The Dune science fiction novels and subsequent movies are classics. Difficult to forget the 1965 description of the giant sandworms on the planet Arrakis, based on the equally gruesome looking real sand worms. Author Frank Herbert was stirred by his travels to the constantly moving Oregon Dunes and his imagining that they could swallow whole cities. Like most sci-fi the plot soon turns to warfare.
Easily one of the most harrowing books I have ever read is the 2008 novel Guernica by Dave Boling and alongside it the eponymous 1937 painting by Picasso, even more tormenting. It is no coincidence that German and Italian Fascist forces were alongside Franco’s Nationalists during the 1936-1939 Spanish Civil War, immediately before the Nazis initiated the blitzkrieg into Poland on 1 September 1939, triggering WWII. The invasion of the Basque town of Guernica was a trial run, a full-dress rehearsal.
A rehearsal testing how all means of defence and retaliation are neutralised by a focus on infrastructure. Railways, bridges, airports, hospitals, power plants, water supplies, media outlets. And testing the equipment and technology. Troops are emasculated without resources.
In the period since then, the concept and practice of a war of total annihilation, as blitzkrieg is also known, has progressed. The process of simultaneously using all available technologies that were available back then: tanks, aircraft, ground forces, artillery, psychological weapons; tactical operations to surround and “cut off the head”, overwhelmingly and with meticulous planning, speed and surprise the vital factors, has progressed because there are new technologies. And not just piecemeal like propeller planes to jets, or bullets to rockets. Not even computers from Alan Turing’s Bombe to Lawrence Livermore’s supercomputer El Capitan, although that is a hint. I’m talking about software. Software did not exist in 1939. It was still a theoretical concept of Ada Lovelace.
These same traditional ground tactics were deployed when Russia invaded Crimea on 27 February 2014 using unmarked soldiers, taking over the parliament, isolating the peninsular from access by Ukraine in the north and creating supply lines for Russia in the east. With history repeating itself, this proved to be the Russian “testing ground” for the later full-scale attempt to invade Ukraine on 24 February 2022.
But the 2022 Russian blitzkrieg of Ukraine did not go as planned, despite the rapid progress seen in videos of hundreds of Russian tanks overflowing highways across borders, resulting even in the short-lived occupation of Kiev airport. Unlike Germany’s almost instant takeover of most of Europe, Russia is still, 4 years later, still trying to keep Crimea and get Ukraine. No longer a blitzkrieg, it’s a war of attrition.
While increasing land and resources is the usual motivator for annexing countries, the motivator for illegal software activities has always been purely financial. For instance since 2000 there have been 224 reported examples of Chinese industrial espionage hacking in the USA alone, stealing industrial and military secrets. Much of it to secure intellectual property, patents and technology knowhow, trade secrets, that sort of thing. If money seems to be the motivation a quicker way to get some is to take a hostage. In just 2025, ransomware attacks increased a third to over 7400 instances, still concentrated on industrial, manufacturing, lawyers and medical. Where the hostage data were sufficiently sensitive, an average ransom of $1.2million was demanded.
It was soon realised that the damage caused by hacking could be used simply to create confusion. In reaction to removal of a post-Soviet monument in Estonia in 2007, a cyberattack was used to devastate Estonian infrastructure. At the height of the attack, Gohen of Control Engineering says “58 prominent Estonian websites had been knocked offline. Most of the significant ones were distributed denial-of-service (DDoS) attacks,” a primitive approach where infected computers are commandeered to flood a target site with spam to slow it down or make it crash. “The result for Estonian citizens was that cash machines and online banking services were sporadically out of action; government employees were unable to communicate with each other on email; and newspapers and broadcasters suddenly found they couldn’t deliver the news,” wrote Damien McGuinness of the BBC. Vengeance for the sake of it. Even though Estonia is part of NATO, apparently Article 5 could only be activated on the basis of traditional attacks, not cyberattacks. Convenient for the shy?
But there were no fiscal demands. The software behind factories and infrastructure is different from that of business or the internet. Software that runs and controls machinery is located on programable logic controllers or PLCs and are self-contained. It is not connected externally. It is like giant versions of a software package that might control your washing machine, except it is controlling train schedules, or factory production. So a hack to attack such software is special, has a different signature to that of ransomware. At least such PLC software is not meant to be connected externally to anything, but at times operators break the rules and the isolated system is suddenly open to a virus lurking waiting. That is how it was known that the Estonian attacks were deliberate attempts to damage operating systems. Who would ransomware a PLC?
A global hack called the WannaCry ransomware attack, linked to the Lazarus Group, a North Korean hacking team, occurred on May 12, 2017, and affected over 230,000 computers in more than 150 countries. It exploited a vulnerability in Microsoft Windows.
Russian’s Main Directorate of the General Staff of the Armed Forces of the Russian Federation, the CRU, became emboldened, as is want to happen when there is a power vacuum or a weak reaction to insurgency. Given the timing and the fact that it exploited the same MS Windows weakness it is unlikely that a different attack, by Russian actors just a month later in June 2017, was unrelated to the N Korean one. Maybe it was not N Korea? Causing $10billion in damage with global reach across America and Europe. Maersk in Denmark, USA railways, Pennsylvanian hospitals, Merk pharmaceuticals, banks, TV channels, and even Cadbury in Tasmania, were hit. But by far the worst damage was in Ukraine. Again there seemed to be no apparent rationale other than to cause havoc.
On 30 June 2017, the Associated Press reported experts agreed that the responsible virus NotPetya was masquerading as ransomware, while it was actually designed to cause maximum damage, with Ukraine being the main target. From malware to ransomware to hybrid warfare. On 28 June 2017, the Ukrainian government stated that the attack was halted. This was an extremely rapid repair job.
Then on 23 February 2022, the day before the Russian invasion of Ukraine, dozens of networks across Ukraine had fallen, pushing the country into chaos. Energy, IT, agriculture, finances, government agencies. This was all now becoming familiar. In 2014 alongside the Russian invasion of Crimea, an all-out cyberattack unconcerned with the distinction between military and civilian targets hit the peninsular. It was the forecast of cyber weaponry joining the traditional forces of armed conflict, and used simultaneously as part of a blitzkrieg.
But it had not helped Russia’s blitz into Kiev in 2022. What had happened was the earlier attack on Estonia did not go unheeded. Unlike many countries worldwide, where the counter activity had remained focussed on dealing with financial cyberfraud, Estonia was aware of the military threat of these cyberattacks and had developed a comprehensive cyber defence strategy, leading to the establishment of the NATO Cooperative Cyber Defence Center of Excellence in 2008. Estonia has since become a leader in cybersecurity, implementing advanced measures to protect its digital infrastructure.
And not limited to Estonia, showing the skill of small nations to react rapidly to complex technology threats. Not bogged down with bureaucracy and the torpor of giant institutions. A private software security company called ESET in Slovakia presented findings at the Virus Bulletin conference in Seatle in 2014 which first found the Russian culprit, the one now known as NotPetya. ESET, which is the Slovakian word for the Egyptian goddess of love Isis, did not publish their work further, so the following details are from an identical exercise around the same time by private intelligence firm iSight Partners in Virginia.
Modern viruses are giant software systems in their own right. The sophisticated ones used for serious ransom demands or to create the most infrastructure damage as part of military campaigns, are also encrypted. That proved to be both a frustration and a blessing. Jason Passwaters head of iSight’s international intelligence collection team had detected a virus embedded in a MS PowerPoint (PPT) presentation on a computer in Ukraine and handed it to John Hultquist in Virginia in September 2014 who passed it to his analytical teams to investigate. The fact that it surfaced in Ukraine was relevant. The PPT presentation it had been inserted into was a list of pro-Russian terrorists. It was bait. It was hoped that some Ukrainian, loyal and unaware, would pick up the PPT program because of the suggestive content, which when executed loaded the virus. Once on someone’s computer, it gets passed on. If that person then links into say some infrastructure software, inappropriately, say to check on something from home, whammo, that system is contaminated and collapses. Power stations shut down, trains stop running, pipelines don’t flow, satellites don’t communicate, hospital operating theatres cease to open, ATM’s malfunction, TV stations go off air.
That is part of the sophistication. The viruses exploiting MS Windows loopholes, were in normal looking documents such as a PPT for which there is always someone curious to open it as long as the bait attracted the intended audience. Others for instance were in a Word document discussing oil and gas prices luring a Polish energy company. Another was a diplomatic envoy on Europe-Russian struggles, another attracted attendees of a NATO summit in Wales and one was opened by an American scientist researching Russian foreign policy.
Hultquist’s main analyst Drew Robertson had an immediate breakthrough. He detected the IP address for the host server that sent the virus out over the internet and was able to trace it back to Europe. Amazingly the same protection allocated to the virus had not been applied to the home server, which was readily accessed, and found to contain instructions for commanding the virus software. Even more, the language was in Russian, confirming the source and purpose of the cyberware. Using that information, Robertson was able to decode the software, which turned out to be encrypted threefold. Encrypted, then that encrypted code encrypted again, then again. Someone did not want anyone to see into it. Robertson knew that since the virus code was self-contained, the encryption key to unravel itself must be inside. Usually the key to a code is held remotely, making it all but impossible to work out. So after that it was just tedious work for a cyber expert now that he had the instructions.
The result of all of that effort though was still just a string of ones and zeros, the lowest level machine code, not assembly language or higher level language to understand what the code was doing. That took more work using step by step running of the virus in an isolated simulated Windows environment, letting each bit out one at a time until a computer operation was triggered, and noting what that binary word meant. Continued in a sort of stop motion mode. That work took the iSight team about 6 weeks and the fact that it was done at all is a minor miracle, and remember that Slovakia was doing the same thing unbeknownst to them, and even earlier.
Ultimately the virus’s function was worked out. One thing that is harder than working out the function of a virus is finding where it came from and who created it. In the code once it was all deciphered Robinson found the word Arrakis02. A meaningless word unless you are a fan of Frank Herbert and his Dune novels, as he was. Whoever wrote this virus was a Dune fan. Suspecting that key Dune words might help identify other viruses, it was eventually found that many different earlier viruses also had Dune references embedded in them, indicating that they all came from the same Russian source and the same cyberattack team of individuals. Individuals fascinated with Dune. Words like houseatreides94, BasharoftheSardaukars, SalusaSecundus2, episilneridani0. Just as the discoverer of a new species has the right to allocate a name, iSight’s team called the whole NotPetya project Sandworm.
According to Wikipedia, “Sandworm is an advanced persistent threat operated by MUN 74455, a cyberwarfare unit of the GRU, Russia’s military intelligence service.” Then United States Attorney for the Western District of Pennsylvania Scott Brady described the group’s cyber campaign as “representing the most destructive and costly cyber-attacks in history.” This is not 1936 though. The world knows about blitzkrieg today, and because of the work of ESET, and Estonia and iSight (now Mandiant), the power of malicious military malware has been destructive yes, but less than optimal.
The newest malware threat is manipulation of public thought. Making people think they want the UK to separate from the EU for instance or to believe a politician is more popular than they are or that a certain distasteful behaviour is no longer offensive, or someone else won an election. A whole different ballgame.
The updated 2025 edition of the book, “Operation Sandworm” by Andy Greenberg was my main source and the inspiration for this blog.








A good folow-up from Immunity. One can see the saw of development one way and the response in return and so on and on, back and forth. As for psychological warfare, that is as old as mankind or very nearly so, one suspects. Evidence of it goes back thousands of years, at least, if one cares to look for it. Then, the Blitzkrieg. Some of the many experts on modern warfare may disagree, but the Russian invasion into Ukraine by way of Belarus would hardly qualify as a blitzkrieg, I would have thought. The co-ordination of the various means of attack was lacking and the slow execution of it was an act of intimidation rather than a blitz. It did not work as, supposedly, was envisaged, though it is impossible to know what really, never mind exactly, was and is going on in geopolitics. It’s not as though Russia is operating in a vacuum. This is a global game of chess of total politics- totalisator politics? Maybe the less said about it the better, except for the national moral and international legal implications. Where are the philosophers now when we desperately need them? Academics and scholars are lagging behind in the interpretation of the total politics of geopolitics, in a global sense as well as on the level of the nation-state. Few people venture exposing the secret business of busy international bodies of vested interest, who want stay alive to await a natural death, and if they do, it’s about that which has passed into the canals of history.
That leaves the individual who is not part of the inner circles to ignore what happens as much as possible, go with the flow directed from on high, or become a conspiracy theorist. All up, we live in an ever-changing world where stability is a figment of many people’s imagination. Well, I did not think along these terms 50 years ago, even though my scepticism was awakened, or re-awakened due to my genetical disposition and home environment, at a tender age.
Public opinion matters. Private opinion matters equally, given that thoughts and feelings have an effect as much as publicly avowed belief (or mere toleration of a narrative forced upon the public).
The Spnish civil war: Noam Chomsky wrote “On Anarchy”. Another to recommend on this topic generally is “The Power of the Powerless” by Vaclav Havel. Some veils are gradually being lifted. As readily are new veils being woven and hung out to befuddle and vex our minds. Don’t we live in interesting times, folks?
The similarity between Immunity and Sandworm never occurred to me but you are right, it is there, attack and defence. Maybe it was subconscious, good observation.
My first thought when I saw the invasion of Ukraine on TV was blitzkrieg, and my second thought as the days went on was that it was failing. I am convinced that is what Putin had hoped for. But surprise is impossible if the target knows you are coming. The advent of a complete cyber attack the day before, with the accumulated awareness and knowledge that such hacks were militarily strategic, from the work of Estonia for instance, meant that Ukraine was forewarned that the ground attack was to follow. Even a day, in today’s world, seemed to have been enough to allow a strong and prepared resistance by Ukraine. This is my assessment, I have not seen it anywhere except that Russia was unprepared for the level of opposition.
The interesting part of this story for me was the forensics used to uncover the NotPetya virus and its creators and its intention.
Like I say, this is not 1939, and the public awareness of a less naïve public contributes. It is a pity that the naivete of politicians remains. A quick reaction by global forces to Russia’s aggression at the start would have removed it and sent a message that borders are sacrosanct. The word Ukraine comes from the Slavic word for borderland. Instead, time has allowed Russia to gather resources and revert to a traditional war.
Also interesting that you mention “stability is a figment of many people’s imagination”. Just yesterday I sent a separate piece to some of our readers about “fairness” which is extracted from a chapter that discusses how balance, stability, equilibrium, are impossible in the biosphere. It is also exactly what Mark Carney from Canada said yesterday to the world about Trump.
I am impressed with this web site, really I am a big fan .