Malware Caused 2016 Ukrainian Power Outage

By

Malware called CRASHOVERRIDE or Industroyer was likely to blame for last year’s power grid attack in the Ukraine that left Kiev in the dark for an hour. And that malware represents the most dangerous threat to industrial control systems since Stuxnet.

These revelations come from separate, but related, reports from Dragos and ESET.

Senior Malware Researcher Anton Cherepanov of Slovakian security firm ESET in a blog earlier this week explained that Industroyer is especially dangerous given its ability to control circuit breakers and electricity substation switches directly using native industrial communication protocols. Those protocols have been in use since before the Internet became commercialized, and predate control systems being connected to the outside world. So security wasn’t a consideration at the time they were designed and put into service.

“That means that the attackers didn’t need to be looking for protocol vulnerabilities,” Cherepanov explained, “all they needed was to teach the malware ‘to speak’ those protocols.”

The ability to speak that language apparently enabled Industroyer to turn off remote terminal units controlling the power system in the Ukraine on Dec. 17, 2016. According to The Hill, it’s believed that Russia is to blame for the attack.

Industroyer reportedly can be used to alter settings, shut down systems, and wipe files. It can be used on various kinds of industrial control systems. And it contains specific attacks for one type of Siemens system.

That said, Robert Lee of Dragos in a blog earlier this week noted that the electric grid is extremely reliable and that, because of that fact, any outages it might suffer would last hours or days as opposed to weeks or months. That said, Lee commented that “CRASHOVERRIDE represents alarming tradecraft and the ability to disrupt operations….”

Lee added that ESET on June 8 called on Dragos to validate its findings to reporters covering the new revelations discussed above. “Dragos was able to confirm much of ESET's analysis and leveraged the digital hashes to find other undisclosed samples and connections to a group we are tracking internally as ELECTRUM,” Lee said. (ELECTRUM is the adversary group behind the 2016 attack of the Ukraine electric grid, Lee explained.)

As for the Stuxnet malware referenced above, that was used by the U.S. and Israel to sabotage the Iranian nuclear arms program.




 
Get stories like this delivered straight to your inbox. [Free eNews Subscription]

Executive Editor, TMC

SHARE THIS ARTICLE
Related Articles

Why Block Websites? Understanding the Reasons

By: Contributing Writer    5/6/2024

The internet is such an expansive network where every click can lead to information, entertainment, or opportunities for productivity. However, this a…

Read More

ChatGPT Isn't Really AI: Here's Why

By: Contributing Writer    4/17/2024

ChatGPT is the biggest talking point in the world of AI, but is it actually artificial intelligence? Click here to find out the truth behind ChatGPT.

Read More

Revolutionizing Home Energy Management: The Partnership of Hub Controls and Four Square/TRE

By: Reece Loftus    4/16/2024

Through a recently announced partnership with manufacturer Four Square/TRE, Hub Controls is set to redefine the landscape of home energy management in…

Read More

4 Benefits of Time Tracking Software for Small Businesses

By: Contributing Writer    4/16/2024

Time tracking is invaluable for every business's success. It ensures teams and time are well managed. While you can do manual time tracking, it's time…

Read More

How the Terraform Registry Helps DevOps Teams Increase Efficiency

By: Contributing Writer    4/16/2024

A key component to HashiCorp's Terraform infrastructure-as-code (IaC) ecosystem, the Terraform Registry made it to the news in late 2023 when changes …

Read More