Thursday, February 24, 2022

Russians Selling Access to Critical Infrastructure on Dark Web

Dragonfire Cyber released a brief report today concerning recent offerings on the Dark Web for access to critical infrastructure computer systems. They report that the Zhukov Brigade, a Russian hackers collective sometimes loosely associated with the Russian military, had posted a long list of organizations in Europe and the United States that it had proven access to computer networks. Exclusive access was being offered to those systems individually or in related groups.

Maskirovka, the frequent spokesperson for the Zhukov Brigade on these Dark Web sites, reports that the access being sold is sufficient to allow ransomware attacks on the systems without the need for additional exploit tools. Access is being offered for 1BTC (about $35,000) and 10% of ransomware proceeds.

Dade Murphy, CTO of Dragonfire Cyber, told reporters this morning that the list of organizations includes public sector and private sector systems in power generation and transmission, ports, railroads and airports throughout the United States and Europe. “We have notified each of the organizations listed, as well as cybersecurity organizations in the respective governments,” Murphy said.

When asked if this appeared to be related to last night's invasion of the Ukraine by Russia, Dade replied: “We do not know. The Zhukov Brigade is not an agency of the Russian government, but they have been employed by the Russian military for some specific hacking operations that we know of.

General Turgidson, Director of the National Critical Infrastructure Security Operations Center (CI-SOC), was asked about the report at this morning’s CI-SOC briefing, he told reporters that they had received advanced notice of the information from Dragonfire Cyber. “We have a close working relationship with Dade and his outstanding crew,” The General explained; “And we continue to work with them to address any potential threats to organizations in this country.”

When asked about rumors of government agencies buying up the access rights on the Dark Web sites, Turgidson laughed and said: “We do not have budget authority for that type of operation. Besides, I do not think that the Zhukov Group would be interested in selling us that access.” When asked if any intelligence agency might have the necessary authority, the General replied: “No comment.”

CAUTIONARY NOTE: This is a future news story –

Wednesday, February 23, 2022

Insulin Pump Hack Discovers Dosing Errors

Medical device software expert FrediG announced today at BlackCap Europe that he had found a calculation error in the GerateSoft application that he uses with the Robotron IPumpe insulin pump that he used to control his blood sugar levels. The pump routinely administered 0.5% more insulin than was necessary to keep his blood sugar levels at target levels. As a result, his blood sugar levels over the last six months have routinely been on the low end of the target range for the treatment of his Type 1 diabetes.

Robotron spokesperson, Erich Mielke, told reporters at a news conference at the conference that FrediG had disclosed the problem to Robotron last week, and that Robotron was recommending that the users of its IPumpe stop using the GerateSoft application. “We are very concerned that the application is incorrectly dosing patients using our device,” Mileke said; “But we are even more concerned that it appears that this dosing error may be deliberate.”

That unusual comment by Mielke was based on a claim by FrediG that the application used two different calculation formulas, depending on which account was used. FrediG reported in his talk today that the equations used when the default account on the application was being used was the industry standard calculation. The default account would be expected to be used by regulatory agencies and companies like Robotron when testing the application.

Users are specifically warned by GerateSoft not to use the default account to protect their privacy. But when users set up their own unique account on the App, a different equation is used to calculate the insulin dosage. That calculation produces a dose that is 0.5% higher than the industry standard equation.

GerateSoft tried to get a German Court to stop FrediG’s presentation claiming that he had accessed GerateSoft’s system without permission, but lawyers for Robotron told the Court that FrediG had been a registered member of Robotron’s vulnerability discovery program and access to GerateSoft’s application was covered by that program.

Mielke noted that FrediG had reported vulnerabilities in a number of Robotron’s devices over the last two years, including a vulnerable version of OpenSSL used in the IPumpe that Robotron reported and corrected last summer.

CAUTIONARY NOTE: This is a future news story –

Monday, February 14, 2022

EF-1 Charging Stations Hacked Again

The San Francisco Transit Authority (SFTA) announced today that hackers were stealing electricity from the enroute charging stations for the City’s new electric bus fleet. The electric costs for the new charging stations were five times higher than expected during the first six months of operation according to a report released today by the SFTA. Johan Muir, a spokesperson for the SFTA reported that the federal grant supporting the e-charging system would only last another three months at this rate.

Brewster Zenneck, the Director of the City’s SF eBus System, explained this morning that the innovative new electric transit bus system was able to use smaller, lighter batteries to power their new busses because the city had installed cordless power charging stations at about half of the bus stops used by the new vehicles. This means that the busses could partially recharge their batteries while unloading and loading passengers.

Zenneck explained that the system uses inductive charging plates built into to road at the bus stop. When a bus stopped to pickup passengers, a device on the bus would signal the charging system to turn on and then turn off when the bus pulled away. The high-powered charging system would be able to provide enough electricity to the vehicles batteries to allow it to reach the next powered bus stop.

According to an article in last week’s Democratic Press, an alternative new site, not long after the EF-1 charging system was installed a free application appeared on some alternate power web sites that would operate the charging stations. These apps would allow users to charge electric vehicles equipped with cordless charging systems while parked on or near the bus stops. Other apps soon appeared that would allow cordless charging of smaller devices, including cell phones from the vehicle charging system.

Zenneck confirmed that the appearance of the apps had taken the SFTA by surprise. They were enabled by the hard-coded credentials used by the busses to control the charging stations. Once the SFTA had become aware of the problem they had worked with Robotron, the supplier of the EF-1 charging system, to update the system software to provide for unique passwords for each city vehicle that used the system.

Updates for the apps soon appeared on scene that were able to steal passwords from the vehicles when they powered on the system. Zenneck said that the SFTA was working with Robotron to solve that problem.

CAUTIONARY NOTE: This is a future news story –

Wednesday, January 26, 2022

NVR Ransomware Provides Network Access

The National Critical Infrastructure Security Operations Center (CI-SOC) announced today that it had discovered that the recent ransomware attacks by the Blockflötenkollektiv (BFK) on Robotron network video recorders was accompanied by the installation of a root kit utilizing the recently reported VerpfändenBausatz Linux vulnerability. “While the ransom payment for releasing the NVR’s is relatively small (0.03 bitcoin which currently equals about $1,100), the BKF is selling root access to the decrypted systems for 1 bitcoin.” Gen Buck Turgidson, CI-SOC Director, told reporters this morning.

BKF is a hacker collective loosely based out of Germany. It was started in 1990 by technical specialists connected to the East German Stasi, the group has had close ties with Russian cyber gangs.

According to a background briefing provided by an analyst working with the CI-SOC, the organization had received reports from an unnamed US intelligence agency that one of the critical infrastructure organizations protected by CI-SOC had shown up on a dark web site known to be utilized by BFK. BFK was offering to sell root access to one of the corporate networks of the unidentified company. It was one of two hundred such access rights being offered.

Other sources tell me that the intelligence agency bought the rights from BFK and provided the information to CI-SOC. While CI-SOC worked out the details of the system compromise, the intelligence agency was able to use the bitcoin information from their transaction to track back the bitcoin wallet used by BFK. The wallet was seized by the German government and two members of the organization were arrested in Berlin.

CAUTIONARY NOTE: This is a future news story –

Tuesday, December 28, 2021

Airport Ransomware Slows Christmas Returns

Fred P. Ayres, Operations Manager for the Porter Alexander Airport, confirmed today that the flight delays yesterday at the Delano, GA airport were caused by a ransomware attack on the carryon baggage screening equipment being used at the passenger screening checkpoints. He was not able to tell reporters this morning whether a ransom had been paid.

Bessie Coleman, spokesperson for the Airline Transportation Security Agency (ATSA), confirmed that there had been screening delays at Alexander. “We had to go to 100% manual baggage screening of carryon baggage at that airport,” Coleman told reporters; “For security reasons, I cannot discuss what prompted that requirement.”

“We had flight delays of up to two hours to allow for passengers to complete the screening protocols,” Ayers told reporters.

Frank Whittle, who’s son was scheduled to fly back to Ft Carson, Co, after Christmas leave, reported that his son missed his connecting flight in Atlanta. “He ended up spending twelve hours in the Atlanta airport and ended up getting back to his unit three hours late,” Whittle explained; “I hope he does not get in trouble with the Army over the delay.”

The National Critical Infrastructure Security Operations Center (CI-SOC) has been working with the airport and the ATSA on the investigation of the cyberattack. Turgidson told reporters this morning that it is unusual to see a ransomware attack on federal government operations. “Everyone knows that the official policy of the government is to not pay ransoms,” Turgidson explained; “So there is little incentive for a ransomware attack.”

There are rumors circulating that this was not a typical ransomware attack, that files were not encrypted. A security employee of the airport, not associated with ATSA, told me that the screening devices were picking up false weapon returns. Three passengers were apparently pulled aside for additional screening before the ransomware message showed up on the system.

CAUTIONARY NOTE: This is a future news story –

Friday, December 3, 2021

Polymer Hack Via Drive-by Malware

The Federal Bureau of Inquiry confirmed today that the attack earlier this week on the Blew Bayou polymer facility used a new version of the SolarFlare malware that was originally delivered as part of the 2019 Sunburst campaign. “There have been substantial modifications to the malware,” Johnathan Quest, FBI spokesperson, told reporters this morning; “Enough changes in language and syntax that we are not sure if this was produced by the original team or a completely different attacker.”

Kate Libby, a researcher at Dragonfire Cyber that has been working with the FBI on the Blew Bayou investigation, told reporters that the malware was introduced into the polymer control system via a sophisticated phishing attack. “A personal email to the process control engineer directed her to go to the Robotron web site to see a new product introduction,” Libby explained; “The engineer did not click the link in the email but used an existing link from her system to get to the Robotron web site. While on the site she clicked on one of those ubiquitous check boxes accepting site cookies. That action downloaded the malware.”

Erich Mielke, spokesperson for Robotron, confirmed that the company’s web site had been hacked to set up the drive by download. “We use a web privacy compliance company, Datenshutz, to handle all of our website regulatory compliance activities,” Mielke explained; “They were responsible for the cookies notification application on our site. We have been assured that they have corrected the problem.”

Helga Brache, spokesperson for Datenshutz, confirmed that the company was responsible for the application on the Robotron site. “We are currently investigating how the malware download was inserted into our application. We do not believe that any other sites have been affected at this time.”

Libby urged anyone that had visited the Robotron site over the last six months to have their systems checked for the presence of the SolarFlare malware. “The indicators of compromise that were published by CI-SOC for the original malware still apply to the new version,” Kate explained to reporters.

Quest told reporters that the FBI investigation was still progressing. “We are continuing to follow leads and hope to identify the perpetrators of this attack in the coming days,” he explained; “If you have any indications that your systems have been compromised via the Robotron web site, please contact your local FBI office.”

CAUTIONARY NOTE: This is a future news story –

Thursday, December 2, 2021

Water Treatment Chemical Manufacturer Declares Force Majeure

The Blew Bayou Chemical Company in Louisiana announced yesterday evening that their production capacity for polyacrylamide emulsion polymers had been cut in half by a suspected cyberattack on their facility. The Blew Bayou facility is one of only two domestic facilities currently producing these polymers for the municipal water treatment market. The loss of production at the facility could begin impacting drinking water and wastewater treatment facilities across the United States in the next two weeks.

The chemical reaction vessel was damaged when the mixing system was interrupted in the early stages of a polymerization process. The lack of agitation prevented adequate cooling and the exothermic reaction ran out of control. Safety systems stopped a catastrophic overpressure situation from occurring, but the vessel and many of its attached lines were damaged in the incident. Engineers are currently assessing how much damage actually occurred and what repairs will be necessary to return the facility to operation.

An older sister plant in Mississippi was taken out of operation early in the pandemic because of efficiency issues and limited monomer availability. Blew Bayou is reportedly considering reopening that plant.

Blew Bayou CEO Issac B Kaghun told reporters this morning that the agitator stoppage was apparently caused by a cyberattack. “Our engineers have log data showing that the agitator motor was turned off remotely, even while the control room computers were showing continued agitation,” Kaghun said.

The Federal Bureau of Inquiry has confirmed that they are investigating a potential cyber attack at the facility. “We have a cyber investigation team at the site,” Johnathan Quest, FBI spokesperson, said at a news conference this morning.

CAUTIONARY NOTE: This is a future news story –