Showing posts with label Temperature Control. Show all posts
Showing posts with label Temperature Control. Show all posts

Friday, November 20, 2020

COVID-19 Vaccine Hack

General Buck Turgidson, Director of the Critical Infrastructure Security Operations Center (CI-SOC), told a press conference this morning that the ransomware attack on Mengele Pharma earlier this week used a variant of the WannaControl ransomware. He also noted that investigators working for CI-SOC discovered that the as yet unidentified attackers gained access to the warehouse facility control system via storage batteries associated with the rooftop solar array.

Turgidson told reporters: “There were significant changes made to the ransomware code. We do not believe at this time that those changes were made by Stasi Ehemalige, the authors of the original ransomware.” A manager at CI-SOC told me that there are indications that Stasi Ehemalige has been selling copies of their ransomware on the Dark Web.

A briefing document provided to reporters says that changes to the ransomware include the inclusion of a data exfiltration module as well as a tool specifically designed to make modifications to the programming of the Robotron Kühlsicherheit refrigeration safety system that is used at the facility. The report also notes that the manufacturing control system at the Mengele Pharma vaccine plant adjacent to the warehouse was also infected, but that it had not yet been shut down by the ransomware.

Dade Murphy, CTO at Dragonfire Cyber, said that his team supporting the CI-SOC investigation had been able to deconstruct the ransomware package that shut down the warehouse operations. “The new code that facilitated this particular attack,” Murphy told reporters, “has significant structural and coding differences that indicate that a different team of developers worked on the new modules. There are many similarities between the coding styles used here and that used in the ĀnquánShújīn PLC ransomware used in an attack earlier this summer.” Murphy was unable to explain why those coders would have used Stasi Ehemalige malware for this attack.

Murphy told reporters that they had found one of the affected freezers had an old-style circular chart recorder for temperature still working on the freezer. “This system with its dedicated thermocouple was unaffected by the attack. While the one-week chart had not been changed in a month we can clearly see that the temperature in the freezer rose to -30˚C for extended periods,” Murphy said; “If this chart had been tracked, the problem would have been detected in time to prevent the problems with vaccine storage conditions.”

The attack on the warehouse control system was initiated via the energy storage system associated with the roof top solar array. “The known vulnerability in the direct internet connection of the battery system was used to gain access to the facility maintenance network.” Murphy told reporters, “Once that network access was gained, it was relatively easy for the attackers to pivot into the building automation system and then into the warehouse refrigeration systems.”

Wolfgang Gerhard, President of Mengele Pharma told reporters that the solar system had apparently been installed before the vulnerability was reported. “We have been in contact with the contractor we used for that installation.” Gerhard said, “They are currently working on updating the system and mitigating that particular vulnerability.”

Wolfgang was able to update reporters on the effect of the refrigeration attack on the inventory of COVID-19 vaccine stored on the premises. Each box is equipped with a chemical temperature warning decal that changes color when the temperature rises above a set point. “We have examined each of the boxes in all five of the freezers on site,” Gerhard said; “About 80% of the indicators show that the packages had been exposed to temperatures above the -50˚C limit set by the Federal Drug Administration in their approval of the vaccine.” Mengele is turning over all of those cases to the FDA for study and disposal.

Clark Stanley, spokesperson for the FDA, told reporters that the agency would be storing each of the affected boxes in the appropriate conditions. “We will be conducting efficacy testing on samples from each of the boxes to determine what effect the unfortunate temperature excursions had on the vaccine,” Stanley said; “We may be able to provide box-by-box approval for the use of some of the vaccine. We do understand the importance of having a COVID-19 vaccine available as quickly as possible, but we want to ensure that it is an effective vaccine that the public can rely on.”

CAUTIONARY NOTE: This is a future news story –

Friday, January 6, 2017

Local Company Claims Chinese Hackers Cause of Bankruptcy

New Orleans, LA

Today Isaac B (IB) Kaghun announced that the bankruptcy proceedings completed today meant that the Blew Bayou Chemical Company was not going to re-open its doors. IB reported that Chinese hackers were responsible for the high-rework rate over the last six months that destroyed the profitability of the company. He claimed that hackers supporting Tianjin Chemical, his only competitor in the production of Tetramethyldeath (TMD), the revolutionary plasticizer being used as a replacement for BPA.

IB Kaghun, the son of Russian emigres, developed TMD during his graduate studies at LSU. TMD is a monomer that can be added to the polymerization of PVC and other plastics to provide both increased flexibility and strength to those plastics. Tianjin Chemical started production of the chemical after a well-publicized hack of Blew Bayou Chemical computers stole proprietary information about the production of the material. The FBI was never able to find prove that Tianjin Chemical had anything to do with the data theft.

Blew Bayou had been successfully manufacturing TMD for about ten years with multiple expansions of their facility east of New Orleans. Last spring the company started to experience manufacturing problems that resulted in high contamination rates in their product that made the TMD unusable. The costs associated with the lost production and disposal of the flammable chemical quickly ate into the bottom line of Blew Bayou Chemical.

Recent disclosures about vulnerabilities in the Robotron programmable logic controllers (PLC) raised the possibility that a hack of those devices being used in the Blew Bayou manufacturing facility raised the possibility of that being the cause of the manufacturing problems at the plant. IB contacted the Electronic Control System CERT for assistance to determine if a cyber attack had taken place.

Immanuel C. Securitage, a spokesman for ECS-CERT, confirmed that the agency had completed an on-site investigation and did find unauthorized modifications to the programming of some of the PLCs used in the manufacturing process.

“This was a very sophisticated attack,” Securitage said. “There is a critical temperature that must be maintained in the manufacturing process. Any temperature above that critical point causes an increase in the production of undesirable byproducts. The programing of the PLC was modified to change the temperature being reported by two separate temperature probes so that they reported lower temperatures than was actually being experienced in the reaction vessel.”

Kaghun added that whoever was responsible for the hack had very detailed knowledge of the manufacturing process. The revised PLC programming used a complex algorithm so that the rate of change of the reported temperature increased as the temperature approached the critical point. The reported temperature changes then slowly decreased back to actual temperatures above the critical temperature. This was important because at about 15 degrees above the critical point the pressure would have started to rise in the vessel, alerting operators to problems with the reaction.

UPDATE

Houston, TX

Rumors have been confirmed that as part of the bankruptcy settlement, IB Kaghun is providing the details about the manufacturing process for TMD to one of his suppliers, a major chemical company outside of Houston. This is being used in lieu of cash payment for the debts to that company. There are no plans to re-open the facility in Louisiana, according to industry sources.


There are also rumors that the Federal government is considering sanctions against Tianjin Chemical for their alleged part in the hacking of Blew Bayou Chemical.