Showing posts with label Ransomware. Show all posts
Showing posts with label Ransomware. Show all posts

Sunday, February 25, 2024

Ransomware Class Action Suit

The City of Los Angeles filed a class action lawsuit against Hodes Automation for damages related to the recent ransomware attack against the City’s traffic light control system. Harry R. Haldeman announced the lawsuit this morning along with district attorneys from 25 other Southern California cities. “Not only was Hodes negligent in the design of their system, but they published a list of their customers on their web site,” Haldeman told reporters; “That list provided the hackers easy targets for publicly available exploits.”

Dean Hodes, owner of Hodes Automation, had no comment, referring reporters to his lawyer, Eunice Rivers. Rivers’ office issued a statement this morning; “We are looking at the details of the filing by the District Attorney and cannot comment on the facts of the case at this time, but Mr. Haldeman is clearly overreaching in trying to collect expenses the city incurred in their recovery from an incident from my client.” Rivers noted that Hodes had published an updated version of their software two weeks before the vulnerability was announced by Robert Lightman, the researcher who discovered the vulnerability.

Lightman published his report two months ago on the security bypass vulnerability in the TL Control program used by Los Angels and thirty other municipalities in Southern California. “I discovered the vulnerability while doing some work for the city of Montecito,” Lightman told reporters; “And I worked closely with Hodes to help them correct the problem.” Lightman explained that he had a disclosure agreement with Hodes that allowed him to publish his research two weeks after Hodes made their update available on their web site.

The City of Los Angeles installed the TL Control system two years ago after the hack of the Robotron system that the City had been using was discovered. Doug Wilson, the Los Angeles City Manager told reporters this morning that the city had decided to work with a local vendor after having problems working with Robotron. “We felt that a local vendor would be more responsive to our needs,” Wilson said.

When asked when the city became aware of the vulnerability in the TL Control product, Wilson told reporters that he was not able to comment on ongoing litigation. “All questions about the lawsuit should be referred to Haldeman’s office,” Wilson said.

A technician working with the Traffic Department who was not authorized to talk to the press told me that the city never received notification about the vulnerability from Hodes. “We read about the vulnerability in a newspaper article about the ransomware attack,” she said.

The Hodes web site announced the availability of a new version of the TL Control product on December 2nd. There was no mention of security vulnerability on the web site. The TL Control web page was taken down early this afternoon, after the lawsuit was announced.

The lawsuit is seeking $15 million in damages.

The City Traffic department announced a request for bids on a new traffic light control system. The bid request includes new requirements for cybersecurity notifications, including notifying the Department when vulnerabilities are reported to the vendor and reporting when the vendor has mitigation measures available for reported vulnerabilities.

CAUTIONARY NOTE: This is a future news story - 

Friday, February 24, 2023

Innovative Ammo Manufacturer Shut Down to Ransomware Attacks

Bermite Ammo Mfg announced today that it would miss delivery of the next batch of its new carbon-composite 155mm artillery shells to the US Army because of a ransomware attack on its facility in Saugus, CA. “We have experienced a ransomware attack on the IT systems at our Saugus facility, so we have shut down all of our cyber systems pending resolution of the problem,” Patrick Lizza, corporate spokesperson told reporters; “Our production control systems were not directly affected by the ransomware, but we are doing detailed checks of those systems out of an abundance of caution.”

The Army Ammunition Command reports that they are aware of the shutdown and have coordinated with Cyber Command for assistance in investigating the problem. LTC Henry Knox, from AAC, told reporters at a press conference in St Louis, MO: “We are concerned about any delay in the manufacture at BAM since their new carbon composite 155mm artillery shells allow us to free up additional ammunition for shipment to Ukraine as the Army replaces their conventional shells with the lighter, more powerful BAM shells.”

Bermite had met all Army cybersecurity requirements for primary manufacturers, so the Cyber Command is concerned that this may represent a more effective ransomware attack. Cyber Command has employed investigators from Dragonfire Cyber to look specifically at the industrial control systems on the site to see if they were impacted. “Dragonfire has specific experience in incident response in the type of equipment utilized at BAM, Knox told reporters; “Cyber command will look at the ransomware issue, and Dragonfire will clear the control systems.”

A technician with Dragonfire that is not authorized to talk to the press about the investigation told me that there were some indications of unusual activity between corporate IT systems and the control systems at the facility. “Investigators are still looking to see if any changes had been made in device programming or security settings,” she said.

CAUTIONARY NOTE: This is a future news story –

Thursday, February 9, 2023

‘We’re Back’ Ransomware Targets Chemical Facilities

The National Critical Infrastructure Security Operations Center (CI-SOC) reported today that it was seeing an increasing number of chemical facilities being affected by ‘We’re Back’ ransomware attacks. “This ransomware is specifically designed to disrupt chemical manufacturing operations,” Gen Buck Turgidson told reporters; “Instead of shutting down equipment, it typically closes valves at non-critical points in the process and sends a ‘We’re Back’ message to the HMI controlling that valve.”


 The Federal Bureau of Inquiry is investigating these attacks. “We have only been notified of three attacks, so far,” Johnathan Quest, FBI spokesperson, said, “We know from anecdotal reports that many more facilities have been affected.” The FBI is requesting that any facilities that have been affected by this ransomware contact their local FBI office.

Turgidson confirmed that they have been notified of more than three attacks. “We have had some facilities share information with us on the condition that we specifically do not report the information to law enforcement,” Turgidson explained. CI-SOC does not report the incident to the FBI in those cases, but they do share technical information about the attack.

Kate Libby, a Technical Director for Dragonfire Cyber which is working with the CI-SOC on this investigation, told reporters that they have not yet been able to track down how the ransomware has made its way into the systems. “The previously unidentified attackers have apparently been in these systems for some time and have erased their tracks well,” Libby explained. Dragonfire has been able to locate the ransomware in the systems, it resides in programmable logic controllers (PLC’s). “We have found multiple copies of the malware in each facility,” she reported; “We are concerned that this may mean that the attackers may be prepared to re-demand ransom in the future.”

“We have not yet been able to identify the group behind the attacks, they are very sophisticated in their security measures,” Turgidson told reporters, “We do believe that they are operating out of Venezuela.”

According to the FBI, efforts to track the bit coins have been unsuccessful, “The WB Group, as we are currently calling them, transfers funds out of their initial wallets almost immediately and closes wallets or abandons wallets once used,” Quest said; “We need to be able to track transactions in real time if we are to have any hope of shutting these folks down. This is why we need to be informed immediately about any attack.”

CAUTIONARY NOTE: This is a future news story –

Thursday, February 2, 2023

Multiple Ransomware Attacks on Artillery Contractors

The Defense Armaments Agency announced today that production of 155mm artillery shells at Blackshear Arsenal in Georgia has been halted for two weeks due to multiple ransomware attacks on subcontractors supply parts for the high-tech munitions that are being consumed in high number in the Ukraine. “We are unable to obtain component parts for the fuses and attitude control systems because various manufacturers have had production interruptions due to cyberattacks on manufacturing facilities,” Samuel C Robinson, spokesperson for the Agency, told reporters this morning.

The Federal Bureau of Inquiry is the lead agency in the investigation because the facilities are not directly contracted by the Department of Defense. According to Johnathan Quest, FBI spokesperson, the companies involved provide parts to component manufacturers that supply the Blackshear Arsenal. “In most cases, the initial set of attacks were being investigated by State and local authorities as routine ransomware attacks,” Quest explained.

General Turgidson, Director of the National Critical Infrastructure Security Operations Center (CI-SOC) which is supporting the investigation, it was not until Blackshear reported supply interruptions of multiple contractors that national level interest was focused on the investigation. “For the most part, these are small businesses using highly-automated manufacturing systems to provide small volume, high-tech components for these ammunition components,” Turgidson explained.

“It looked like these were simply ransomware attacks on random organization when we first started receiving reports form our suppliers” Blackshear spokesperson George Forno told reporters; “When we started receiving reports of damaged control systems after ransoms were paid, it became apparent that this was something more organized.”

“We are still not convinced that this is a centrally directed effort,” Quest responded. The FBI has isolated four different ransomware programs associated with known criminal groups from Russia, North Korea, Iran and Nigeria.

CI-SOC had determined that there have been some indicators that some unknown actor is providing corporate access data to known ransomware groups. “While most of these small businesses do not have significant cyber defenses due to a lack of cybersecurity personnel, there have been at least two of the facilities have been supported by the CI-SOC,” Turgidson explained; “Access to those systems took a level of sophistication not normally associated with criminal organizations.”

A technician at CI-SOC that is not authorized to talk to the press has told me that a number of cybersecurity and industrial control system companies are working closely with CI-SOC, the FBI and the affected facilities in a coordinated effort to get them back on line. Turgidson confirmed that this is an all-hands effort. “We cannot afford to allow production at Blackshear to remain idle while our allies in Ukraine are preparing for an expected Russian offensive. They need these 155mm shells.”

CAUTIONARY NOTE: This is a future news story –

Sunday, September 12, 2021

VaxSurge Ransomware

The Federal Bureau of Inquiry announced this morning that it was investigating a new ransomware campaign targeted at local public health agencies. While the attack was encoding files at the affected agencies the attacker has not been demanding a monetary ransom. Instead, they are unlocking files once the agency has published a notice in the local newspaper that they were not supporting the President’s new mandatory COVID-19 vaccination program.

“We have been notified by twenty local public health agencies about successful attacks since yesterday morning,” Johnathan Quest, spokesperson for the FBI, told reporters this morning; “Since the attacks appear to have started on Saturday, we expect to receive more notifications on Monday when many of these organizations return to normal workhours.”

The National Critical Infrastructure Security Operations Center (CI-SOC), working with the Delano, Georgia Health Department, has determined that the attackers have delivered the ransomware via a letter emailed to the Department. “The email was apparently sent by a compromised email server in the Department of Health and Medical Services. It purportedly came from the Office for COVID Vaccinations,” General Turgidson explained at an unusual Sunday press conference at CI-SOC.

A spokesperson for the Department confirmed that there was no such office in DHMS.

A technician from the CI-SOC, speaking on background, told reporters that this was not a very sophisticated ransomware program. Instead of trying to penetrate the organization network before announcing its presence, the ransomware encrypted the machine at the point of infection before it started penetrating the network. Promptly unplugging the connections to the network effectively stopped the spread of the ransomware.

Turgidson reported that the infected email included a Microsoft Word document entitled “Mandatory COVID-19 Vaccination Surge”. It contained an ActiveX-control that exploited the newly reported 0-day Microsoft® MSHTML Remote Code Execution Vulnerability. “The rapid exploitation of the Microsoft vulnerability and the use of the old-school ransomware program do not paint a consistent picture of this attacker,” Turgidson explained; “That combined with an exploitation of a SolarWinds compromised mail system is causing us all sorts of investigative headaches.”

CI-SOC is calling this the VaxSurge malware campaign because of that term is used in a comment line in the malware code sample that they are working on.

CAUTIONARY NOTE: This is a future news story –

Thursday, November 12, 2020

CI-SOC Recovers Bitcoin Ransom

The Critical Infrastructure Security Operations Center (CI-SOC) announced today that it had successfully conducted operations today against a North Korean ransomware gang that was operating out of Soul, South Korea. The bitcoin ransom paid by three separate, unidentified companies in the United States was recovered, the small server farm used by the gang was seized and four North Korean agents were arrested.

General Buck Turgidson, Director of CI-SOC, told reporters that his group, working with the South Korean government and elements of US Special Operations Command, tracked the gang by following the bitcoin trail to a compound on the outskirts of Soul. “A special team of Army Special Forces that included cyber-operators worked with a team from the South Korean Army to enter the compound and seize computer equipment before any information could be destroyed,” Turgidson told reporters.

Special Operations Command confirmed that special operations forces were involved but refused to comment on the identity of the team. They explained the participation of the military by noting that the underlying cyberattacks had been performed by agents of a foreign government. There have been rumors circulating in Washington of the formation of a Cyber A-team being formed to work on this type of operation, but there has been no confirmation from Special Operations Command or the Pentagon.

The four North Koreans captured in the raid are being held in Soul pending extradition to the United States. There are rumors that the Justice Department has concerns about trying them for their alleged cyber crimes because of search and seizure implications. A national security warrant had been issued for tracking the bitcoins, but the rules of evidence for supporting that type of warrant are different from those that would be used in a criminal court case in the United States. The tools used to track the bitcoin trail were developed by the National Security Agency and that agency would not be prepared to share the technology upon which that trace was based with the defense team. It is suspected that any criminal defense attorney would move to have the identification of his clients by such undisclosed technology suppressed.

There are rumors circulating that the Justice Department is considering certifying the ransomware attacks as terrorist attacks and allowing the foreign nationals to be tried by a military tribunal.

CAUTIONARY NOTE: This is a future news story –

Saturday, September 26, 2020

Hearing at CI-SOC on Recent Ransomware Attacks in Delano

Rep. Tucker Watts (R,GA) was on site today at the Critical Infrastructure Security Operations Center (CI-SOC) to participate in a virtual hearing of the House Subcommittee on Cybersecurity Oversight looking at the recent ransomware attacks on two facilities in Delano, GA that appeared to be related. Watts is the Ranking Member of the Committee and requested the hearing.

In his opening statement, Chairman Richard Gil (D,NY) explained that todays meeting was called to look at both the root cause of the two attacks and the role that IC-SOC could have played in preventing such attacks. “Let us be clear,” Gil explained; “Neither the Intershop Meat Plant nor the Delano Waste Water Treatment Plant had signed up to be covered by the IC-SOC, so the IC-SOC team was not setup to protect those facilities. And, even if they had, since the attacks were both initiated by an onsite insertion of a USB device, as currently configured, IC-SOC would not have been able to prevent the attacks.”

General Buck Turgidson, the Director of the National Critical Infrastructure Security Operations Center, present onsite with Congressman Watts, testified that away teams from IC-SOC responded to both incidents at the request of ECS-CERT. “Our teams only had to drive a couple of minutes across town,” Turgidson said; “The ECS-CERT team would have taken a day or more to get here.”

Immanuel C. Securitage, ECS-CERT spokesperson, testified by a video link from Washington. “We asked for assistance for two reasons,” he explained as a response to a question by Watts; “First the IC-SOC away teams were already in Delano. Second, and maybe more importantly, our staffing was cut in half to provide investigative personnel to IC-SOC.”

Horst Sinderman, the facility manager at the Delano meat plant that was attacked, testified remotely from the corporate headquarters in Birmingham, AL. He explained that, when it became obvious that the investigation team was not going to be able to fix the problem, corporate management contacted the company’s cyber-insurance provider who provided the funds to pay the ransom.

Dragonfire Cyber assisted in the investigation of attack on the meat plant and was on hand when the ransom was paid. “We were able to intercept the decryption key when it was sent to the facility,” Dade Murphy testified by video remote; “Having copies of both the encryption software from the USB devices and the decryption key, we were able to put together a decryption key for the attack on the Delano Waste Water Treatment Plant.”

That plant was able to restart about two hours after it had started discharging untreated wastewater into the Flint River. That discharge resulted in a large fish-kill and two cities downstream had to slow their processing of drinking water from the River to ensure that all contaminants and bacteria from the discharge were removed. Cities further downstream noticed little additional contamination in their intake testing.

Mayor Arrington Carter provided a written statement that was read into the record of the hearing. In part she said, “We are very grateful for the assistance that IC-SOC provided to the two facilities in the city during these attacks on our essential infrastructure. A major employer and our city services would have been affected much more severely if the government team had not stepped in with their expertise.”

The Federal Bureau of Inquiry is still investigating the two attacks. Johnathan Quest, spokesperson for the FBI, answered my questions this morning in a telephone interview about the investigation. The FBI continues to investigate both incidents as part of a larger plot by TrabajoSeUnen to affect operations at meat packing plants around the country. “While they are employing typical labor jargon in their messaging,” Quest said; “We can find no evidence of collusion between the group and local labor organizations. We believe that this is a straightforward ransomware campaign executed with the intent to make money.”

Congressman Watts told this reporter that he intended to introduce legislation that would require municipal water treatment facilities and wastewater treatment facility to either join IC-SOC or some other cybersecurity monitoring service. “We just cannot afford to have these facilities shut down by either criminals or terrorists,” he said.

CAUTIONARY NOTE: This is a future news story –

 

Thursday, September 24, 2020

Water Treatment Plant Hit by Ransomware Attack

The Delano Waste Water Treatment Plant (WWTP) announced this morning that its computer systems that control the physical operation of the facility have been shutdown by a ransomware attack. The attackers, reportedly the same group that shutdown the operation of the Intershop Meat Plant last week, are demanding 1,000 bitcoin from the City of Delano to unlock the facility control systems.

George Funderburke, the director of the Delano Water Maintenance Department (DWMD) told reporters at a brief news conference that both the Federal Bureau of Inquiry and the Environmental Process Protection Agency (EPPA) about the attack. “EPPA and ECS-CERT will be sending teams to help us get our plant back in operation,” Funderburke said; “We have about six hours of storage capacity available for incoming sewage, after that we will have to start discharging untreated sewage into the Flint River.”

Jay Muir, spokesperson for the EPPA, told this reporter that the EPPA was sending an action team to Delano, but that it would probably be the ECS-CERT that would be the lead agency on the investigation. “The team we are sending are process engineering types,” Muir said; “They will be responsible for helping the WWTP operate as effectively as possible in a manual operating mode. They should arrive on site before it is necessary to start discharging untreated sewage.”

The WWTP has only limited capacity to continue operation under manual conditions. The facility will continue to be discharging treated water through manual operations. A warning will be issued before any untreated sewage is discharged. Cities downstream of Delano have been warned that a sewage discharge may be required.

The DWMD does not have funds available in their budget to pay the ransom. Mayor Arrington Carter has scheduled an emergency meeting of the Delano City Council for later this morning to see what actions the City will be taking. “The DWMD has had problems with cash flow since the COVID-19 epidemic hit last spring. They have had a much larger than normal non-payment rate on water bills for both household and commercial accounts. We have been using the City’s rainy day fund to supplement their accounts for the last two months, so we may have problems coming up with the money for the ransom.”

Kate Libby, a spokesperson for Dragonfire Cyber, said that the Company has not yet been notified about this ransomware attack, but was working with the ECS-CERT on the investigation at the Intershop Meat Plant. “We have discovered that the source of that attack was a USB drive inserted into one of the PLC’s at the facility; it was apparently an insider attack.”

Funderburke has asked residents and businesses in Delano to reduce their water use and waste generation while the City works to correct this problem. Commercial and industrial facilities with large volume discharges have been notified to stop those discharges as soon as possible. This does include the Intershop Meat Plant that just reopened yesterday.

The Critical Infrastructure Security Operations Center (CI-SOC) would not comment on this attack.

CAUTIONARY NOTE: This is a future news story –

Saturday, August 1, 2020

Ransomware Re-infected from Sensor

Dragonfire Cyber published a report today on a recent ransomware attack on a PLC being used in a safety system at a Louisiana chemical manufacturing plant. There were two unique things about this ransomware attack, the report states. First the ransomware did not encrypt system files, it simply shutdown the safety system and demanded a 100-bitcoin ransom. The second item of interest is that the system was re-infected as soon as the affected PLC was released.

 

The active portion of the ransomware reset the Robotron SicherheitsKontrolle PLC to factory default settings, erasing the programming designed to ensure that the styrene storage tank remained in an inherently safe state. It also erased the control screen on the HMI used by the safety system, replacing the virtual system diagram with the ransomware message.

 

Since the affected system was a safety system, the facility had a preprogramed replacement on hand for both the PLC and the HMI. As soon as the ransomware message was reported, maintenance personnel were contacted and the two devices were replaced within an hour.

 

“The attackers understood how easy it was to replace the affected devices without resorting to paying the ransom,” Kate Libby, spokesperson for Dragonfire, told this reporter; “So they designed their ransomware system so that it would immediately infect the replaced equipment.”

 

The local control system maintenance personnel were not able to find the initial source of the infection or the re-infection. In order to ensure the safety of the facility, the company paid the ransomware and the system was immediately returned to its pre-infection state.

 

Dragonfire was retained to discover the source of the infection, determine how the system was re-infected, and ensure that there were no other problems with the system. The source of the initial infection was the USB that was used to apply the annual system updates for the safety system. The USB, sent from Robotron offices in Germany, was apparently intercepted at the local delivery company office and the infected with the ĀnquánShújīn worm.

 

The USB device was erased when it was removed from the laptop used to update the PLC, but the technician who performed the update copied the update to a backup drive for record keeping purposes. The drive erase program was not transferred as it was hidden USB firmware. The malware programming on the laptop was automatically erased and overwritten with the original update after the safety system was updated.

 

“With a copy of the actual ransomware code on hand, it was easy enough to track down the source of the re-infection,” Libby told me; “A copy of the worm was moved to one of the smart sensors attached to the safety system, in this case a Robotron DSensor”.

 

When the new PLC made initial contact with the infected sensor, the worm reinstalled the malware on the PLC, restarting the whole process.

 

Immanuel C. Securitage, spokesperson for ECS-CERT, said that the malware seen in this attack was much more sophisticated that the GUMMI BAREN ransomware that was seen in earlier attacks on Robotron PLC’s. “Two years allows for a lot of malware advancement,” IC Securitage told this reporter; “We also suspect that there may be a State actor involved which also allows for an entirely different level of sophistication.”

 

The Federal Bureau of Inquiry is reportedly investigating if this incident is the work of the NoReturn group that has been causing problems at a number of chemical companies in the United States. Johnathan Quest refused to comment on that portion of the ongoing investigation, saying: “We are continuing to work with the facility owner, ECS-CERT and Dragonfire on the incident investigation. We currently have no suspects, but we are talking with persons of interest at the GHB Air facility in Shreveport about the Robotron USB delivery.

 

CAUTIONARY NOTE: This is a future news story –


Sunday, July 19, 2020

Control System Ransomware Attack Shuts Down Chem Plant


Blew Bayou Chemical Company announced that it had shut down its Shreveport, LA facility due to a ransomware attack on a control system at the facility. Only one storage tank safety system is currently affected, but the decision was made to shut down the entire plant as a precautionary measure. The Federal Bureau of Inquiry and the ECS-CERT are conducting a joint investigation.

Johnathan Quest, FBI spokesperson, told reporters that since the facility is considered critical infrastructure, a ransomware attack is considered to be a federal crime. “We are working closely with ECS-CERT and the facility owners to determine who is behind this attack;” Quest said.

Immanuel C. Securitage, ECS-CER spokesperson, confirmed that it had investigators onsite.

Issac B Kaghun, CEO of Blew Bayou Chemical, told reporters that the company became aware of the problem when a screen for the safety control system for the styrene monomer tank turned red and an announcement was printed on the screen that said a ransom would have to be paid to regain control of the system. The attackers asked for a ransom of 100 bitcoin for the return of control of the system.

Securitage told reporters: “The screen claimed that the safety PLC for the system was under the control of ‘Ä€nquánShújÄ«n’, Chinese for ‘safety ransom’. We have never seen this type of ransomware before.”

An investigator from Dragonfire Cyber working with the ECS-CERT team speaking anonymously said that, instead of encrypting files as is seen in most normal ransomware, the AS ransomware reprogramed the PLC to shutdown all sensors and valve controllers associated with the system.”

Securitage confirmed that the company had removed the affected PLC from the system and replaced it with a preprogramed substitute that was kept on hand for emergency situations. “The replacement worked properly for about five minutes and then it was corrupted as well,” he explained; “That caused us to assume that there was some sort of worm in the system that caused the reinfection. We recommended that the company under take a shutdown of all control systems pending further investigations.”

The company is currently running all safety systems in manual mode.


Monday, May 25, 2020

More Chemical Company Attacks by NoReturn Group


The FBI announced today that Sohio Chemical of Columbus, OH reported a ransomware attack that was conducted by the NoReturn APT group. “We had been watching the progress of the previously identified attack as part of our ongoing investigation of the NoReturn group;” Johnathan Quest, a spokesman for the Federal Bureau of Inquiry; “The adversary then initiated a ransomware attack using a protocol we had not seen before, knocking out most of the corporate network”.

Sohio operates an acrylonitrile manufacturing facility in Wuhan, China. According to the company president, Franklin Veatch, because of the problems running a manufacturing facility in the epicenter of the COVID-19 outbreak in China and a recent push by the Trump Administration to move critical manufacturing back to the United States, Sohio was actively exploring moving their acrylonitrile manufacturing back to Ohio.

Dade Murphy, the CTO for Dragonfire Cyber, told reporters today that Dragonfire was working with Sohio because his company had detected the initial attack on the company while monitoring a server in China associated with the NoReturn group. “We had assured the company and the FBI that we could detect and block the ransomware attack,” Dade told reporters, “But the NoReturn group used a new attack methodology that we were not prepared to block. We will be ready the next time.”

Dade did note that the initial phishing email was disguised to appear to have come from a Sohio email account in their Wuhan, China manufacturing facility. “We have confirmed that it actually originated in the NoReturn group server in Guangzhou, China. The people who received the email in the headquarters engineering department would have had no way of knowing that.”

Veatch told reporters that; “Against the advice of both the FBI and Dragonfire, we decided to pay the 1,000-bitcoin ransom to get our system released.” The company had made every other day backups of most of their operational files, but while the attackers were operating within their systems, they had gained access to those backups and erased the last three backups just before the ransomware locked up the company systems. “We had critical financial files saved in those three missing backups, so we were forced to pay the ransom,” Franklin told reporters.

Murphy told reporters that Dragonfire was working with Sohio Chemical to determine if any critical engineering files were missing, something that they had seen in earlier attacks. “That does not seem to be the case in this attack, but we are seeing some indications that some of the engineering data may have been changed,” Murphy said.

Rep. Martin L. Davey (D,OH) is calling on the Cybersecurity Agency (CSA) and the Agency for Chemical and Environmental Security (ACES) to take a more active role in helping to prevent these types of attacks on critical infrastructure. Davey is planning on introducing new legislation requiring those agencies to protect critical chemical manufacturers for cyberattacks before next week’s House hearing on the NoReturn group.


Tuesday, February 25, 2020

Refinery Still Down from Ransomware Attack


Cesar Chavez of the Rafael Ravard Refinery in Baton Rouge, LA announced this morning that the refinery was still shut down from last month’s ransomware attack. “We initially decided not to pay the ransom since we had off sit backups for our major control system components, but after determining that the ransomware had encrypted device level software for which we had no backups, we decided that we had to pay the ransom” Chavez told reporters.

Chavez explained that the owners of the WannaControl malware added additional penalties for the delay in paying the ransomware and were now releasing the control system devices on a unit-by-unit basis with a separate, smaller ransom being required for each unit. So far, the refinery has reportedly paid out $1.9 million in bitcoin ransom payments.

Johnathan Quest, spokesman for the Federal Bureau of Inquiry, told reporters that the Bureau was still investigating the attack, but were unable to trace the ransom ware payments. “Bitcoin transactions are very difficult to trace, but we are working with a number of international law enforcement agencies and various intelligence agencies to crack the Bitcoin network.

Immanuel C. Securitage, spokesman for the ECS-CERT, told reporters that his agency was working closely with the refinery and Robotron on the security issues related to this attack. “The agency has not been notified of other facilities that may have experienced a WannaControl attack, but we suspect that some attacks have taken place and that the owners quickly paid the ransom to avoid the results that the refinery has experienced,” he explained.

ECS-CERT strongly recommends that anyone facility that had purchased Robotron pumps in the last half of 2019 immediately take them out of service until a Robotron representative can reload the motor control software. Facilities with such pumps in service should have their control system immediately checked for possible compromise. “ECS-CERT has noted that the refinery attackers apparently had access to the control system for at least a month before the attack was initiated,” Securitage reported.

In response to a reporter’s question about ECS-CERT support for finding apparently affected systems, Securitage said: “ECS-CERT does not have enough investigators to help everyone affected by the Robotron vulnerability, nor apparently does Robotron.” ECS-CERT is not allowed to recommend private sector companies that could do this work, but Securitage noted that: “Any major ICS security organization could probably do the assessment.”

Erich Mielke from Robotron released a statement that said the company was deploying as many of their security engineers as it had available to look at potentially affected Robotron control systems, but facilities that used Robotron pumps with other vendor control systems should probably reach out to the system vendor for assistance. Robotron has published a report on the malware that was loaded on their pump controllers that includes indicators of possible compromise that could be looked for on other products.

Rep. Harvey Milk (D,CA) announced that his subcommittee will be holding a hearing this week looking at the refinery attack. “We need to ensure that these types of ransomware attacks on critical infrastructure cannot happen,” he told reporters. He went on to criticize ECS-CERT’s inability to effectively support critical infrastructure owners in preventing further occurrences of this particular attack, saying: “Congress expects ECS-CERT to be proactive in responding to attacks like this; we want answers now.”


Friday, January 31, 2020

WannaControl Attack on Louisiana Refinery


Cesar Chavez of the Rafael Ravard Refinery in Baton Rouge, LA announced this morning that overnight the refinery operations had been shut down by a a ransomware attack. “It appears that the refinery was the victim of the WannaControl ransomware. The attackers are demanding 100 Bitcoin to release our control systems back into operation,” he reported. At today’s exchange rate that is about $930,000.

Chaves reported that: “We have not yet made a decision on paying the ransom. We will consult with our insurers and the Federal Bureau of Inquiry before finalizing that decision.”

Chavez explained that the refinery operations were shutdown in an orderly manner, but there were numerous flaring incidents during the process. “It does not appear that any damage has been done to the refinery and no personnel were injured,” he explained.

ECS-CERT and the FBI will be conducting a joint investigation of this attack, according to Immanuel C. Securitage of the ECS-CERT. “Preliminary indications are that this attack may be related to the announcement by Robotron earlier this week;” Securitage noted. That announcement was about the possible compromise of software shipped by Robotron after a cyberattack on their facility last October.

When asked about that announcement Chaves acknowledged that the refinery had installed a number of the potentially impacted Robotron controlled pumps during a turn around last year. The company had been planning on replacing those pumps during the next scheduled maintenance activity of each refinery unit. “We may try to do that before the refinery restarts, but it depends on the availability of replacement pumps;” Chavez told reporters.


Monday, January 2, 2017

ECS-CERT Confirms Ransomware Attack

The Chemical Safety Bored (CSB) and the Electronic Control System CERT (ECS-CERT) issue a joint statement today confirming that the recent spate of fires at the Rafael Ravard Refinery south of Baton Rouge were a result of a ransomware attack on the electronic control systems at the refinery. According to the statement, the attack was caused by a new variant of the GUMMI BAREN worm associated with the Stasi Ehemalige, a German criminal syndicate.

Immanuel C. Securitage, the ECS-CERT lead for the refinery investigation, stated that the new variant of GUMMI BAREN has been modified specifically to attack electronic control systems that use the programmable logic controllers manufactured by Robotron, a German electronics company. The Robotron update system has apparently been hacked by Stasi Ehemalige and the GUMMI BAREN launcher included in their latest PLC updates.

Robotron has issued a statement that they are working closely with ECS-CERT to identify the source of the problem with their updater and currently recommend that their customers do not apply the most recent update to their PLC firmware.

Securitage explained that the GUMMI BARREN variant was specifically designed to infect multiple PLCs at a facility through infection via an engineering lap top. The worm includes a delay mechanism so that the encryption of the PLC firmware takes simultaneously across an organization.


Cesar Chavez, a spokesman for the Rafael Ravard Refinery, confirms that a ransom of 1000 bitcoin was demanded by Stasi Ehemalige. They have refused to pay the ransom. Chavez notes that the facility has backups for all firmware for their electronic control system. As soon as the facility has recovered from the uncontrolled shutdown caused by this ransomware attack, they expect that only a short turnaround will be needed to get the facility back into production.

Tuesday, December 27, 2016

CSB Continues to Investigate Multiple Fires at Ravard Refinery

Baton Rouge, LA

Investigators from the Chemical Safety Bored continue their investigation of multiple fires at the Rafael Ravard Refinery south of the city even as more fires break out. So far there has been no serious damage to the refinery, no deaths and limited injuries in the on-going incident. Refinery officials press on with their attempts to manually shut-down the operations.

CSB investigators showed up Saturday as fires were extinguished in Cracker #2 which was undergoing non-routine maintenance when the fires started. Additional fires in other units started while those investigators were on-site as unscheduled shut-downs started in other units.

A CSB spokesman confirmed earlier reports that the initial fire appears to be related to unplanned shutdown of electronic control system components in Cracker #2. Those shutdowns were apparently associated with the routine maintenance of a valve controller in a bypassed line in that unit.

Unconfirmed reports continue to be heard that the initial problem was caused by a software issue associated with that valve maintenance. Investigators from an unnamed federal lab in Idaho did arrive on seen on yesterday. These investigators are reportedly cybersecurity experts that work with electronic control systems.

Reports are starting to circulate that a ransomware incident involving a lap top involved in that valve maintenance may be the starting point of the incident. At least on engineer from the facility has stated that ransomware is spreading through the facility. That engineer has not been available for talks with the press.

Ransomware is an attack on computer information systems that encrypts files and requires the owner of the system to pay a ransom to have those files decrypted. There have been an increasing number of ransomware incidents being reported. Most recently the Women and Children’s Hospital here in Baton Rouge was affected and was forced shutdown many operations while backup files were used to bypass the problem.


There have been no reports from the refinery about the number of on-site first aid cases related to the fires during this incident. There have been 12 people taken to local hospitals, mainly with smoke inhalation issues. One facility fire fighter is in serious condition in with chemical burns. Names of the injured have not been publicly released.