Showing posts with label Stuxnet. Show all posts
Showing posts with label Stuxnet. Show all posts

Monday, June 30, 2014

AFP: Malware "Dragonfly" Aims at US, Europe Energy Sector


AFP news says:

The US security firm Symantec said it identified malware targeting industrial control systems which could sabotage electric grids, power generators and pipelines

This Stuxnet-like malware attack is likely to be government-sponsored, says Symantec. No word about nuclear power plants.

From Security Week quoting AFP (6/30/2014; emphasis is mine):

Malware Aims at US, Europe Energy Sector: Researchers

WASHINGTON - Cyberattackers, probably state sponsored, have been targeting energy operations in the United States and Europe since 2011 and were capable of causing significant damage, security researchers said Monday.

The US security firm Symantec said it identified malware targeting industrial control systems which could sabotage electric grids, power generators and pipelines.

"The attackers, known to Symantec as Dragonfly, managed to compromise a number of strategically important organizations for spying purposes," Symantec said in a blog post.

"If they had used the sabotage capabilities open to them, (they) could have caused damage or disruption to energy supplies in affected countries," it added.

The researchers said this malware is similar to Stuxnet, a virus believed to have been developed by the United States or Israel to contain threats from Iran.

"Dragonfly bears the hallmarks of a state-sponsored operation, displaying a high degree of technical capability," Symantec said.

"Its current main motive appears to be cyberespionage, with potential for sabotage a definite secondary capability."

Symantec said the Dragonfly, also known as Energetic Bear, appeared to be an operation based in Eastern Europe based on the hours of activity of those involved.

It said one of the tools was a Trojan that appeared to have originated in Russia.

Officials in the US and elsewhere in recent months have expressed growing concerns about cyberattacks which could cripple critical infrastructure systems such as power grids, dams or transportation systems.

The Dragonfly group has used several infection tactics including spam email with malicious attachments, and browser tools which can install malware.

Once installed on a victim's computer, the malware gathers system information and can extract data from the computer's address book and other directories.

"The Dragonfly group is technically adept and able to think strategically," Symantec said.

"Given the size of some of its targets, the group found a 'soft underbelly' by compromising their suppliers, which are invariably smaller, less protected companies."

Symantec said it had notified victims of the attacks as well as relevant national authorities, such as the US Computer Emergency Response Team.

The affected companies were not named, but Symantec said targets of Dragonfly included energy grid operators, major electricity generation firms, petroleum pipeline operators, and energy industry industrial equipment providers.

Most targets were located in the United States, Spain, France, Italy, Germany, Turkey, and Poland.


And Security Week's own article with more details including the link to Symantec's report (6/30/2014; part, emphasis is mine):

...The report builds on information released earlier this year by security firms CrowdStrike - which publicized the attack in January - and F-Secure.

The attacks on the energy sector began with malware sent via phishing emails to targeted personnel. Symantec observed the spear phishing attempts hitting organizations in the form of PDF attachments between February 2013 and June 2013, mostly targeting the US and UK. They emails were disguised as messages about administration issues such as delivery problems or issues with an account.

Later on, the group added watering hole attacks into its repertoire by compromising websites likely to be visited by people working in the industry and redirecting them to sites hosting an exploit kit known as Lightsout. The Lightsout kit has been upgraded over time, and eventually became known as the Hello exploit kit.

The third phase of the campaign involved the Trojanizing of legitimate software bundles belonging to three different industrial control system (ICS) equipment manufacturers using malware detected as Backdoor.Oldrea (Havex), according to Symantec's report (PDF).

The researchers reported that the first piece of Trojanized software was a product used to provide VPN access to programmable logic controller (PLC) type devices. The vendor discovered the attack shortly after it began, but by then there had already been 250 unique downloads of the compromised software. In the second incident, a European manufacturer of specialist PLC devices was compromised and had a software package containing a driver for one of its devices was compromised. According to Symantec, the software was available for download for at least six weeks between June and July in 2013.

The third firm was a European company that designs systems for managing wind turbines, biogas plants and other technology. In that case, the compromised software is believed to have been available for download for roughly 10 days in April 2014.

"Oldrea appears to be custom malware, either written by the group itself or created for it," according to the researchers. "This provides some indication of the capabilities and resources behind the Dragonfly group. Once installed on a victim’s computer, Oldrea gathers system information, along with lists of files, programs installed, and root of available drives. It will also extract data from the computer’s Outlook address book and VPN configuration files. This data is then written to a temporary file in an encrypted format before being sent to a remote command-and-control (C&C) server controlled by the attackers."

The majority of the command and control servers appear to be hosted on compromised servers running content management systems. Oldrea was linked to the vast majority of the infections caused by the group.

A second piece of malware used by the group was a Russian remote access Trojan known as Karagany, which was found in about five percent of the infections. The Karagany Trojan is available on the underground market. The source code for the first version of the malware was leaked in 2010. Symantec researchers suspect the Dragonfly group may have taken this source code and modified it for the group's own use. The malware can upload stolen data, download new files and run executable files on an infected machine. It is also capable of running additional plugins such as tools for collecting passwords and taking screenshots, according to Symantec.

"The attacks do have the hallmarks of a state-sponsored operation," said Vikram Thakur, principal security response manager at Symantec. "The attackers are well resourced, with a high degree of technical capability and have a lot of tools at their disposal. Their targets are of strategic interest. Their motivations appear to be espionage rather than cybercrime. As an example, we see the threat not only targeting specific industries, but also stealing credentials to connect into networks with industrial equipment. Such activity maps to espionage. Coupled with the sophistication of the campaigns, this activity lends itself to being perceived as being state sponsored."

(Full article at the link)


Well, remember the hacking incident at Monju earlier this year? A night-shift worker there downloaded a free video playback software from a supposed South Korean site and managed to infect the PC in the central control room. The PC was hacked, and email information was stolen. I haven't seen the result of the follow-up investigation of the incident.

Tuesday, November 20, 2012

French Officials Accuse US of Hacking Sarkozy's Computers, Attacks Bear Hallmarks of "Flame"


From The Hill (11/20/2012; emphasis is mine):

Report: French officials accuse US of hacking Sarkozy's computers

The United States used U.S.-Israeli spy software to hack into the French presidential office earlier this year, the French cyberwarfare agency has concluded, according to the newsmagazine l'Express.

The magazine reported late Tuesday that the computers of several close advisers to then-president Nicolas Sarkozy – including Chief of Staff Xavier Musca – were compromised in May by a computer virus that bears the hallmarks of Flame, which was allegedly created by a U.S.-Israeli team to target Iran's nuclear program. Anonymous French officials pointed the finger at the United States.

“You can be on very good terms with a 'friendly' country and still want to guarantee their unwavering support – especially during a transition period,” an official told the magazine. The alleged spying attack took place a few days before the second round of the French presidential elections, which Sarkozy lost to Francois Hollande, a socialist.

Homeland Security Secretary Janet Napolitano reportedly did not deny the allegations when asked point-blank about them.

“We have no greater partner than France, we have no greater ally than France,” Napolitano reportedly answered, at the opening of an interview with l'Express. “We cooperate in many security-related areas. I am here to further reinforce those ties and create new ones.”

In the interview, Napolitano also said that the Flame and Stuxnet viruses had “never been linked to the U.S. government.”

The White House did not return a request for comment from The Hill.


I remember there was a little noted piece of news earlier this month that the oil giant Chevron admitted that their system was infected with Stuxnet.

From CNET (11/8/2012):

Stuxnet, the sophisticated computer virus that attacked a nuclear enrichment facility in Iran two years ago, also inadvertently infected Chevron's network.

Reportedly created by the U.S. and Israel, the highly destructive worm was designed to infect Iran's Natanz nuclear facility. Rather than steal data, Stuxnet left a back door meant to be accessed remotely to allow outsiders to stealthily knock the facility offline and at least temporarily cripple Iran's nuclear program.

The oil giant discovered the malware in July 2010 after the virus escaped from its intended target, Mark Koelmel, Chevron's general manager of the earth sciences department, told The Wall Street Journal.

"I don't think the U.S. government even realized how far it had spread," he said. "I think the downside of what they did is going to be far worse than what they actually accomplished."

A Chevron spokesperson told CNET that the company's network was not adversely affected by the virus.

"Two years ago, our security systems identified the Stuxnet virus. We immediately addressed the issue without incident," a Chevron representative said.


What does Stuxnet have to do with Flame? It turns out that they share the same source codes, according to Computerworld (6/11/2012):

The two pieces of malware -- Flame for reconnaissance, Stuxnet for attack -- each included a module that appears to originate from the same source code, likely written by a single programmer.


Persistent comments that Fukushima I Nuke Plant was infected by Stuxnet don't seem to take into account, though, that their network system hadn't been quite brought up to speed in the PC era, not advanced enough to get infected.

Friday, June 1, 2012

New York Times: Obama Ordered Stuxnet Attacks on Iran Nuclear Facilities


A long article that appeared on New York Times (6/1/2012) does mention that the program was started by President Bush.

According to the article, the Nobel Peace Prize winner president's decision to use the computer virus on Iranian nuclear facilities was made in his first months in office. I remember one of the very first things he did after his inauguration was to bomb Pakistan.

From New York Times (6/1/2012):

Obama Order Sped Up Wave of Cyberattacks Against Iran
By DAVID E. SANGER

WASHINGTON — From his first months in office, President Obama secretly ordered increasingly sophisticated attacks on the computer systems that run Iran’s main nuclear enrichment facilities, significantly expanding America’s first sustained use of cyberweapons, according to participants in the program.

Mr. Obama decided to accelerate the attacks — begun in the Bush administration and code-named Olympic Games — even after an element of the program accidentally became public in the summer of 2010 because of a programming error that allowed it to escape Iran’s Natanz plant and sent it around the world on the Internet. Computer security experts who began studying the worm, which had been developed by the United States and Israel, gave it a name: Stuxnet.

At a tense meeting in the White House Situation Room within days of the worm’s “escape,” Mr. Obama, Vice President Joseph R. Biden Jr. and the director of the Central Intelligence Agency at the time, Leon E. Panetta, considered whether America’s most ambitious attempt to slow the progress of Iran’s nuclear efforts had been fatally compromised.

“Should we shut this thing down?” Mr. Obama asked, according to members of the president’s national security team who were in the room.

Told it was unclear how much the Iranians knew about the code, and offered evidence that it was still causing havoc, Mr. Obama decided that the cyberattacks should proceed. In the following weeks, the Natanz plant was hit by a newer version of the computer worm, and then another after that. The last of that series of attacks, a few weeks after Stuxnet was detected around the world, temporarily took out nearly 1,000 of the 5,000 centrifuges Iran had spinning at the time to purify uranium.

(Full article at the link)


That's an act of war by the way, without declaration. But that's nothing new in the US. Zero Hedge has a post dissecting the NY Times article, here.

Tuesday, October 5, 2010

Stuxnet and Deep Water Horizon Rig

From F-SECURE.com's Security Lab blog:

Q: Did Stuxnet sink Deepwater Horizon and cause the Mexican oil spill?
A: No, we do not think so. Although it does seem Deepwater Horizon indeed did have some Siemens PLC systems on it.
F-SECURE.com also thinks this malware was created by a government.

Now, do you remember one curious response of Obama after the oil rig sank? He dispatched SWAT teams to secure other oil rigs and platforms as if he thought it was a terrorist attack on Deepwater Horizon. Or was it a terrorist attack, using Stuxnet that some unknown government created?

It's getting curiouser and curiouser.

Monday, October 4, 2010

More on Stuxnet: 'Insider and Government Job'

according to V3.co.uk.

Stuxnet worm could have been inside job (10/01/2010 V3.co.uk)

"Delegates at the Virus Bulletin 2010 conference in Vancouver have heard that the Stuxnet worm could have been an inside job.

"Graham Cluley, senior technology consultant at Sophos, told V3.co.uk that the worm may have been written by someone with detailed knowledge of Siemens' computer systems, possibly a current or former employee.

""The message I got was that it appears to have been written by someone with inside knowledge of how Siemens' systems work," he said.

"...The malware contains the date 9 May 1979, which coincides with the execution of an Israeli businessman in Iran. But Cluley explained that this date is also, for example, the birth date of actress Rosario Dawson, and could be a red herring.

"Cluley also said that the evidence for this being a targeted attack on Iran is patchy, since Symantec reported that more attacks had been reported in India and Indonesia than in Iran.

"Mikko Hyppönen, chief research officer at F-Secure, told V3.co.uk that, based on the evidence he'd seen, the Stuxnet worm looks like a government attack, although conference presentations focused on the technical details of the attack rather than the motive.

"The obvious conclusion from Stuxnet is that there isn't any clear motive other than sabotage," he said.

"Crucially no-one has found a way that anyone could make money from this, which makes criminal involvement unlikely. If you look at the level of difficulty and complexity behind Stuxnet, it has to be a government effort."

[Emphasis is mine. The entire article at the link above.]

Spending so much effort (and time and money, probably) on a complex project for no financial gain. That surely fits the definition of a government job...

May 9, 1979 also happens to be the day when a Unabomber bomb injures Northwestern University graduate student John Harris, according to Wikipedia.

Sunday, October 3, 2010

Stuxnet Followup: Stick It to Russians

It has wrecked havoc in Iran, it has moved to China and is doing the same, as I posted a few days ago.

No one supposedly know where Stuxnet, a virus that targets industrial control systems built by Siemens, originated, though there are not many nations in the world that are capable of programming something like this.

DEBKAfile, a website in one of such nations, insinuates that it was Russians who planted the virus:

"debkafile's intelligence sources report from Iran that dozens of Russian nuclear engineers, technicians and contractors are hurriedly departing Iran for home since local intelligence authorities began rounding up their compatriots as suspects of planting the Stuxnet malworm into their nuclear program.

"Among them are the Russian personnel who built Iran's first nuclear reactor at Bushehr which Tehran admits has been damaged by the virus.

"One of the Russian nuclear staffers, questioned in Moscow Sunday, Oct. 3 by Western sources, confirmed that many of his Russian colleagues had decided to leave with their families after team members were detained for questioning at the beginning of last week. He refused to give his name because he and his colleagues intend to return to Iran if the trouble blows over and the detainees are quickly released after questioning.

"According to our sources, these detentions were the source of the announcement Saturday, Oct. 2, by Iranian Intelligence Minister Heidar Moslehi that several "nuclear spies" had been captured. "The enemy had sent electronic worms through the internet to undermine Iran's nuclear activities," he said. This was the first high-level Iranian admission that the Stuxnet virus had been planted by foreign elements to sabotage their entire nuclear program - and not just the Bushehr reactor. The comprehensive scale of the damage is attested to by the detention of Russian nuclear experts also at Natanz, Isfahan and Tehran.

"...The prime aim of their interrogation is to find out if Russian intelligence knowingly planted the destructive worm in Iran's nuclear facilities, possibly for under-the-counter pay, or were the unwitting carriers of equipment on order by Iran that had been previously infected.

"debkafile's Western sources report that the hundreds of Russian scientists, engineers and technicians employed in Iran were responsible for installing the Siemens control systems in Iran's nuclear complex and other facilities which proved most vulnerable to the cyber attack.

"They were the only foreigners with access to these heavily guarded plants. At Bushehr, for instance, the Russian personnel enjoyed full access to all its systems."

Uh huh. Sure. It may be easy to bribe Russians to do things like plant the virus. The obvious question is, WHO BRIBED Russians?

And of course, the usual question: Cui bono?

Thursday, September 30, 2010

Stuxnet Has Moved On to China

After having wrecked havoc in Iran, Stuxnet the 'cyber weapon of mass destruction' apparently has moved on to China and is busy destroying computers there.

I'm very curious to know how it traveled from Iran to China... Hmmm. Maybe Chinese should have used legit copies of Windows from Microsoft...

So, who was it who created this malware? Maybe this one and this one?

Stuxnet 'cyber superweapon' moves to China (9/30/2010 AFP via Breitbart)

"A computer virus dubbed the world's "first cyber superweapon" by experts and which may have been designed to attack Iran's nuclear facilities has found a new target -- China.

"The Stuxnet computer worm has wreaked havoc in China, infecting millions of computers around the country, state media reported this week.

"Stuxnet is feared by experts around the globe as it can break into computers that control machinery at the heart of industry, allowing an attacker to assume control of critical systems like pumps, motors, alarms and valves.

"It could, technically, make factory boilers explode, destroy gas pipelines or even cause a nuclear plant to malfunction.

"The virus targets control systems made by German industrial giant Siemens commonly used to manage water supplies, oil rigs, power plants and other industrial facilities." [The article continues.]