Natto Thoughts

Natto Thoughts

Ransom-War in Real Time, Final Case Study: Tumultuous 2021

What do Russia's low-trust political culture and Putin's "zero-sum sovereignty" have to do with Colonial Pipeline?

Natto Team's avatar
Natto Team
Oct 30, 2024
∙ Paid

In this Ransom-War series,1 we have made the argument that at least some Russia-origin ransomware attacks are “hybrid.” They are hybrid in two senses: 1) they have some political, not just financial, motivation, and 2) they align with Russia’s undeclared “hybrid war” against the “collective West.” 

The previous posting in the series characterized the social and political context in which Russian cybercriminals operate. As we pointed out, in Russian society, business, crime and politics overlap. Citizens cannot trust in impartial legal and judicial institutions to ensure their safety and well-being; they have to rely on informal mechanisms to protect themselves, often by finding patrons among influential figures in Russian government or intelligence. In return for protection, the criminals may find themselves doing favors for intelligence services. Moved by patriotism and/or duress, some Russian ransomware groups align at least some of their activities with Russian state strategic priori…

User's avatar

Continue reading this post for free, courtesy of Natto Team.

Or purchase a paid subscription.
© 2026 Natto Thoughts · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture