Norway is facing an unprecedented wave of cyberattacks targeting its national digital infrastructure. The Digdir portal, the single interface for Norwegian citizens to access all administrative and tax services, was the target of an exceptionally intense distributed denial-of-service (DDoS) attack. Although the agency managed to keep its services operational despite a massive influx of artificial requests, this assault marks a turning point in the destabilization strategy targeting the country. This offensive follows Prime Minister Jonas Gahr Støre’s announcement of a massive $9.2 billion financial aid package for Ukraine, further heightening geopolitical tensions between Oslo and Moscow.

The pro-Russian collective Server Killers claimed responsibility for the action, citing it as direct retaliation for Norway’s support of Kyiv. The operation relies on the "DDoSia" project, a recruitment platform that gamifies cybercrime. In exchange for their contribution—which involves lending the bandwidth of their own machines to saturate target servers—hacktivists are compensated in cryptocurrencies, primarily Toncoin. This method allows for the creation of a decentralized, volunteer-based strike force capable of paralyzing essential public services without requiring direct intrusion into data systems.

However, the financial dimension of this operation serves as an Achilles' heel for the attackers. While the use of digital assets offers apparent transaction ease, the public and immutable nature of blockchain ledgers allows law enforcement agencies, coordinated by Europol, to track financial flows. Investigators are leveraging this data to trace back to the infrastructure and key actors within the network. Operation Eastwood, conducted on an international scale, recently led to the dismantling of around a hundred servers and the issuance of several arrest warrants, proving that the transparency of crypto transactions can be turned against those who attempt to use them to fund illegal activities.

Beyond the technical impact, these attacks underscore the national security challenges of the cyberwarfare era. The use of cryptocurrencies to pay "task-based" contributors turns cyber-harassment into a outsourced, profitable activity that is difficult to eradicate entirely. While European intelligence services are strengthening their surveillance of complicit hosting providers and the communication networks used by these collectives, the challenge remains immense: digital infrastructures, while resilient, have become the preferred theater of a hybrid conflict where digital currency plays a central role, serving as both a logistical tool and a source of judicial evidence.