WWIII Weapon of destruction: Highly destructive malware used to knock-out power to thousands of homes in Ukraine! First known instance of someone using malware to generate a power outage.
iSIGHT's report suggests a troubling escalation in malware-controlled conflict that has consequences for industrialized nations everywhere.
Highly destructive malware that infected at least three regional power authorities in Ukraine led to a power failure that left hundreds of thousands of homes without electricity last week, researchers said. The outage left about half of the homes in the Ivano-Frankivsk region of Ukraine without electricity, Ukrainian news service TSN reported in an article posted a day after the December 23 failure.
The report went on to say that the outage was the result of malware that disconnected electrical substations.
On Monday, researchers from security firm iSIGHT Partners said they had obtained samples of the malicious code that infected at least three regional operators.
They said the malware led to "destructive events" that in turn caused the blackout.
If confirmed it would be the first known instance of someone using malware to generate a power outage.
"It's a milestone because we've definitely seen targeted destructive events against energy before-oil firms, for instance-but never the event which causes the blackout," John Hultquist, head of iSIGHT's cyber espionage intelligence practice, told Ars. "It's the major scenario we've all been concerned about for so long." Researchers from antivirus provider ESET have confirmed that multiple Ukrainian power authorities were infected by "BlackEnergy," a package discovered in 2007 that was updated two years ago to include a host of new functions, including the ability to render infected computers unbootable.
More recently, ESET found, the malware was updated again to add a component dubbed KillDisk, which destroys critical parts of a computer hard drive and also appears to have functions that sabotage industrial control systems.
The latest BlackEnergy also includes a backdoored secure shell (SSH) utility that gives attackers permanent access to infected computers.
Until now, BlackEnergy has mainly been used to conduct espionage on targets in news organizations, power companies, and other industrial groups.
While ESET stopped short of saying the BlackEnergy infections hitting the power companies were responsible for last week's outage, the company left little doubt that one or more of the BlackEnergy components had that capability.
In a blog post published Monday, ESET researchers wrote: Our analysis of the destructive KillDisk malware detected in several electricity distribution companies in Ukraine indicates that it is theoretically capable of shutting down critical systems.
However, there is also another possible explanation.
The BlackEnergy backdoor, as well as a recently discovered SSH backdoor, themselves provide attackers with remote access to infected systems.
After having successfully infiltrated a critical system with either of these trojans, an attacker would, again theoretically, be perfectly capable of shutting it down.
In such case, the planted KillDisk destructive trojan would act as a means of making recovery more difficult.
Over the past year, the group behind BlackEnergy has slowly ramped up its destructive abilities.
Late last year, according to an advisory from Ukraine's Computer Emergency Response Team, the KillDisk module of BlackEnergy infected media organizations in that country and led to the permanent loss of video and other content.
The KillDisk that hit the Ukrainian power companies contained similar functions but was programmed to delete a much narrower set of data, ESET reported. KillDisk had also been updated to sabotage two computer processes, including a remote management platform associated with the ELTIMA Serial to Ethernet Connectors used in industrial control systems.
In 2014, the group behind BlackEnergy, which iSIGHT has dubbed the Sandworm gang, targeted the North Atlantic Treaty Organization, Ukrainian and Polish government agencies, and a variety of sensitive European industries. iSIGHT researchers say the Sandworm gang has ties to Russia, although readers are cautioned on attributing hacking attacks to specific groups or governments. According to ESET, the Ukrainian power authorities were infected using booby-trapped macro functions embedded in Microsoft Office documents.
If true, it's distressing that industrial control systems used to supply power to millions of people could be infected using such a simple social-engineering ploy.
It's also concerning that malware is now being used to create power failures that can have life-and-death consequences for large numbers of people.
Ukrainian authorities are investigating a suspected hacking attack on its power grid, the Reuters news service reported last week.
ESET has additional technical details about the latests BlackEnergy package here.
While Saudi Arabia's largest gas producer was also infected by destructive malware in 2012, there's no confirmation it affected production.
iSIGHT's report suggests a troubling escalation in malware-controlled conflict that has consequences for industrialized nations everywhere.
http://www.thebigwobble.org/2016/01/wwiii-weapon-of-destruction-highly.html
iSIGHT's report suggests a troubling escalation in malware-controlled conflict that has consequences for industrialized nations everywhere.
Highly destructive malware that infected at least three regional power authorities in Ukraine led to a power failure that left hundreds of thousands of homes without electricity last week, researchers said. The outage left about half of the homes in the Ivano-Frankivsk region of Ukraine without electricity, Ukrainian news service TSN reported in an article posted a day after the December 23 failure.
The report went on to say that the outage was the result of malware that disconnected electrical substations.
On Monday, researchers from security firm iSIGHT Partners said they had obtained samples of the malicious code that infected at least three regional operators.
They said the malware led to "destructive events" that in turn caused the blackout.
If confirmed it would be the first known instance of someone using malware to generate a power outage.
"It's a milestone because we've definitely seen targeted destructive events against energy before-oil firms, for instance-but never the event which causes the blackout," John Hultquist, head of iSIGHT's cyber espionage intelligence practice, told Ars. "It's the major scenario we've all been concerned about for so long." Researchers from antivirus provider ESET have confirmed that multiple Ukrainian power authorities were infected by "BlackEnergy," a package discovered in 2007 that was updated two years ago to include a host of new functions, including the ability to render infected computers unbootable.
More recently, ESET found, the malware was updated again to add a component dubbed KillDisk, which destroys critical parts of a computer hard drive and also appears to have functions that sabotage industrial control systems.
The latest BlackEnergy also includes a backdoored secure shell (SSH) utility that gives attackers permanent access to infected computers.
Until now, BlackEnergy has mainly been used to conduct espionage on targets in news organizations, power companies, and other industrial groups.
While ESET stopped short of saying the BlackEnergy infections hitting the power companies were responsible for last week's outage, the company left little doubt that one or more of the BlackEnergy components had that capability.
In a blog post published Monday, ESET researchers wrote: Our analysis of the destructive KillDisk malware detected in several electricity distribution companies in Ukraine indicates that it is theoretically capable of shutting down critical systems.
However, there is also another possible explanation.
The BlackEnergy backdoor, as well as a recently discovered SSH backdoor, themselves provide attackers with remote access to infected systems.
After having successfully infiltrated a critical system with either of these trojans, an attacker would, again theoretically, be perfectly capable of shutting it down.
In such case, the planted KillDisk destructive trojan would act as a means of making recovery more difficult.
Over the past year, the group behind BlackEnergy has slowly ramped up its destructive abilities.
Late last year, according to an advisory from Ukraine's Computer Emergency Response Team, the KillDisk module of BlackEnergy infected media organizations in that country and led to the permanent loss of video and other content.
The KillDisk that hit the Ukrainian power companies contained similar functions but was programmed to delete a much narrower set of data, ESET reported. KillDisk had also been updated to sabotage two computer processes, including a remote management platform associated with the ELTIMA Serial to Ethernet Connectors used in industrial control systems.
In 2014, the group behind BlackEnergy, which iSIGHT has dubbed the Sandworm gang, targeted the North Atlantic Treaty Organization, Ukrainian and Polish government agencies, and a variety of sensitive European industries. iSIGHT researchers say the Sandworm gang has ties to Russia, although readers are cautioned on attributing hacking attacks to specific groups or governments. According to ESET, the Ukrainian power authorities were infected using booby-trapped macro functions embedded in Microsoft Office documents.
If true, it's distressing that industrial control systems used to supply power to millions of people could be infected using such a simple social-engineering ploy.
It's also concerning that malware is now being used to create power failures that can have life-and-death consequences for large numbers of people.
Ukrainian authorities are investigating a suspected hacking attack on its power grid, the Reuters news service reported last week.
ESET has additional technical details about the latests BlackEnergy package here.
While Saudi Arabia's largest gas producer was also infected by destructive malware in 2012, there's no confirmation it affected production.
iSIGHT's report suggests a troubling escalation in malware-controlled conflict that has consequences for industrialized nations everywhere.
http://www.thebigwobble.org/2016/01/wwiii-weapon-of-destruction-highly.html
» Baghdad and Erbil agree to resume oil... and SOMO announces an agreement of "many points."
» Intelligence announces the confiscation of millions of oil derivatives and the seizure of 58 vehicle
» Al-Musawi: Iraq tends to Chinese companies to implement projects for these reasons
» The Committee of Experts announces the procedures for selecting the Council of the Commissioner for
» The final dispute.. The Sunni hawks gather under the wing of al-Sudani, waiting to pounce on al-Halb
» Al-Khalidi: The percentage of the operational budget in Iraq is terrifying, being the highest in the
» https://earthiq.news/archives/216050
» Al-Sudanese confirmations from Karbala: We aspire to contract with international companies to implem
» Al-Rafidain: advances of employees and salaries ranging between 5 million and 25 million dinars
» Amer Al-Jawahiry to / NINA /: The large deficit in the upcoming budget is scary and will be repeated
» More than 50 million dollars... the region's losses due to the cessation of oil exports
» For the first time in years, dollarization is declining in 5 vital sectors in Iraq
» Reuters: Paris court embarrassed Türkiye and Kurdistan
» The Ministry of Oil reveals, via Shafaq News, a preliminary agreement to resume exporting Kurdistan
» Al-Sudani: The Karbala refinery will provide 70% of Iraq's need for oil products and $3 billion for
» Report: 8 thousand American dead in Iraq and the "change" of the Iranian regime has become acceptabl
» About $4 billion in Iraqi Central Bank auction sales within a month
» Fears of the collapse of oil prices and the delay in the budget put Iraq on an "uncharted road"
» An Iraqi government official expects the dollar to drop to 1,400 dinars by the end of the week
» Dollar exchange rates in the Iraqi market
» "Al-Iqtisad News" monitors the exchange rates of the dollar against the dinar
» Referring the budget to the Parliamentary Finance Committee and directing to expedite its study
» Over $236 Million Central Bank Sales at Auction Today
» Details of the collapse of the building under construction in Baghdad
» An informed source: Oil will resume pumping from Kurdistan within the next 48 hours
» A political analyst comments on Iraq's accession to the Convention for the Protection of Water Areas
» Martyrs: 113 million dinars as a real estate grant and housing allowance for those included
» Iraq markets its dry canal to neighboring countries and the world
» Integrity controls waste of public money and manipulation in Muthanna departments
» Mazhar Saleh: Financing foreign trade in the “recovery” stage
» Attention awaits approval of the budget
» "The Suspicious Concealment"... the full story of Al-Halbousi's "surprising" leave
» Al-Sudani chairs a new meeting of the Coordination Committee between the governorates today
» Zaidan and Al-Alaq are discussing follow-up to the Central Bank's cases before the courts
» With the intervention of the Kurdish ministers.. Details of the Baghdad and Erbil agreement to resum
» The Ministry of Oil announces the total amount of crude oil exports during March
» 17 days after it arrived in Parliament.. Parliamentary Finance "knows nothing" about the budget unti
» Within two days... Kurdistan's oil will resume its march outside Iraq under the supervision of Baghd
» The dollar continues to decline against the Iraqi dinar in Baghdad's exchanges
» A slight decline.. The Central Bank sells more than $236 million
» Once again... dollar prices are falling in Baghdad's exchange offices
» New agreement between Baghdad and Erbil
» The State Company for Textile and Leather Industries supplies the American University with its handm
» Al-Halbousi is on leave awaiting the return of al-Sadr, and protests are expected on April 9
» The dollar continues to decline in the markets of Baghdad and the Kurdistan region
» Central Bank: Gradual decline of the dollar in the parallel market
» The parliament session ignores the budget..and deputies: the Presidency is afraid of making it for t
» Iraq uses Japanese techniques to desalinate sea water and remove the salty tongue in Basra
» Electricity: Efforts to increase the free national gas investment by operating the stations
» Al-Halbousi's office reveals the fact that there are differences with Al-Sudani
» Tomorrow.. Al-Halbousi visits Cairo
» Mohsen Al-Mandalawi refers the draft federal budget law to the Parliamentary Finance Committee
» Iraqi oil exports to America decreased for the second week in a row
» Zaidan and Al-Alaq are discussing follow-up cases of the Central Bank before the courts
» The Ministry of Labor: Adopting a new method to speed up social searches
» Al-Sudani directs to address any delay that may accompany the distribution of Ramadan baskets
» Agriculture: The current season exceeded expectations and secured all irrigations for the wheat and
» Parliamentary Finance: Any financial deficit in the budget will not affect employee salaries and app
» Zaidan and Al-Alaq discuss the issues of the Central Bank before the courts
» The exchange rates of the dollar in the Iraqi market today
» Al-Rafidain determines the percentage of advances of employees and retirees
» Calling to speed up its study.. Mandalawi refers the draft budget to the Finance Committee
» For the third day in a row... Customs and Finance employees continue their demonstrations and strike
» Happy Birthday newday
» Al-Sudani: The government has placed at the top of its priorities the increase in the production cap
» The central bank refuses to open a window for selling dollars to citizens
» Minister of Industry: The ministry has 102,000 employees, and we need a maximum of 50,000 employees
» An American report reveals two trends within the framework for dealing with Kurdistan's oil after th
» American Institute: Washington will lose from the region's oil shutdown, and it must take these step
» The Communications Commission is carrying out surveys along the border strip with Syria
» Al-Araji and the head of the Military Industrialization Authority stress the importance of opening I
» Al-Khazraji: Iraq's continued import of oil derivatives is surprising
» Central Bank: We expect an increase in the amounts of foreign transfers in the coming days
» From 5 points... Disclosure of the details of an agreement between Baghdad and Erbil regarding the r
» Central Bank: Opening a window to sell dollars to citizens violates international regulations and no
» Disclosure of the contents of (initial agreement) between Baghdad and Erbil regarding oil sales
» Basra.. Dismantling a network to transfer foreign workers to Iraq
» Al-Araji stresses the importance of opening Iraqi production lines to manufacture weapons
» Al-Halbousi is accused of bargaining and extortion for refusing to present the budget
» Parliamentary Finance sets the official date for putting the budget on the dialogue table
» The conditions for federalism are present.. Kurdistan's oil setback changes the rules of negotiation
» Internal collapse and implicit messages.. Behind the scenes of Al-Halbousi's long vacation request
» Al-Halbousi's struggle with sovereignty delays the interests of 40 million citizens
» Al-Fath: The budget will be approved after the Eid holiday and under these conditions
» According to a Kurdish media network: Erbil and Baghdad agree on a new mechanism for selling the oil
» Rasheed Bank: The premiums withheld from retirees will be returned
» Planning: 2023 is the year of implementing service, infrastructure and vital projects in accordance
» Al-Bayati: Al-Sudani is continuing with his government program despite some American pressure
» Prime Minister: We have placed raising the production capacity of existing refineries at the top of
» Sudanese advisor determines the reason for preventing dollar smuggling abroad
» A specialist reveals the fate of dollar prices within a month
» Iraq is not perfect: an American call to support the Iraqis through 3 steps
» Rasheed Bank acknowledges the error and returns the installments deducted from the salaries of retir
» Al-Sudani's advisor identifies the reasons for the decline in the parallel price of the dollar in th
» Samir Al-Nusairi, Advisor to the Association of Private Banks: Economic reform begins with banking r
» Gulf Keystone Petroleum decided to reduce production in the fields of Kurdistan
» Kurdistan owes $6 billion to oil companies
» Parliamentary Finance reveals a new development in the salary scale