Xorte logo

News Markets Groups

USA | Europe | Asia | World| Stocks | Commodities



Add a new RSS channel

 
 


Keywords

2024-07-23 19:14:14| Engadget

Cybersecurity company Dragos has flagged malware that can attack industrial control systems (ICS), tricking them into malicious behavior like turning off the heat and hot water in the middle of winter. TechCrunch reports thats precisely what the malware, dubbed FrostyGoop, did this January in Lviv, Ukraine, when residents in over 600 apartment buildings lost heat for two days amid freezing temperatures. Dragos says FrostyGoop is only the ninth known malware designed to target industrial controllers. Its also the first to specifically set its sights on Modbus, a widely deployed communications protocol invented in 1979. Modbus is frequently used in industrial environments like the one in Ukraine that FrostyGoop attacked in January. Ukraines Cyber Security Situation Center (CSSC), the nations government agency tasked with digital safety, shared information about the attack with Dragos after discovering the malware in April of this year, months after the attack. The malicious code, written in Golang (The Go programming language designed by Google), directly interacts with industrial control systems over an open internet port (502). The attackers likely gained access to Lvivs industrial network in April 2023. Dragos says they did so by exploiting an undetermined vulnerability in an externally facing Mikrotik router. They then installed a remote access tool that voided the need to install the malware locally, which helped it avoid detection. The attackers downgraded the controller firmware to a version lacking monitoring capabilities, helping to cover their tracks. Instead of trying to take down the systems altogether, the hackers caused the controllers to report inaccurate measurements resulting in the loss of heat in the middle of a deep freeze. Dragos has a longstanding policy of neutrality in cyberattacks, preferring to focus on education without assigning blame. However, it noted that the adversaries opened secure connections (using layer two tunneling protocol) to Moscow-based IP addresses. I think its very much a psychological effort here, facilitated through cyber means when kinetic perhaps here wasnt the best choice, Dragos researcher Mark Magpie Graham told TechCrunch. Lviv is in the western part of Ukraine, which would be much more difficult for Russia to hit than eastern cities. Dragos warns that, given how ubiquitous the Modbus protocol is in industrial environments, FrostyGoop could be used to disrupt similar systems worldwide. The security company recommends continuous monitoring, noting that FrostyGoop evaded virus detection, underscoring the need for network monitoring to flag future threats before they strike. Specifically, Dragos advises ICS operators to use the SANS 5 Critical Controls for World-Class OT Cybersecurity, a security framework for operational environments.This article originally appeared on Engadget at https://www.engadget.com/russia-linked-hackers-cut-heat-to-600-ukrainian-apartment-buildings-in-the-dead-of-winter-researchers-say-171414527.html?src=rss


Category: Marketing and Advertising

 

Latest from this category

17.01How to cancel CyberGhost and get a refund
17.01Papers Please but with zombies, a farming-based shoot-'em-up and other new indie games worth checking out
16.01Google is appealing the ruling from its search antitrust case to avoid sharing data with rivals
16.01CyberGhost VPN review: Despite its flaws, the value is hard to beat
16.01Anthropic opens up its Claude Cowork feature to anyone with a $20 subscription
16.01OpenAI is bringing ads to ChatGPT
16.01The mother of one of Elon Musk's children is suing xAI over nonconsensual deepfake images
16.01Lego's latest educational kit seeks to teach AI as part of computer science, not to build a chatbot
Marketing and Advertising »

All news

17.01How to cancel CyberGhost and get a refund
17.01Papers Please but with zombies, a farming-based shoot-'em-up and other new indie games worth checking out
17.01Chicago prepares for WNBA All-Star Weekend with a pitch to local investors and businesses: Do a little more
17.01SIP stocks! HDFC Securities names 10 companies to accumulate in 2026. Check details
17.01Rs 2.5 lakh crore IPO boom in 2026 could create liquidity drain, says HDFC Securities; pegs Nifty at 28,720
17.01FIIs dump Rs 22,530 crore worth of domestic shares in first fortnight of January
17.01Elmhurst museum explores history of healthcare in DuPage County in new exhibit
17.01Youre banned from blocking Trumps face on your national park passbut theres a work-around
More »
Privacy policy . Copyright . Contact form .