cyber conflicts.

The trend: Cybersecurity providers are increasingly pairing technical disruption with court-ordered control of alleged hostile infrastructure.

Discussion

  • @sarahasmith75 Sarah Armstrong-Smith on x
    Microsoft has obtained a court order authorizing us to take control of seven #internetdomains Strontium was using to conduct attacks against Ukraine. We have re-directed these domains to a #sinkhole controlled by Microsoft Read more in our blog... https://twitter.com/...
  • @ersincmt @ersincmt on x
    New Microsoft observed Russian GRU-connected Strontium APT's (aka APT28, Fancy Bear, Sofacy) cyber espionage ops targeting Ukrainian institutions. They also targeting govt institutions and think tanks in the US and the EU involved in foreign policy. https://blogs.microsoft.com/ .…
  • @klyngec @klyngec on x
    1/3 We have disrupted some attacks on targets in Ukraine. Strontium, a Russian GRU-connected actor, was targeting Ukrainian institutions including media organizations as well as government institutions & think tanks in the United States & the EU. https://blogs.microsoft.com/ ...