AntiMalwareJuly 21, 2026🇷🇺Translated from Russian

Russia's Supreme Court Bans Silent Crow and Cyberpartisans BY as Extremist Organizations

The Supreme Court of the Russian Federation has recognized the cybercriminal groups Silent Crow (also known as the Silent Crow) and Cyberpartisans BY as extremist organizations and prohibited their activities on Russian territory. The decision is subject to immediate enforcement following a closed session in which the court granted an administrative claim filed by the General Prosecutor's Office.

According to the ruling, both groups conducted coordinated attacks on the information infrastructure of Russia and Belarus. Their stated goals, as presented by the authorities, include destabilizing the socio-political situation and effecting an unconstitutional change of state power.

The court established that Cyberpartisans BY belong to the Belarusian association Supratsiv (Resistance), which advocates the violent alteration of the republic's constitutional order. The group was further connected to the Polk named after Kastus Kalinouski, already banned in Russia, and to a subunit of information-psychological operations within the Armed Forces of Ukraine.

Silent Crow, previously operating under the names CyberWar and Cyber LegionsUA, is characterized in the judgment as a pro-Ukrainian alliance of politically motivated hacktivists. Its principal objective, according to the court, is to inflict damage on Russian government agencies, commercial enterprises, and critical information infrastructure.

The groups are accused of carrying out cyberattacks against the IT systems of Aeroflot, databases belonging to Rostelecom and Rosreestr, as well as servers of the Belarusian Railway. As a result of the ruling, both Silent Crow and Cyberpartisans BY now hold not only a digital but also an official extremist status in Russia, making participation in their activities or provision of support subject to criminal or administrative liability.

Related articles

HabrPolicy & Regulation

Advanced Windows Auditing Configuration Guide for Effective Incident Response in SOC Environments

The article provides a detailed walkthrough on configuring advanced audit policies in Windows 10 and Windows 11 to generate meaningful security events for incident investigation. It explains the role of the LSASS service in logging activities to the Security event log and contrasts basic auditing with the more granular advanced auditing that offers 53 subcategories. The guide covers enabling key subcategories such as Logon, Process Creation, and Account Management using auditpol commands, along with registry tweaks for PowerShell Script Block Logging and command-line auditing in process creation events. Practical tests demonstrate real-world events including successful and failed logons (Event IDs 4624 and 4625), process creation with arguments (Event ID 4688), and user account creation (Event IDs 4720 and 4732). All steps are performed on a VMware Workstation virtual machine running Windows 10 Pro 22H2 to avoid impacting production systems.

SecuritylabPolicy & Regulation

How CISOs Can Speak to CEOs: Translating Cyber Risks into Business Impact and Financial Consequences

The July 2025 Aeroflot cyber incident, claimed by Silent Crow and Belarusian Cyber-Partisans, demonstrated how technical vulnerabilities quickly translate into canceled flights, regulatory investigations, stock market reactions, and direct executive accountability. The article examines the persistent communication gap between CISOs, who focus on metrics like EDR coverage and mean time to detect, and CEOs, who prioritize costs, operational disruptions, revenue loss, and personal liability. Research from EY and Splunk highlights differing perceptions of threats and success measures, while real-world cases such as Marks & Spencer, Jaguar Land Rover, Clorox, Change Healthcare, SolarWinds, and Uber show how contractor weaknesses, missing MFA, and delayed disclosures lead to hundreds of millions in damages and legal actions. Regulatory developments, including SEC charges against CISOs and Russia's 420-FZ with turnover-based fines, further force cybersecurity discussions into the boardroom. The piece provides a practical translation table showing how technical warnings should be reframed using concrete business scenarios and financial impacts. It concludes that both CISOs and CEOs must initiate conversations around unacceptable events, downtime costs, and risk reduction versus post-incident consequences.

BoletimSecPolicy & Regulation

EU Forces Google to Open Android Microphone, Camera and Screen Access for Rival AI Assistants

The European Union has ordered Google to provide competing AI assistants with the same level of access to sensitive Android resources that is currently reserved for Gemini. The ruling covers eleven system functions, including voice activation, home button integration, background execution, and on-device AI model access. Rival assistants will also gain real-time environmental data streams from the microphone, camera, screen, and speakers under identical consent and notification rules applied to Google services. Additional capabilities include cross-app interaction, messaging, scheduling, device settings control, and multi-step task automation. Screen automation will allow assistants to operate apps inside a virtual window while the user performs other activities. Most changes are scheduled for Android 18 by 1 August 2027, while simultaneous activation of multiple assistants by voice keyword will arrive in Android 19 no later than 1 August 2028. Access to the most sensitive functions may require objective security certification and explicit user authorization.

HabrPolicy & Regulation

Walk In, You've Been Recognized: The Evolution of Identification Technologies in Modern Access Control Systems

PERCo has expanded its PERCo-Web access control system with new BLE-enabled readers, companion mobile apps, and a joint facial recognition solution developed with the CRТ group. The update provides an opportunity to examine how identification methods in physical access control have developed without any single technology fully displacing the others. Traditional proximity and MIFARE cards remain the foundation, while QR codes, NFC, BLE, and biometrics each occupy specific niches based on convenience, security, and regulatory requirements. Russian Federal Law 572-FZ has fundamentally changed facial biometrics deployment by mandating use of the Unified Biometric System (EBS) or accredited commercial systems (KBS) for authentication. The article explains the technical workflow from reader to controller, the cryptographic protections of modern cards, the contactless advantages of BLE, and the privacy and compliance considerations that now make facial recognition a 'technology of trust' rather than simple convenience.