Pro-Russian Group Launches 3-Day DoS Attack on Norwegian Government Services
The Server Killers group executed a sustained denial-of-service campaign against Norwegian public digital infrastructure, motivated by Norway's security cooperation with Ukraine. While services reportedly remained largely operational, a three-day disruption to citizen-facing portals like unified login systems highlights the real-world impact politically motivated cyberattacks can have on government continuity. This incident underscores that nation-state-aligned threat actors increasingly target allied nations' digital public services as an extension of geopolitical conflict. The ability to withstand the attack reflects the importance of pre-planned resilience measures, but also reveals that critical citizen services remain attractive and viable targets for prolonged volumetric attacks.
Tactical Insight
Immediate actions
- Activate DDoS mitigation services (e.g., Cloudflare, Akamai, or national-level scrubbing centers) at the first sign of sustained volumetric attack traffic.
- Coordinate with national cybersecurity agencies (e.g., NSM in Norway) and ISPs to filter malicious traffic upstream before it reaches government infrastructure.
Long-term improvements
- Implement redundant, geographically distributed infrastructure for critical citizen-facing portals to ensure continuity during targeted attacks.
- Establish formal threat intelligence sharing agreements with allied nations and CERTs to receive early warning of politically motivated threat actor campaigns.
- Develop and regularly test a DDoS-specific incident response playbook that includes predefined escalation paths and communication protocols.
Detection & monitoring measures
- Deploy real-time traffic anomaly detection to identify volumetric spikes indicative of DoS/DDoS activity before service degradation occurs.
- Maintain continuous uptime and performance monitoring dashboards for all public-facing government services with automated alerting thresholds.