Tuesday, February 25, 2020

Refinery Still Down from Ransomware Attack


Cesar Chavez of the Rafael Ravard Refinery in Baton Rouge, LA announced this morning that the refinery was still shut down from last month’s ransomware attack. “We initially decided not to pay the ransom since we had off sit backups for our major control system components, but after determining that the ransomware had encrypted device level software for which we had no backups, we decided that we had to pay the ransom” Chavez told reporters.

Chavez explained that the owners of the WannaControl malware added additional penalties for the delay in paying the ransomware and were now releasing the control system devices on a unit-by-unit basis with a separate, smaller ransom being required for each unit. So far, the refinery has reportedly paid out $1.9 million in bitcoin ransom payments.

Johnathan Quest, spokesman for the Federal Bureau of Inquiry, told reporters that the Bureau was still investigating the attack, but were unable to trace the ransom ware payments. “Bitcoin transactions are very difficult to trace, but we are working with a number of international law enforcement agencies and various intelligence agencies to crack the Bitcoin network.

Immanuel C. Securitage, spokesman for the ECS-CERT, told reporters that his agency was working closely with the refinery and Robotron on the security issues related to this attack. “The agency has not been notified of other facilities that may have experienced a WannaControl attack, but we suspect that some attacks have taken place and that the owners quickly paid the ransom to avoid the results that the refinery has experienced,” he explained.

ECS-CERT strongly recommends that anyone facility that had purchased Robotron pumps in the last half of 2019 immediately take them out of service until a Robotron representative can reload the motor control software. Facilities with such pumps in service should have their control system immediately checked for possible compromise. “ECS-CERT has noted that the refinery attackers apparently had access to the control system for at least a month before the attack was initiated,” Securitage reported.

In response to a reporter’s question about ECS-CERT support for finding apparently affected systems, Securitage said: “ECS-CERT does not have enough investigators to help everyone affected by the Robotron vulnerability, nor apparently does Robotron.” ECS-CERT is not allowed to recommend private sector companies that could do this work, but Securitage noted that: “Any major ICS security organization could probably do the assessment.”

Erich Mielke from Robotron released a statement that said the company was deploying as many of their security engineers as it had available to look at potentially affected Robotron control systems, but facilities that used Robotron pumps with other vendor control systems should probably reach out to the system vendor for assistance. Robotron has published a report on the malware that was loaded on their pump controllers that includes indicators of possible compromise that could be looked for on other products.

Rep. Harvey Milk (D,CA) announced that his subcommittee will be holding a hearing this week looking at the refinery attack. “We need to ensure that these types of ransomware attacks on critical infrastructure cannot happen,” he told reporters. He went on to criticize ECS-CERT’s inability to effectively support critical infrastructure owners in preventing further occurrences of this particular attack, saying: “Congress expects ECS-CERT to be proactive in responding to attacks like this; we want answers now.”


Tuesday, February 4, 2020

Federal Judge Releases LNG Hackers


Today Judge Phantly R. Bean of the 14th US District Court released the two hackers that were arrested in the case of the liquified natural gas railcar that was hacked last month. Bean ruled that the two could not be charged with federal computer fraud charges. The two were subsequently arrested on State charges as they left Federal custody.

Bean ruled that Federal prosecutors erred in charging the two under 18 USC 1030, the Federal criminal code chapter dealing with computer fraud. This is the chapter under which most computer hackers are charged. “While this computer fraud chapter is broadly written, none of the elements of crime described in the chapter pertain to the actions alleged to have been conducted by these two individuals;” Bean wrote in his decision; “With that firmly in mind, I hereby grant the defense motion to dismiss the charges.”

Junio Butts, the lawyer defending the two in Federal Court declared that: “This is a good day for the American judicial system. Bean recognized that the actions of my clients was a modern-day issue of civil disobedience not fraud. We are currently discussing with Pennsylvania State prosecutors an appropriate charge to which my clients can legitimately plead guilty.”

Bean has testified before Congress on the inadequacies of the §1030 language with respect to attacks on computers that are part of a control system of some sort. He testified last summer that “Industrial control systems do not fit well into the description of fraud related offenses listed in §1030(a) and Congress needs to address this issue before the Courts are forced to deal with the situation.”

Rep Harvey Milk (D,CA) is reportedly working on legislation that would add a new paragraph to §1030 that would specifically address the issue of attacks on industrial control systems. “My staff has been working with tech industry lawyers to craft language that would address attacks on these increasingly important information systems.”

CAUTIONARY NOTE: This is a future news story –

Friday, January 31, 2020

WannaControl Attack on Louisiana Refinery


Cesar Chavez of the Rafael Ravard Refinery in Baton Rouge, LA announced this morning that overnight the refinery operations had been shut down by a a ransomware attack. “It appears that the refinery was the victim of the WannaControl ransomware. The attackers are demanding 100 Bitcoin to release our control systems back into operation,” he reported. At today’s exchange rate that is about $930,000.

Chaves reported that: “We have not yet made a decision on paying the ransom. We will consult with our insurers and the Federal Bureau of Inquiry before finalizing that decision.”

Chavez explained that the refinery operations were shutdown in an orderly manner, but there were numerous flaring incidents during the process. “It does not appear that any damage has been done to the refinery and no personnel were injured,” he explained.

ECS-CERT and the FBI will be conducting a joint investigation of this attack, according to Immanuel C. Securitage of the ECS-CERT. “Preliminary indications are that this attack may be related to the announcement by Robotron earlier this week;” Securitage noted. That announcement was about the possible compromise of software shipped by Robotron after a cyberattack on their facility last October.

When asked about that announcement Chaves acknowledged that the refinery had installed a number of the potentially impacted Robotron controlled pumps during a turn around last year. The company had been planning on replacing those pumps during the next scheduled maintenance activity of each refinery unit. “We may try to do that before the refinery restarts, but it depends on the availability of replacement pumps;” Chavez told reporters.


Thursday, January 30, 2020

Sophisticated SWATTING Attack Destroys Facility


The Federal Bureau of Inquiry announced this morning that it was investigating a recent fire and explosions at an Iowa biodiesel facility as a potential act of terrorism. The attack Tuesday resulted in the release of methanol from multiple storage tanks with resulting explosions and fire. No employees were injured and two police officers were treated and released from the local hospital with minor burns and contusions. One off-site evacuation was necessary as only one family lived within ½-mile of the rural facility.

The attack was first reported to the police in nearby Bums Rush, IA as consisting of five to six individuals armed with apparent automatic weapons. The report was made by the Security Control Center for American Security Guard, Inc. Paul Blart, their spokesman, told reporters that security cameras and intrusion detection devices alerted the company to the possible intrusion. Security Guards at the site were dispatched to the perimeter location where the intrusion was detected. Guards confirmed a whole in the perimeter fence and footprints of multiple individual entering the facility.

When asked if the local security force was armed, Blart replied: “Our contract with Biodiesel of Iowa prohibits us from having armed personnel on-site. That is why we notified the police when our cameras indicated that armed individuals had entered the site.”

When police arrived on scene they started searching for the intruders. When they entered the main storage tank area they were fired upon by automatic weapons. Patrol officers returned fire, apparently puncturing two methanol storage tanks. Minutes later an explosion occurred in the tank farm, destroying multiple tanks. Fires continued to burn well into this Wednesday afternoon.

When investigators were able to enter the site last night, they found a WWI machine gun equipped with remote control and a large supply of blank ammunition. It appears that no intruders were on-site during the exchange of gun fire and no one actually fired at the police officers. Meanwhile, a check of security systems at SGI determined that their system had been hacked and the photos upon which the police report was made were fake. At that point local authorities contacted the FBI.


Sunday, January 26, 2020

Robotron Reports Devices Reprogramed


A press release from Robotron today reported that a number of their devices loaded with MotorSteuerung software have been compromised during the recent ransomware attack on the main manufacturing facility in Dresden, Germany. Devices purchased directly from Robotron since November 2nd, 2019 should be removed from service until a Robotron service representative can check the software.

Erich Mielke, spokesman for Robotron, reported that the company had learned that the MotorSteuerung master software on their severs had apparently been corrupted during the attack. “In the 24-hours that our servers remained encrypted, it appears that doctored software was substituted for factory standard version that is used to load devices being shipped for service,” Mielke explained.

Registered customers can check their device serial number against the list on the Customer Service web site.

Dade Murphy from Dragonfire told reporters that his company had reported the corrupted software to Robotron. We were doing an investigation at one of our customer sites and noted that the software was communicating with a command and control server in Bulgaria that was associated with WannaControl ransomware. This is a new ransomware strain that specifically attacks industrial control systems, putting control systems into shutdown mode and encrypting the files.

Murphy noted that; “In the few cases we have identified, the attackers took great care to safely shutdown the control systems before encrypting the files that would allow for a restart of the process. This requires a great deal of system knowledge and probably reflects a long residence time on the system before the actual attack takes place.” Dragonfire has not yet been able to determine the source of the infection for these attacks; phishing attacks have been ruled out.

CAUTIONARY NOTE: This is a future news story –

Arrests Made in LNG Railcar Hack


At today’s press conference in Franklawn, Johnathan Quest announced that the FBI had arrested two individuals in connection with the cyberattack on the liquified natural gas railcar that was subsequently parked on a siding outside of this small Pennsylvania town. He confirmed that they were loosely tied to the protest group, Frack No More. George P. Mitchell and Willi Barnett are currently being held in the Franklawn jail pending their transfer to a federal facility in Philadelphia.

Floyd Faris, founder of the group, acknowledged that the two individuals had been members of Frack No More but had left the group over policy disagreements. “They wanted to move beyond protests and picketing,” Faris explained. He did note that the attack never increased the level of danger the public was exposed to during the transportation of LNG.

George Schneider, founder and CEO of Schneider Gas, the company that owned the affected railcar, said: “I am happy to see that these two have been arrested, but I will be happier when I am notified that the TransTrac vulnerability is fixed.”

Chief Margaret Stevenson from the Franklawn Fire Department was asked if the public had been in any danger. She responded: “No. The pressure in the railcar never reached unsafe levels. Schneider Gas responded quickly and helped the Department deal with the problem. If it were not for the illegal hack on the railcar, I would treat this as a successful emergency response drill.”

She explained that in accordance with Department training and guidance from the Railroad Safety Administration, her teams had responded to the rail siding where the LNG car had been parked by the Genovese and Newark Railroad. An immediate evacuation of about 20 families living within a mile of the siding was undertaken and methane detectors were set up around the siding. The Schneider team arrived and attached a flare-line to the railcar to allow unsafe pressures to be safely reduced and set-up for unloading the railcar into trucks.

“Schneider and I agreed that unloading should proceed, even though there were no actual safety concerns about the railcar,” Chief Stevenson explained. They both doubted that the railroad would accept the railcar with the flawed reporting device.

Immanuel C. Securitage from ECS-CERT confirmed that the same vulnerability that was used in the Los Angeles traffic hack was used to attack the reporting system on the LNG railcar. “While TransTrac utilized a slightly different GPS tracking device than those used on cars, the same flaw in the information control system at GPS Associates allowed the attackers to provide false information to the railroad,” Securitage reported.

Quest told reporters that both suspects had confessed to their parts in the situation. “They are both proud of the fact that they stopped this railroad shipment of LNG,” Quest said; “Their mistaken opinion will make their transition into the federal penal system quite quick.” Both will be arraigned in Philadelphia on federal computer fraud charges on Monday.

CAUTIONARY NOTE: This is a future news story –

Monday, January 20, 2020

GPS Associates May Be Involved in Hazmat Incident


ECS-CERT announced today that they were joining the investigation of hazardous material incident involving a rail shipment of liquified natural gas that started last week. Immanuel C. Securitage told reporters that the agency’s involvement came at the request of the head of the Franklawn Fire Department, Margaret Stevenson. She had noted a similarity between Thursday’s incident and the GPS Associates related incident earlier this month in Los Angeles.

Stevenson explained that her department had been called to respond to a hazmat incident at a remote railroad siding outside of town. The Genovese and Newark Railroad had parked an LNG railcar on the siding when remote sensors had reported that the pressure inside the railcar was too high to continue transport. When the Schneider Gas and Oil team arrived on the scene to assist in the incident response, they found that the pressure in the railcar was well within the expected limits.

George Schneider, owner and CEO of Schneider Gas and Oil, told reporters that he agreed with Stevenson that it appeared that there was something wrong with the remote reporting unit on the railcar owned by his company. When Stevenson had noted that the TransTrac was made by GPS Associates she told Schneider about the LA incident and both agreed that the two incidents could be related.

John P. Morgan of the Railroad Safety Administration told reporters that all LNG railcars were required by regulation to include a tracking device that reported the location and pressure to the railroad operations center. He noted that the GNR had been transporting about one railcar of LNG per week for the last month without incident. He explained that the railroad had followed the agreed upon emergency response plan in this incident.

Morgan said: “While involving the ECS-CERT in a hazmat investigation is unusual, the involvement of the new tracking device did add a new level of complexity that the RSA was not equipped to address.”

Securitage told reporters: “If hacking of the TransTrac device was involved in this incident, the Federal Bureau of Inquiry would certainly be notified.”

CAUTIONARY NOTE: This is a future news story –