• COVID-19
  • About Us
  • Contact Us
  • Events
  • Industries
  • Partners
  • Products & Services
  • Contribute
  • Webinars

Aerospace

  • Québec’s CloudOps Will Build Telesat LightSpeed’s Cloud Network
  • Myriota and Goanna Ag Team Up on IoT Agriculture Solutions
  • Fleet Picks Swissto12 to Deliver Additively Manufactured All-Metal Patch Antennas

Chemical

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Evonik deepens partnership with IBM to accelerate AI implementation
  • Achieving Plant Efficiency – the Digital Way

Cybersecurity

  • House Passes Eight Bipartisan Cyber, Homeland Security Bills
  • Biden Administration Targets Electric Utilities For Cybersecurity Protections
  • White House Attributes SolarWinds Hack To Russian Agency

Healthcare

  • CISA Services In High Demand Related To COVID Vaccine Response
  • AI tool detects COVID-19 by listening to patients’ coughs
  • Printing Wearable Sensors Directly onto Skin

Oil & Gas

  • Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
  • Cybersecurity: Continuous Vigilance Required
  • Repsol and Microsoft renew partnership developing AI-powered digital solutions

Power

  • POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
  • Self-Tuning Artificial Intelligence Improves Plant Efficiency and Flexibility
  • How to Put the Power Grid to Work to Prevent Wildfires

Transportation

  • Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
  • Trump Issues Cyber Security Plan For Maritime Transportation System
  • Sabic Launches New Compounds for Automotive Radar Sensors

Webinars

  • Anticipating the Unknowns: Accelerating Incident Response Without Losing Control
  • Industrial Endpoint Protection in Operational Technology
  • Known and Unknown: Putting a Stop to OT and IT Threats Before they Act

Sign up today for our free weekly e-letter

sign up
CONNECTING INNOVATIONS
WITH INSIGHT
SIGN UP
LOG IN
  • Aerospace
    Québec's CloudOps Will Build Telesat LightSpeed's Cloud Network
    Read story View all articles
  • Chemical
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Cybersecurity
    House Passes Eight Bipartisan Cyber, Homeland Security Bills
    Read story View all articles
  • Healthcare
    CISA Services In High Demand Related To COVID Vaccine Response
    Read story View all articles
  • Oil & Gas
    Globalstar Wins Asset Tracking Order from Brazilian Oil and Gas Company
    Read story View all articles
  • Power
    POWER magazine and Chemical Engineering magazine announce Eastman Chemical as the Host Chemical Process Industries (CPI) Sponsor for the 5th annual Connected Plant Conference
    Read story View all articles
  • Transportation
    Swarm CEO Sara Spangelo Sets Disruptive Pricing on New Satellite IoT Service
    Read story View all articles
Cybersecurity Power
August 2 2018 7:49 am

New Cyber Threat Actor Targeting Power Sector Identified

S

Sonal Patel

Cybersecurity experts have identified a new activity group that they say is targeting access operations at electric utilities in the U.S., Europe, Middle East, and East Asia. 

Cybersecurity firm Dragos Inc. told POWER on August 1 that though it has confirmed that the group–which it dubbed "RASPITE"–is actively targeting electric utilities, "there is no current indication the group has the capability" to conduct destructive widespread blackouts like those in Ukraine in 2016. Dragos added, "Operations against electric utility organizations appear limited to the U.S. at this time." 

Symantec, another security firm, calls the group, "Leafminer." On July 25, Symantec said in a blog post that the group's activity remains centered on the Middle East, mostly in Saudi Arabia–noting that threat is likely being perpetrated by Iranian actors. "One interesting source of target information discovered during the Leafminer investigation was a list of 809 targets used by the attackers for vulnerability scans," it said. "The list is written in the Iranian language Farsi and groups each entry with organization of interest by geography and industry." According to Symantec, however, industry verticals suggest the group is targeting mainly government, financial, and petrochemical sectors, and to a lesser degree, airline, security services, and the utility sectors. 

Symantec said that Leafminer uses three main techniques for initial intrusion of target networks. These include compromised web servers used for watering hole attacks; scans or exploits for vulnerabilities of network services; and dictionary attacks against logins of network services. 

Dragos's analysis of tactics, techniques, and procedures (TTPs) used by RASPITE indicate the group has been active "in some form" since early- to mid-2017–an origin timeframe that Symantec confirms. "RASPITE leverages strategic website compromise to gain initial access to target networks. RASPITE uses the same methodology as DYMALLOY and ALLANITE in embedding a link to a resource to prompt an SMB connection, from which it harvests Windows credentials. The group then deploys install scripts for a malicious service to beacon back to RASPITE-controlled infrastructure, allowing the adversary to remotely access the victim machine," Dragos said. 

According to Dragos, however, RASPITE is focused on entities that operate industrial control systems (ICS), though it "has not demonstrated an ICS-specific capability to date." Yet, Dragos warned that the group's "recent targeting focus and methodology are clear indicators of necessary activity for initial intrusion operations into an IT network to prepare the way for later potential ICS events."

 The Benefits of Early Identification

Sergio Caltagirone, director of Threat Intelligence at Dragos, told POWER that catching RASPITE early in its maturity "is ideal as it allows us to track its behavior and threat progression to help organizations defend against them. RASPITE uses common techniques, which is good because defenders with sufficient monitoring can catch them and mitigate any opportunity for them to get better," he said. 

Dragos noted that it does not describe ICS activity group technical details (except in extraordinary circumstances) in order to limit tradecraft proliferation. "Although Dragos does not conduct country-specific attribution of industrial control threats, generally, threats focused on industrial control are state-sponsored due to the inherent risk, limited financial gain, and potential blow back from the operations," said Caltagirone. 

Earlier this year, Dragos warned that 2017 was a "watershed" year in ICS security, largely due to the discovery of new capabilities and a significant increase in ICS threat activity groups. Before last year, only three families of ICS-specific malware were known: STUXNET, discovered before 2010; BLACKENERGY 2, discovered in 2012; and HAVEX, which emerged in 2013. In 2017, two new samples emerged: TRISIS and CRASHOVERRIDE. "Both of these samples led to industry firsts," Joe Slowik, a Dragos senior threat analyst, said in March. "CRASHOVERRIDE was the first malware to ever specifically target and disrupt electric grid operations and led to operational outages in Kiev, Ukraine, in 2016 (although it was not definitively discovered until 2017)," he said. "TRISIS is the first malware to ever specifically target and disrupt safety instrumented systems (SIS), and is the first malware to ever specifically target, or accept as a potential consequence, the loss of human life."

This May, the firm described a new cyberattack threat activity group it identified "XENOTIME," which it said is intent on compromising and disrupting industry safety instrumented systems globally.  

DHS Kicks off Cybersecurity Summit

The proliferation of cyber threat actors targeting critical infrastructure has been a long-standing concern for industry and government. On July 31, the U.S. Department of Homeland Security (DHS) kicked off the first-of-its-kind National Cybersecurity Summit in New York City, seeking to lay out a vision for a "collective defense strategy" to protect critical infrastructure. 

The DHS said in a statement on August 1 that throughout the summit, government and industry partners agreed "on a series of concrete steps to better understand what is truly critical and work together to reduce strategic risk." 

At the summit, DHS Secretary Kirstjen Nielsen also announced the creation of the National Risk Management Center, which will coordinate national efforts to protect the nation's critical infrastructure. The center will work closely with the National Cybersecurity and Communications Integration Center (NCCIC)–the DHS's central hub for cyber operations focused on threat indicator sharing, technical analysis and assessment services, and incident response. "The two centers will work hand-in-hand to ensure effective coordination between strategic risk management and tactical operations," the DHS said. 

At the event, the DHS also unveiled the formation of the Information and Communications Technology (ICT) Supply Chain Risk Management Task Force, which will examine and develop recommendations "for actions to address key strategic challenges to identifying and managing risk associated with the global information and communications technology supply chain and related third-party risk." The task force is intended to focus on solutions to manage strategic risks through policy initiatives and opportunities for innovative public-private partnership. 

The DHS said the summit was attended by a group of more than 20 CEOs from large companies and senior-most government officials, along with "hundreds of others from across a wide range of industries."

–Sonal Patel is a POWER associate editor (@sonalcpatel, @POWERmagazine)

Sign up today for our free weekly e-letter

sign up

Aerospace

Chemical

Cybersecurity

Healthcare

Oil & Gas

Power

Quiz

Transportation

Webinars

About Us

IIoT Connection delivers the latest news, trends, insights, events and research surrounding the dynamic and disruptive Industrial Internet of Things (IIoT) marketplace. Brought to you by the publisher of must-read publications Defense Daily, OR Manager, POWER and Chemical Engineering, as well as the conference producers of SATELLITE, Global Connected Aircraft Summit, Connected Plant Conference and ELECTRIC POWER, IIoT Connection is committed to providing the most comprehensive compilation of products and services dedicated to the Industrial Internet of Things. Key verticals with associated products and services include: aerospace, chemical, cybersecurity, healthcare, oil & gas, power, and transportation.


Advertise

  • Privacy Policy
© 2021 Access Intelligence, LLC - All Rights Reserved.
  • × UPS Partners with Wingcopter to Develop, Certify Drone Delivery Fleet
    Read story View all articles
  • × How Industrial Managers Can Identify and Prevent Failures in Facilities
    Read story View all articles
  • × Federal Agencies Partner To Improve Cyber Security Cooperation In Energy Sector
    Read story View all articles
  • × New service lines can create opportunities for ORs
    Read story View all articles
  • × Equinor and Shell to collaborate on digital solutions
    Read story View all articles
  • × Dobroflot to Manage Fuel Savings With IOT Solution By Orange Business Services
    Read story View all articles
  • × The Future of 5G & IoT Technologies in the Transportation Industry
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles
  • ×
    Read story View all articles