• COVID-19
  • About Us
  • Contact Us
  • Events
  • Industries
  • Partners
  • Products & Services
  • Contribute
  • Webinars

Aerospace

  • Québec’s CloudOps Will Build Telesat LightSpeed’s Cloud Network
  • Myriota and Goanna Ag Team Up on IoT Agriculture Solutions
  • Fleet Picks Swissto12 to Deliver Additively Manufactured All-Metal Patch Antennas

Chemical

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Evonik deepens partnership with IBM to accelerate AI implementation
  • Achieving Plant Efficiency – the Digital Way

Cybersecurity

  • House Passes Eight Bipartisan Cyber, Homeland Security Bills
  • Biden Administration Targets Electric Utilities For Cybersecurity Protections
  • White House Attributes SolarWinds Hack To Russian Agency

Healthcare

  • CISA Services In High Demand Related To COVID Vaccine Response
  • AI tool detects COVID-19 by listening to patients’ coughs
  • Printing Wearable Sensors Directly onto Skin

Oil & Gas

  • Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
  • Cybersecurity: Continuous Vigilance Required
  • Repsol and Microsoft renew partnership developing AI-powered digital solutions

Power

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Self-Tuning Artificial Intelligence Improves Plant Efficiency and Flexibility
  • How to Put the Power Grid to Work to Prevent Wildfires

Transportation

  • Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
  • Trump Issues Cyber Security Plan For Maritime Transportation System
  • Sabic Launches New Compounds for Automotive Radar Sensors

Webinars

  • Anticipating the Unknowns: Accelerating Incident Response Without Losing Control
  • Industrial Endpoint Protection in Operational Technology
  • Known and Unknown: Putting a Stop to OT and IT Threats Before they Act

Sign up today for our free weekly e-letter

sign up
CONNECTING INNOVATIONS
WITH INSIGHT
SIGN UP
LOG IN
  • Aerospace
    Québec's CloudOps Will Build Telesat LightSpeed's Cloud Network
    Read story View all articles
  • Chemical
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Cybersecurity
    House Passes Eight Bipartisan Cyber, Homeland Security Bills
    Read story View all articles
  • Healthcare
    CISA Services In High Demand Related To COVID Vaccine Response
    Read story View all articles
  • Oil & Gas
    Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
    Read story View all articles
  • Power
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Transportation
    Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
    Read story View all articles
Cybersecurity Power
October 31 2019 6:33 am

Malware Discovered at Nuclear Plant in India

S

Sonal Patel

Malware detected at the Kundankulam nuclear power plant in India's state of Tamil Nadu has not affected plant systems, an investigation by Nuclear Power Corp. of India (NPCIL), the nation's nuclear plant operator, confirms. 

The entity said in a press release on Oct. 30 that it discovered the malware on Sept. 4 on the personal computer of a user that was connected to an administrative network via the internet. "This is isolated from the critical internal network," NPCIL said. "The networks are being continuously monitored. 

ZDNet, an IT-centered news website owned by CNET Networks, reported that speculation about the incident first emerged on Twitter, when Pukhraj Singh, a former security analyst for India's National Technical Research Organization (NTRO), suggested the malware, VirusTotal, was linked to a malware infection at the 1,834-MW nuclear plant, though he later acknowledged he did not know whether the plant's operational technology (OT) systems were compromised. Security researchers have since identified the malware as a version of Dtrack, a "backdoor trojan developed by Lazarus Group, North Korea's elite hacking unit."

So, it's public now. Domain controller-level access at Kudankulam Nuclear Power Plant. The government was notified way back. Extremely mission-critical targets were hit. https://t.co/rFaTeOsZrw pic.twitter.com/OMVvMwizSi

— Pukhraj Singh (@RungRage) October 28, 2019

 

According to the Times of India, NPCIL issued the press release in response to the viral tweet that alleged the cyberattack had compromised the nuclear plant's domain controller-level access. But  plant information officer R. Ramdoss in a press release on Oct. 29 called that information "false," noting that the plant has isolated control systems–a feature in all nuclear plants–which made cyberattacks on the control system "impossible." 

Kundankulam has two 917-MW VVER V-412 reactors that were designed and engineered by Russia's state-owned nuclear firm Atomstroyexport, The first, completed in December 2014, was a POWER Top Plant. NPCIL brought the second online in March 2017. Units 3 and 4 are now under construction under an agreement with Russia, and Units 5 and 6 are in planning.  Ramdoss noted that Units 1 and 2  were operating "at 1,000 MWe and 600 MWe respectively without any operational or safety concerns."

Security firms like Kaspersky note that Dtrack malware rarely targets the energy and industrial sector, and previous samples have been discovered in politically motivated cyber-espionage operations and in attacks on banks. 

But as Andrea Carcano, co-founder and chief product officer at industrial cybersecurity firm Nozomi Networks told POWER, there is a reason the Indian incident is worrying: "Dtrack malware may usually be used for reconnaissance purposes but the information gathered from infected industrial and critical infrastructure plants could be used for other malicious purposes," he said. 

"It is imperative that critical infrastructure organizations put plans in place to prevent malicious attacks, and the cybersecurity community comes together to share expertise and knowledge on identifying and providing solutions to cybersecurity challenges," Carcano added. "Applying artificial intelligence and machine learning detection and response enables organizations to monitor for malware and rapidly respond to remove malicious code."

For Barak Perelman, CEO of Indegy, another industrial cyber security expert, another concerning detail is that the vulnerability window "was too long." The exploit, discovered on  Sept. 4, wasn't made public until earlier this week.  "The initial denial means that either there was a serious lack of situational awareness or they were working to hide this incident from public knowledge. Lastly, once there was an admission of the infection, scoping the problem and appropriate response was not clear," he told POWER. "This event underscores the importance of having the right industrial threat detection, asset tracking and risk mitigation systems in place, which has long been the security posture for IT operations. Yet, we have not applied it to critical infrastructure operations."

Perelman stressed the importance of an audit trail that could help prevent similar incidents at other facilities. "Since individuals tend to cover their tracks when they make mistakes, having a reliable audit trail that can't be tampered with is critical. Finally, when a threat is detected, an audit trail can significantly reduce incident response times to mitigate or contain an infection," he said. 

Dave Weinstein, chief security officer at operational technology (OT) network protection firm Claroty–who was recently a guest on  the POWER Podcast–also told POWER the incident was noteworthy. "In some respects, it's reassuring that the attackers did not reach the plant's control systems, but it's a stark reminder that safety and cybersecurity go hand-in-hand these days. Organizations can no longer rely on the so-called ‘air gap' to secure their control systems; they must perform continuous security monitoring," he said. 

–Sonal Patel is a POWER senior associate editor (@sonalcpatel, @POWERmagazine)

Sign up today for our free weekly e-letter

sign up

Aerospace

Chemical

Cybersecurity

Healthcare

Oil & Gas

Power

Quiz

Transportation

Webinars

About Us

IIoT Connection delivers the latest news, trends, insights, events and research surrounding the dynamic and disruptive Industrial Internet of Things (IIoT) marketplace. Brought to you by the publisher of must-read publications Defense Daily, OR Manager, POWER and Chemical Engineering, as well as the conference producers of SATELLITE, Global Connected Aircraft Summit, Connected Plant Conference and ELECTRIC POWER, IIoT Connection is committed to providing the most comprehensive compilation of products and services dedicated to the Industrial Internet of Things. Key verticals with associated products and services include: aerospace, chemical, cybersecurity, healthcare, oil & gas, power, and transportation.


Advertise

  • Privacy Policy
© 2021 Access Intelligence, LLC - All Rights Reserved.
  • × UPS Partners with Wingcopter to Develop, Certify Drone Delivery Fleet
    Read story View all articles
  • × How Industrial Managers Can Identify and Prevent Failures in Facilities
    Read story View all articles
  • × Federal Agencies Partner To Improve Cyber Security Cooperation In Energy Sector
    Read story View all articles
  • × New service lines can create opportunities for ORs
    Read story View all articles
  • × Equinor and Shell to collaborate on digital solutions
    Read story View all articles
  • × Dobroflot to Manage Fuel Savings With IOT Solution By Orange Business Services
    Read story View all articles
  • × The Future of 5G & IoT Technologies in the Transportation Industry
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles